-
Notifications
You must be signed in to change notification settings - Fork 1.5k
Comparing changes
Open a pull request
base repository: hapijs/joi
base: v17.13.4
head repository: hapijs/joi
compare: v17.13.7
- 11 commits
- 9 files changed
- 2 contributors
Commits on Aug 19, 2026
-
chore: deny prototype pollution in objects by restoring prototype
(cherry picked from commit fe41c4f)
Configuration menu - View commit details
-
Copy full SHA for 30766a2 - Browse repository at this point
Copy the full SHA 30766a2View commit details -
Configuration menu - View commit details
-
Copy full SHA for 172ecec - Browse repository at this point
Copy the full SHA 172ececView commit details -
Merge pull request #3135 from hapijs/chore/backport-rename-proto
chore: backport prevent proto on renames
Configuration menu - View commit details
-
Copy full SHA for 3f3907c - Browse repository at this point
Copy the full SHA 3f3907cView commit details -
Configuration menu - View commit details
-
Copy full SHA for 566e73f - Browse repository at this point
Copy the full SHA 566e73fView commit details -
fix: prevent messages proto injection
(cherry picked from commit 90d0757)
Configuration menu - View commit details
-
Copy full SHA for 8d0b808 - Browse repository at this point
Copy the full SHA 8d0b808View commit details -
Merge pull request #3139 from hapijs/chore/backport-messages-proto
fix: prevent messages proto injection
Configuration menu - View commit details
-
Copy full SHA for 9faeecc - Browse repository at this point
Copy the full SHA 9faeeccView commit details -
Configuration menu - View commit details
-
Copy full SHA for 850be1e - Browse repository at this point
Copy the full SHA 850be1eView commit details
Commits on Sep 2, 2026
-
fix(isoDate): pad a bare-hour timeshift with a colon, not just zeros
internals.isoDate() pads a bare-hour UTC timeshift (e.g. "+04") before handing the string to Date() by appending '00' directly, producing "...+0400" instead of the ISO 8601 extended-format "...+04:00". Node's own Date parser tolerates the malformed form, which is why this went unnoticed, but it breaks stricter parsers (Safari) since ISO 8601 doesn't allow mixing basic-format offsets into an otherwise extended-format string. Flagged by a reviewer on #2421 (the PR that introduced this line) but never addressed after merge; tracked since as #2434. Also drops the leading `.*` in the trigger regex, per the same review thread - matching doesn't require anchoring at the string start, so it was redundant. Since Node's Date constructor doesn't distinguish "+0700" from "+07:00", a test asserting on Joi's converted output wouldn't catch a regression here. The new test instead spies on the Date constructor to assert the actual string produced. Fixes #2434. (cherry picked from commit e70df42)
Configuration menu - View commit details
-
Copy full SHA for 115e7b5 - Browse repository at this point
Copy the full SHA 115e7b5View commit details -
chore: add regression test for #3143
(cherry picked from commit cc81a74a9366452ee6c66411fb8b9f5b96d54935)
Configuration menu - View commit details
-
Copy full SHA for c43fc96 - Browse repository at this point
Copy the full SHA c43fc96View commit details -
Configuration menu - View commit details
-
Copy full SHA for f2729f7 - Browse repository at this point
Copy the full SHA f2729f7View commit details -
Configuration menu - View commit details
-
Copy full SHA for ed9d7cd - Browse repository at this point
Copy the full SHA ed9d7cdView commit details
This comparison is taking too long to generate.
Unfortunately it looks like we can’t render this comparison for you right now. It might be too big, or there might be something weird with your repository.
You can try running this command locally to see the comparison on your machine:
git diff v17.13.4...v17.13.7