Repository navigation
Publish New NPM version for Node-Static聽#231
Description
Activity
Can anyone publish the latest updates to npm? I see that the latest commit fixes some issues but doesn't publish to npm
@cloudhead : I went ahead and replaced the history so as to avoid all the merges (though keeping a copy of the old branch with all of them), so I think it should be ready for your review before a release.
(And if accepted, we can also close #232 )@cloudhead : Can we go ahead with this?
@cloudhead : Do you want periodic checkbacks like this or do you have an ETA? The commit history should be all cleaned up.
Am I crazy, or did this replace the npm package with the wrong code?
- using ubuntu 20.04.2 LTS (WSL)
- npm i node-static
- observe: package.json and package-lock.json shows 0.7.11
- more node_modules/bin/node-static/lib/node-static.js
- observe: line 11 reads
var version = [0, 7, 9]; - observe: missing features, "var"s everywhere, code completely does not match github
Maybe I'm losing it, but something is pretty bizarre here, and my only theory is a funky npm registry update.
alternate path to reproduce:
- download https://registry.npmjs.org/node-static/-/node-static-0.7.11.tgz (the path of the latest npm package for this repo)
- unzip, untar
- observe pacakge/lib/node-static.js: appears to be 0.7.9
edit:
npm i cloudhead/node-staticinstalls the correct version
If you look at https://www.npmjs.com/package/node-static , it was last published 4 years ago, and the latest version is 0.7.11.
If you use the "blame" feature for the file defining the version, you can see a commit from 12 months ago where it was changed from
vartoconst(but still listing 0.7.9) at the time.Thus, the version just hadn't been updated despite subsequent releases up to 0.7.11
As to why there is a
const, etc., there have been (many) changes onmastersince that time and we are awaiting a new publishing. The project owner still needs to give final approval on these changes, so these many changes have not been published to npm yet.FWIW, some of the changes are available on my fork,
@brettz9/node-static(using a different (smaller) versioning number as it is an independent project), but as the author of the regularnode-statichere eventually replied granting access to the project with openness to including my changes, I resumed work here.Reacted by Owen Carter and HCorteHi. When this upgrade will be done? We get this issue from snyk
Denial of Service (DoS) [High Severity][https://snyk.io/vuln/SNYK-JS-NODESTATIC-1297183] in node-static@0.7.11 introduced by node-static@0.7.11 No upgrade or patch availableThank you.
Hey, sorry, am pretty overwhelmed with other stuff, @brettz9 -- can you point me again to the cleaned up history?
Sure, @cloudhead ...Thankfully, we were able to get the history cleaned, so
masteris already a cleaned history.If you want the diffs from what is apparently the final commit for the latest published published version, 0.7.11 (there's no tag for it), see https://github.com/cloudhead/node-static/compare/e59fe21dffbee46678362d26d26fdfb241f49506..master , but there's a whole lot of noise if trying to look at all at once.
Hi,
We are concerned by the same issue as @andreeatirgovatustockX .
Is there a workaround we can apply to not be impacted by the SNYK-JS-NODESTATIC-1297183 security issue anymore ?
(waiting until a new version is published)Reacted by Roberto Posenato@francoisihry : As mentioned at https://security.snyk.io/vuln/SNYK-JS-NODESTATIC-1297183 , this was fixed in
masterof this project. Ideally, however, @cloudhead may be able to review the commits onmastersince the last release so a new npm release can be published.Reacted by Roberto PosenatoThank you @brettz9 we look forward for a new version to be released so that we can easily integrate the fix.
- added a commit that references this issue
on Oct 7, 2025 Not having heard back from @cloudhead , on August 14, I filed for a transfer of ownership to GitHub (who now manage npm). They are unfortunately unable to give a wait time.
If it appears it is taking too long, I've reserved a "node-static" organization, and can publish a
@node-static/node-staticfork.Reacted by peterbernhardtReacted by Guangcong LuoOk, I've gotten around to publishing the fork of @node-static/node-static . Feel free to add further issues to its repository at https://github.com/node-static/node-static . I can keep this issue open here to indicate the fact of the change, and in case we hear back from anyone who may decide to grant access.
Ok, I've gotten around to publishing the fork of @node-static/node-static . Feel free to add further issues to its repository at https://github.com/node-static/node-static . I can keep this issue open here to indicate the fact of the change, and in case we hear back from anyone who may decide to grant access.
This seems to be a dead link. What's up?
Ok, I've gotten around to publishing the fork of @node-static/node-static . Feel free to add further issues to its repository at https://github.com/node-static/node-static . I can keep this issue open here to indicate the fact of the change, and in case we hear back from anyone who may decide to grant access.
This seems to be a dead link. What's up?
Whoops. I created it private. Now switched to public. The npm package has been available for some time though.
As far as ownership of
node-staticI received a message from GitHub today stating:We are sunsetting the previous policy that allowed users to dispute namespace ownership. Moving forward, all requests will need to be submitted as Trademark Policy Violation Reports through [Github's Trademark Policy](https://docs.github.com/en/site-policy/content-removal-policies/github-trademark-policy). As a result, your existing dispute request will be closed. If you would like to pursue your claim, please submit a new request via our online form: https://support.github.com/contact/trademark-policySince I do not hold any trademark for the name, it seems to me that we may need to be content with
@node-static/node-static.EDIT: I confirmed at the form that indicating I am not the trademark holder gives the following message:
We are unable to process Trademark Policy Violation Notices unless they are submitted by the trademark holder or an agent authorized to act on their behalf.
Hi, @brettz9. I'm glad you've migrated to node-static/node-static.
I notice the npm package is still 8 years without an updated version. I believe you can dispute ownership at NPM, too (I've done that in the past), and I recommend that for node-static.
I'd also recommend pushing a README update here, pointing users to the new repository.
Hi, @brettz9. I'm glad you've migrated to node-static/node-static.
I notice the npm package is still 8 years without an updated version. I believe you can dispute ownership at NPM, too (I've done that in the past), and I recommend that for node-static.
With GitHub being the new owners of npm, their reply about sunsetting their old policy allowing for such claims has been revoked. It is only allowed now for trademark violations.
I'd also recommend pushing a README update here, pointing users to the new repository.
Good idea. I've added such a note indicating the current status of the project with a link to the fork. (I wouldn't do this if the owner were objecting to my fork, but it just seems they are not available.)

Hey 馃憢 I notice its been a while since a new version of node-static has been pushed to NPM, and the version that currently exists there contains the package minimist which has a (github advisory) for it. This package was being used which is used by a package in this project called optimist. In this pull request, @brettz9 removed optimist to resolve this vulnerability. As a result, publishing a new version of
node-staticwill ensure that all users of this package will use a safe version by default.cc @cloudhead