Update dependency koa to v2.16.4 #6

Open
renovate wants to merge 1 commits from renovate/koa-2.x-lockfile into master
Collaborator

This PR contains the following updates:

Package Type Update Change
koa (source) dependencies minor 2.15.32.16.4

Release Notes

koajs/koa (koa)

v2.16.4

Compare Source

What's Changed

v2.16.3

Compare Source

What's Changed

Full Changelog: https://github.com/koajs/koa/compare/v2.16.2...v2.16.3

v2.16.2

Compare Source

What's Changed

Full Changelog: https://github.com/koajs/koa/compare/v2.16.1...v2.16.2

v2.16.1

Compare Source

fix: don't render redirect values in anchor ref

v2.16.0

Compare Source

This is a backported release to fix core underlying issue with HEAD requests when using http2.createSecureServer. See discussion at #​1593 and #​1547.

  • fix missing cleanup, if response socket is no longer writeable (issue 1547) (#​1593) 399cb6b

v2.15.4

Compare Source

Full Changelog: https://github.com/koajs/koa/compare/2.15.3...2.15.4

Fix: avoid redos on host and protocol getter, see https://github.com/koajs/koa/security/advisories/GHSA-593f-38f6-jp5m


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [koa](https://koajs.com) ([source](https://github.com/koajs/koa)) | dependencies | minor | [`2.15.3` → `2.16.4`](https://renovatebot.com/diffs/npm/koa/2.15.3/2.16.4) | --- ### Release Notes <details> <summary>koajs/koa (koa)</summary> ### [`v2.16.4`](https://github.com/koajs/koa/releases/tag/v2.16.4) [Compare Source](https://github.com/koajs/koa/compare/v2.16.3...v2.16.4) #### What's Changed - fix(security): Host Header Injection via `ctx.hostname` by [@&#8203;killagu](https://github.com/killagu) <https://github.com/koajs/koa/security/advisories/GHSA-7gcc-r8m5-44qm> ### [`v2.16.3`](https://github.com/koajs/koa/releases/tag/v2.16.3) [Compare Source](https://github.com/koajs/koa/compare/v2.16.2...v2.16.3) #### What's Changed - fix: normalize referer before redirect by [@&#8203;fengmk2](https://github.com/fengmk2) in [#&#8203;1909](https://github.com/koajs/koa/pull/1909) **Full Changelog**: <https://github.com/koajs/koa/compare/v2.16.2...v2.16.3> ### [`v2.16.2`](https://github.com/koajs/koa/releases/tag/v2.16.2) [Compare Source](https://github.com/koajs/koa/compare/v2.16.1...v2.16.2) #### What's Changed - fix: only allow back redirect to the same origin referer by [@&#8203;fengmk2](https://github.com/fengmk2) in [#&#8203;1898](https://github.com/koajs/koa/pull/1898) **Full Changelog**: <https://github.com/koajs/koa/compare/v2.16.1...v2.16.2> ### [`v2.16.1`](https://github.com/koajs/koa/releases/tag/v2.16.1) [Compare Source](https://github.com/koajs/koa/compare/v2.16.0...v2.16.1) fix: don't render redirect values in anchor ref ### [`v2.16.0`](https://github.com/koajs/koa/releases/tag/2.16.0) [Compare Source](https://github.com/koajs/koa/compare/2.15.4...v2.16.0) This is a backported release to fix core underlying issue with `HEAD` requests when using `http2.createSecureServer`. See discussion at [#&#8203;1593](https://github.com/koajs/koa/pull/1593) and [#&#8203;1547](https://github.com/koajs/koa/issues/1547). - fix missing cleanup, if response socket is no longer writeable (issue 1547) ([#&#8203;1593](https://github.com/koajs/koa/pull/1593)) [`399cb6b`](https://github.com/koajs/koa/commit/399cb6b0dd2104224c0ef0ce8e92f84e4f7faf42) ### [`v2.15.4`](https://github.com/koajs/koa/releases/tag/2.15.4) [Compare Source](https://github.com/koajs/koa/compare/2.15.3...2.15.4) **Full Changelog**: <https://github.com/koajs/koa/compare/2.15.3...2.15.4> Fix: avoid redos on host and protocol getter, see <https://github.com/koajs/koa/security/advisories/GHSA-593f-38f6-jp5m> </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMTAuMTQiLCJ1cGRhdGVkSW5WZXIiOiI0My4xMTAuMTQiLCJ0YXJnZXRCcmFuY2giOiJtYXN0ZXIiLCJsYWJlbHMiOltdfQ==-->
renovate added 1 commit 2026-04-14 22:00:22 +00:00
This pull request can be merged automatically.
You are not authorized to merge this pull request.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin renovate/koa-2.x-lockfile:renovate/koa-2.x-lockfile
git checkout renovate/koa-2.x-lockfile
Sign in to join this conversation.
No Reviewers
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: StefanMewes/send2ereader#6