Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Snyk has created this PR to upgrade multiple dependencies.
👯♂ The following dependencies are linked and will therefore be updated together.ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
hono
⚠️ This is a major version upgrade, and may be a breaking change | 21 days ago
⚠️ This is a major version upgrade, and may be a breaking change | 2 months ago
from 2.7.8 to 4.5.10 | 202 versions ahead of your current version
on 2024-08-31
typescript
from 4.9.5 to 5.5.4 | 595 versions ahead of your current version
on 2024-07-22
Issues fixed by the recommended upgrade:
SNYK-JS-HONO-6129070
SNYK-JS-HONO-6129121
SNYK-JS-HONO-6672874
SNYK-JS-HONO-7814167
Release notes
Package name: hono
What's Changed
New Contributors
Full Changelog: v4.5.9...v4.5.10
What's Changed
NO_COLOR
by @ ryuapp in #3306type
(MIME) attribute types by @ ssssota in #3305Full Changelog: v4.5.8...v4.5.9
Security Fix for CSRF Protection Middleware
Before this release, in versions 4.5.7 and below, the CSRF Protection Middleware did not treat requests including
Content-Types
with uppercase letters (e.g.,Application/x-www-form-urlencoded
) as potential attacks, allowing them to pass.This could cause unexpected behavior, leading to a vulnerability. If you are using the CSRF Protection Middleware, please upgrade to version 4.5.8 or higher immediately.
For more details, see the report here: GHSA-rpfr-3m35-5vx5
What's Changed
target
andformtarget
attribute types by @ ssssota in #3299New Contributors
Full Changelog: v4.5.6...v4.5.7
What's Changed
New Contributors
Full Changelog: v4.5.5...v4.5.6
What's Changed
c.header
by @ nakasyou in #3221c.header
by @ nakasyou in #3255.
and not end/
by @ yusukebe in #3256Full Changelog: v4.5.4...v4.5.5
What's Changed
param
inValidationTargets
supports optional param by @ yusukebe in #3229New Contributors
Full Changelog: v4.5.3...v4.5.4
What's Changed
application/json
with a charset as JSON by @ yusukebe in #3199self.fetch
correctly by @ yusukebe in #3200New Contributors
Full Changelog: v4.5.2...v4.5.3
What's Changed
navigator
isundefined
by @ yusukebe in #3171navigator
isundefined
by @ yusukebe in #3173Full Changelog: v4.5.1...v4.5.2
What's Changed
@ experimental
fromcreateApp
by @ yusukebe in #3164query
inws
by @ yusukebe in #3169New Contributors
Full Changelog: v4.5.0...v4.5.1
Package name: typescript
For release notes, check out the release announcement.
For the complete list of fixed issues, check out the
Downloads are available on:
For release notes, check out the release announcement.
For the complete list of fixed issues, check out the
Downloads are available on:
For release notes, check out the release announcement.
For the complete list of fixed issues, check out the
Downloads are available on: