Skip to content

chore(deps): bump hono from ^4.12.34 to ^4.13.7 (#13148) - #13301

Merged
diegosouzapw merged 1 commit into
diegosouzapw:release/v3.8.51from
KooshaPari:pr/13148-hono-bump
Sep 15, 2026
Merged

diegosouzapw merged 1 commit into
diegosouzapw:release/v3.8.51from
KooshaPari:pr/13148-hono-bump

Conversation

@KooshaPari

Copy link
Copy Markdown
Contributor

Summary

Fixes #13148

Bumps hono from ^4.12.34 to ^4.13.7 via the overrides block in package.json.

Why overrides (not direct dep)

On release/v3.8.51, hono lives in the overrides block — not in dependencies. The base structure uses overrides to pin a transitive dep that downstream sub-dependencies pull in. My first attempt added a spurious dependencies.hono entry that doesn't exist on base; this version is the single-line override-only bump that matches the actual base structure.

Changelog highlights (4.13.0 → 4.13.7)

Version Fix
4.13.6 fix(jsx): prevent XSS via JSX children attribute (#4478) — primary motivation
4.13.7 fix(hono-base): use raw value for x-forwarded-proto in getRequestProtocol
4.13.5 fix(deno): RPC type regression
4.13.4 fix(router): RegExpRouter static match regression
4.13.3 fix(client): form data serialization
4.13.2 fix(jsx): hydration mismatch on self-closing tags
4.13.1 fix(context): cookie helper set-cookie ordering
4.13.0 feature: hono/jsx streaming SSR improvements

Security note

4.13.6 fixes an XSS in hono/jsx where JSX children attribute values were not properly escaped. OmniRoute uses hono for its edge-facing HTTP surface, so this closes a real injection vector.

Diff

   "overrides": {
-    "hono": "^4.12.34",
+    "hono": "^4.13.7",
     "h2": "^3.4.4",
     ...
   }

Single-line change, matches base structure, no schema/permission impact.

Fixes #13148

Bumps hono from 4.13.0 → 4.13.7 via the overrides block in package.json.

Release notes highlights:
- 4.13.6 fix(jsx): prevent XSS via JSX children attribute (diegosouzapw#4478) — primary
  motivation for this bump; closes a real injection vector on OmniRoute's
  edge-facing HTTP surface
- 4.13.7 fix(hono-base): use raw value for x-forwarded-proto in
  getRequestProtocol — affects the helper used by middleware
- 4.13.5 fix(deno): RPC type regression
- 4.13.4 fix(router): RegExpRouter static match regression
- 4.13.3 fix(client): form data serialization
- 4.13.2 fix(jsx): hydration mismatch on self-closing tags
- 4.13.1 fix(context): cookie helper set-cookie ordering
- 4.13.0 feature: hono/jsx streaming SSR improvements

Override-only bump (matches release/v3.8.51 base structure where hono
lives in overrides, not as a direct dep). Single-line change,
no schema/permission impact.

Fixes diegosouzapw#13148
Copilot AI lite review requested due to automatic review settings September 11, 2026 00:12

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

diegosouzapw pushed a commit that referenced this pull request Sep 15, 2026
Pins `csv-parse` to `^7.0.2` via `overrides` (Dependabot #13117). Checked with all three pins combined (#13300, #13301, #13302): `npm install --package-lock-only` leaves `package-lock.json` unchanged. The lock already resolves joi 18.2.8, csv-parse 7.0.2 and hono 4.13.7, so the overrides pin those versions against future lock regenerations without changing the installed tree.

Validated in one consolidated batch of this series (37 PRs boarded together on `release/v3.8.51`): `typecheck:core`, `check:open-sse-typecheck` and `check:dashboard-typecheck` clean; ESLint clean on every changed file; file-size, complexity, cognitive-complexity, changelog-integrity, docs-counts, docs-sync and migration-numbering gates green (only the pre-existing `open-sse/utils/stream.ts` file-size red remains, inherited from the base); 3,743 focused `node:test` cases plus 34 vitest cases green.

Thanks @KooshaPari!
@diegosouzapw
diegosouzapw merged commit 6a55d0a into diegosouzapw:release/v3.8.51 Sep 15, 2026
8 of 16 checks passed
diegosouzapw pushed a commit that referenced this pull request Sep 15, 2026
Pins `joi` to `^18.2.8` via `overrides` (Dependabot #13085). Checked with all three pins combined (#13300, #13301, #13302): `npm install --package-lock-only` leaves `package-lock.json` unchanged. The lock already resolves joi 18.2.8, csv-parse 7.0.2 and hono 4.13.7, so the overrides pin those versions against future lock regenerations without changing the installed tree.

Validated in one consolidated batch of this series (37 PRs boarded together on `release/v3.8.51`): `typecheck:core`, `check:open-sse-typecheck` and `check:dashboard-typecheck` clean; ESLint clean on every changed file; file-size, complexity, cognitive-complexity, changelog-integrity, docs-counts, docs-sync and migration-numbering gates green (only the pre-existing `open-sse/utils/stream.ts` file-size red remains, inherited from the base); 3,743 focused `node:test` cases plus 34 vitest cases green.

Thanks @KooshaPari!
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
… (diegosouzapw#13300)

Pins `csv-parse` to `^7.0.2` via `overrides` (Dependabot diegosouzapw#13117). Checked with all three pins combined (diegosouzapw#13300, diegosouzapw#13301, diegosouzapw#13302): `npm install --package-lock-only` leaves `package-lock.json` unchanged. The lock already resolves joi 18.2.8, csv-parse 7.0.2 and hono 4.13.7, so the overrides pin those versions against future lock regenerations without changing the installed tree.

Validated in one consolidated batch of this series (37 PRs boarded together on `release/v3.8.51`): `typecheck:core`, `check:open-sse-typecheck` and `check:dashboard-typecheck` clean; ESLint clean on every changed file; file-size, complexity, cognitive-complexity, changelog-integrity, docs-counts, docs-sync and migration-numbering gates green (only the pre-existing `open-sse/utils/stream.ts` file-size red remains, inherited from the base); 3,743 focused `node:test` cases plus 34 vitest cases green.

Thanks @KooshaPari!
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
…iegosouzapw#13301)

Raises the `hono` override from `^4.12.34` to `^4.13.7` (Dependabot diegosouzapw#13148). Checked with all three pins combined (diegosouzapw#13300, diegosouzapw#13301, diegosouzapw#13302): `npm install --package-lock-only` leaves `package-lock.json` unchanged. The lock already resolves joi 18.2.8, csv-parse 7.0.2 and hono 4.13.7, so the overrides pin those versions against future lock regenerations without changing the installed tree.

Validated in one consolidated batch of this series (37 PRs boarded together on `release/v3.8.51`): `typecheck:core`, `check:open-sse-typecheck` and `check:dashboard-typecheck` clean; ESLint clean on every changed file; file-size, complexity, cognitive-complexity, changelog-integrity, docs-counts, docs-sync and migration-numbering gates green (only the pre-existing `open-sse/utils/stream.ts` file-size red remains, inherited from the base); 3,743 focused `node:test` cases plus 34 vitest cases green.

Thanks @KooshaPari!
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
…iegosouzapw#13302)

Pins `joi` to `^18.2.8` via `overrides` (Dependabot diegosouzapw#13085). Checked with all three pins combined (diegosouzapw#13300, diegosouzapw#13301, diegosouzapw#13302): `npm install --package-lock-only` leaves `package-lock.json` unchanged. The lock already resolves joi 18.2.8, csv-parse 7.0.2 and hono 4.13.7, so the overrides pin those versions against future lock regenerations without changing the installed tree.

Validated in one consolidated batch of this series (37 PRs boarded together on `release/v3.8.51`): `typecheck:core`, `check:open-sse-typecheck` and `check:dashboard-typecheck` clean; ESLint clean on every changed file; file-size, complexity, cognitive-complexity, changelog-integrity, docs-counts, docs-sync and migration-numbering gates green (only the pre-existing `open-sse/utils/stream.ts` file-size red remains, inherited from the base); 3,743 focused `node:test` cases plus 34 vitest cases green.

Thanks @KooshaPari!
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants