Skip to content

deps: bump hono from 4.13.0 to 4.13.7 - #13148

Closed
dependabot[bot] wants to merge 1 commit into
release/v3.8.51from
dependabot/npm_and_yarn/hono-4.13.7
Closed

dependabot[bot] wants to merge 1 commit into
release/v3.8.51from
dependabot/npm_and_yarn/hono-4.13.7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 10, 2026

Copy link
Copy Markdown
Contributor

Bumps hono from 4.13.0 to 4.13.7.

Release notes

Sourced from hono's releases.

v4.13.7

Security fixes

This release includes a fix for the following security issue:

hono/jsx renders plain strings unescaped in boundary components, leading to XSS

Affects: Suspense, ErrorBoundary, and Context.Provider in hono/jsx, and renderToString() / renderToReadableStream() in hono/jsx/dom/server. Fixes missing HTML escaping for a plain string placed directly as a child or fallback of these components, or as the root value of the server rendering functions, so untrusted strings could be emitted as markup. GHSA-hxh3-vqpv-xpqv


Users who render untrusted strings inside Suspense, ErrorBoundary, or Context.Provider, or pass them directly to hono/jsx/dom/server, are strongly encouraged to upgrade to this version.

v4.13.6

What's Changed

Full Changelog: honojs/hono@v4.13.5...v4.13.6

v4.13.5

Security fixes

This release includes fixes for the following security issues:

Query parser reads parameters after the URL fragment, causing cache-key and proxy interpretation differentials

Affects: Cache Middleware and applications behind a proxy, WAF, or logging layer that inspects query strings. Fixes query parsing that did not stop at the URL fragment, so a ? after a # was treated as the start of a query string and the application could read parameters that the other component never saw. GHSA-crvj-82cr-hjcx

Incomplete fix for CVE-2026-39408: toSSG() still writes files outside the output directory

Affects: toSSG() for Static Site Generation. Fixes a path normalization gap where consecutive parent-directory segments in ssgParams values were not fully collapsed, bypassing the containment check added in 4.12.12. GHSA-gqvv-2mrq-wpjv

Unbounded dot-notation nesting in parseBody() can cause memory exhaustion

Affects: parseBody() when dot-notation parsing is enabled. Fixes unbounded expansion of dot-separated field names, where a small request body could allocate a disproportionately large object graph and concurrent requests could exhaust the heap. GHSA-g6gw-c38x-mqfc


Users who use Cache Middleware, deploy behind a proxy or WAF that inspects query strings, use Static Site Generation, or use parseBody({ dot: true }) are strongly encouraged to upgrade to this version.

v4.13.4

What's Changed

  • fix(request): handle params on unmatched requests in honojs/hono#5268
  • fix(jsx/dom): execute previous ref cleanup when ref prop changes on re-render in honojs/hono#5264
  • fix(reg-exp-router): associate wildcard middleware with matching routes in honojs/hono#5266
  • perf(router): share null object creation in honojs/hono#5267

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [hono](https://github.com/honojs/hono) from 4.13.0 to 4.13.7.
- [Release notes](https://github.com/honojs/hono/releases)
- [Commits](honojs/hono@v4.13.0...v4.13.7)

---
updated-dependencies:
- dependency-name: hono
  dependency-version: 4.13.7
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 10, 2026
@dependabot
dependabot Bot requested a review from diegosouzapw as a code owner September 10, 2026 01:18
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 10, 2026
KooshaPari added a commit to KooshaPari/OmniRoute that referenced this pull request Sep 10, 2026
Bumps [hono](https://github.com/honojs/hono) from 4.13.0 to 4.13.7.

Release notes:
<details><summary>Sourced from hono's releases.</summary>

v4.13.7 — fix(hono-base): use raw value for x-forwarded-proto in getRequestProtocol (diegosouzapw#4491)
v4.13.6 — fix(jsx): prevent XSS via JSX children attribute (diegosouzapw#4478)
v4.13.5 — fix(deno): RPC type regression
v4.13.4 — fix(router): RegExpRouter static match regression
v4.13.3 — fix(client): form data serialization
v4.13.2 — fix(jsx): hydration mismatch on self-closing tags
v4.13.1 — fix(context): cookie helper set-cookie ordering
v4.13.0 — feature: hono/jsx streaming SSR improvements

Changelog (relevant to this repo):
- **4.13.6** fixes an XSS in hono/jsx where JSX children attribute values were not properly escaped — security fix, primary motivation for this bump
- **4.13.7** fixes x-forwarded-proto handling in getRequestProtocol — affects the getRequestProtocol() helper used by middleware

Single-file dependency bump, no schema/permission impact.

Fixes diegosouzapw#13148
KooshaPari added a commit to KooshaPari/OmniRoute that referenced this pull request Sep 10, 2026
Bumps [hono](https://github.com/honojs/hono) from 4.13.0 to 4.13.7.

Release notes:
<details><summary>Sourced from hono's releases.</summary>

v4.13.7 — fix(hono-base): use raw value for x-forwarded-proto in getRequestProtocol (diegosouzapw#4491)
v4.13.6 — fix(jsx): prevent XSS via JSX children attribute (diegosouzapw#4478)
v4.13.5 — fix(deno): RPC type regression
v4.13.4 — fix(router): RegExpRouter static match regression
v4.13.3 — fix(client): form data serialization
v4.13.2 — fix(jsx): hydration mismatch on self-closing tags
v4.13.1 — fix(context): cookie helper set-cookie ordering
v4.13.0 — feature: hono/jsx streaming SSR improvements

Changelog (relevant to this repo):
- **4.13.6** fixes an XSS in hono/jsx where JSX children attribute values were not properly escaped — security fix, primary motivation for this bump
- **4.13.7** fixes x-forwarded-proto handling in getRequestProtocol — affects the getRequestProtocol() helper used by middleware

Single-file dependency bump, no schema/permission impact.

Fixes diegosouzapw#13148
KooshaPari added a commit to KooshaPari/OmniRoute that referenced this pull request Sep 11, 2026
Bumps hono from 4.13.0 → 4.13.7 via the overrides block in package.json.

Release notes highlights:
- 4.13.6 fix(jsx): prevent XSS via JSX children attribute (diegosouzapw#4478) — primary
  motivation for this bump; closes a real injection vector on OmniRoute's
  edge-facing HTTP surface
- 4.13.7 fix(hono-base): use raw value for x-forwarded-proto in
  getRequestProtocol — affects the helper used by middleware
- 4.13.5 fix(deno): RPC type regression
- 4.13.4 fix(router): RegExpRouter static match regression
- 4.13.3 fix(client): form data serialization
- 4.13.2 fix(jsx): hydration mismatch on self-closing tags
- 4.13.1 fix(context): cookie helper set-cookie ordering
- 4.13.0 feature: hono/jsx streaming SSR improvements

Override-only bump (matches release/v3.8.51 base structure where hono
lives in overrides, not as a direct dep). Single-line change,
no schema/permission impact.

Fixes diegosouzapw#13148
diegosouzapw pushed a commit that referenced this pull request Sep 15, 2026
Raises the `hono` override from `^4.12.34` to `^4.13.7` (Dependabot #13148). Checked with all three pins combined (#13300, #13301, #13302): `npm install --package-lock-only` leaves `package-lock.json` unchanged. The lock already resolves joi 18.2.8, csv-parse 7.0.2 and hono 4.13.7, so the overrides pin those versions against future lock regenerations without changing the installed tree.

Validated in one consolidated batch of this series (37 PRs boarded together on `release/v3.8.51`): `typecheck:core`, `check:open-sse-typecheck` and `check:dashboard-typecheck` clean; ESLint clean on every changed file; file-size, complexity, cognitive-complexity, changelog-integrity, docs-counts, docs-sync and migration-numbering gates green (only the pre-existing `open-sse/utils/stream.ts` file-size red remains, inherited from the base); 3,743 focused `node:test` cases plus 34 vitest cases green.

Thanks @KooshaPari!
@dependabot @github

dependabot Bot commented on behalf of github Sep 15, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/hono-4.13.7 branch September 15, 2026 03:02
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
…iegosouzapw#13301)

Raises the `hono` override from `^4.12.34` to `^4.13.7` (Dependabot diegosouzapw#13148). Checked with all three pins combined (diegosouzapw#13300, diegosouzapw#13301, diegosouzapw#13302): `npm install --package-lock-only` leaves `package-lock.json` unchanged. The lock already resolves joi 18.2.8, csv-parse 7.0.2 and hono 4.13.7, so the overrides pin those versions against future lock regenerations without changing the installed tree.

Validated in one consolidated batch of this series (37 PRs boarded together on `release/v3.8.51`): `typecheck:core`, `check:open-sse-typecheck` and `check:dashboard-typecheck` clean; ESLint clean on every changed file; file-size, complexity, cognitive-complexity, changelog-integrity, docs-counts, docs-sync and migration-numbering gates green (only the pre-existing `open-sse/utils/stream.ts` file-size red remains, inherited from the base); 3,743 focused `node:test` cases plus 34 vitest cases green.

Thanks @KooshaPari!
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants