Skip to content

chore(deps): bump hono from 4.12.23 to 4.12.34 - #462

Open
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/npm_and_yarn/hono-4.12.34
Open

chore(deps): bump hono from 4.12.23 to 4.12.34#462
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/npm_and_yarn/hono-4.12.34

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 4, 2026

Copy link
Copy Markdown
Contributor

Bumps hono from 4.12.23 to 4.12.34.

Release notes

Sourced from hono's releases.

v4.12.34

Security fixes

This release includes fixes for the following security issues:

memo() retains SSR output across requests, leading to cross-user data disclosure

Affects: hono/jsx (server-side rendering). Fixes memo() reusing a retained render result across requests when props compare equal, where a component reading request-scoped values from ambient context — useContext(), useRequestContext(), or getContext() — could serve HTML rendered for another user's request, disclosing account data or request-scoped secrets such as CSRF tokens. GHSA-f23p-vx2j-j53r

ReDoS in CORS middleware via Access-Control-Request-Headers

Affects: hono/cors. Fixes a whitespace-tolerant regular expression with quadratic backtracking used to parse the Access-Control-Request-Headers preflight header when allowHeaders is not configured (the default), where a single preflight request carrying a long whitespace run could consume seconds of CPU and stall request processing. GHSA-8j4g-w8fx-2239

Algorithmic complexity DoS in Language Middleware

Affects: hono/language. Fixes quadratic string processing in language-tag normalization, where a crafted language tag with a large number of hyphen-separated subtags — supplied via a query parameter, cookie, or Accept-Language header — could cause excessive CPU consumption and block the event loop. GHSA-54fx-42gc-7vw4

Proxy Helper does not remove response headers listed in the Connection header

Affects: hono/proxy. Fixes proxy() forwarding response headers that the origin's Connection header designates as connection-scoped, where headers intended only for the immediate peer — per RFC 9110 Section 7.6.1 — could be exposed to clients, disclosing connection-scoped or internal metadata. GHSA-79qm-7rj5-m7r9


Users who use hono/jsx for server-side rendering, hono/cors, hono/language, or hono/proxy are strongly encouraged to upgrade to this version.

v4.12.33

What's Changed

Full Changelog: honojs/hono@v4.12.32...v4.12.33

v4.12.32

What's Changed

  • ci: enable reports for type & bundle size check in honojs/hono#5148
  • fix(aws-lambda): add jwt and lambda authorizer types for API Gateway v2 in honojs/hono#5142
  • fix(sse): emit empty id field to reset Last-Event-ID in honojs/hono#5138
  • test(cloudflare-workers): add coverage for onClose, onError, send, and close in Cloudflare Workers websocket adapter in honojs/hono#5145
  • fix: use Object.create(null) when parsing query, headers, and params in honojs/hono#5161
  • fix(secure-headers): keep CSP callbacks scoped to their header in honojs/hono#5147

Full Changelog: honojs/hono@v4.12.31...v4.12.32

v4.12.31

What's Changed

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for hono since your current version.


@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 4, 2026
@dependabot
dependabot Bot requested a review from tomymaritano as a code owner August 4, 2026 14:21
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 4, 2026
@github-actions
github-actions Bot enabled auto-merge (squash) August 4, 2026 14:21
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/hono-4.12.34 branch 14 times, most recently from ce24012 to a87ec65 Compare August 20, 2026 18:24
tomymaritano added a commit that referenced this pull request Aug 22, 2026
<!-- CURSOR_AGENT_PR_BODY_BEGIN -->
## Summary

Dependabot PRs fail the required `e2e` check in ~20s during `pnpm
install`, not during Playwright. Automerge is already enabled; it cannot
land while e2e is red.

**Exact failure** (PR #482 job
[96541625973](https://github.com/dripnex/app/actions/runs/32404870524/job/96541625973),
also #464 / #456 / #462 and `commitlint` on #464):

```
ERROR  Command failed with exit code 128: git clone git@github.com:electron/node-gyp.git ...
git@github.com: Permission denied (publickey).
```

This is not missing repo secrets. Dependabot-regenerated lockfiles
resolve `@electron/node-gyp` as a git dep whose `resolution.repo` is
SSH:

```
# PR #456 (shell-quote) lockfile
'@electron/node-gyp@git+https://git@github.com:electron/node-gyp.git#06b29aa...'
resolution: {commit: 06b29aa..., repo: git@github.com:electron/node-gyp.git, type: git}

# develop lockfile (e2e green after #541)
'@electron/node-gyp@https://codeload.github.com/electron/node-gyp/tar.gz/06b29aa...'
resolution: {tarball: https://codeload.github.com/electron/node-gyp/tar.gz/06b29aa...}
```

pnpm clones `resolution.repo` over SSH. GitHub-hosted runners have no
deploy key.

The `setup` job already rewrites SSH to HTTPS and therefore succeeds on
the same PRs. `e2e` and `commitlint` did a fresh `pnpm install` without
that rewrite.

`develop` itself is green after #541 — its lockfile uses the HTTPS
tarball, so e2e never hits the SSH clone.

## Type of Change

- [x] Bug fix
- [ ] New feature
- [ ] Breaking change
- [ ] Documentation update

## Fix

Add the same `git config --global 'url.https://github.com/.insteadOf'
'git@github.com:'` step that `setup` / `release` / `build` / `docs`
already use:

- `.github/workflows/ci.yml` `e2e` job — unblocks the required e2e check
- `.github/workflows/pr-title.yml` — same SSH death on Dependabot
lockfiles

Existing Dependabot PRs (#482, #464, #462, #460, #459, #456, #451, #431,
#430, #248) should go green after rebase onto this `develop` change (the
merge commit picks up the workflow).

## Related Issues

Closes #544

## Checklist

- [x] I've read [CONTRIBUTING.md](../CONTRIBUTING.md)
- [ ] Tests pass locally (`pnpm test`) — workflow-only change; no
product code
- [ ] Build succeeds (`pnpm build`) — not applicable
- [x] PR targets `develop` branch (not `main`)

<!-- CURSOR_AGENT_PR_BODY_END -->

<div><a
href="https://cursor.com/agents/bc-65d9f024-2af5-4bbe-8318-35ae4db127d2?cursor_ref=pr_footer&cursor_cta=open_in_web"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://cursor.com/assets/images/open-in-web-dark.png"><source
media="(prefers-color-scheme: light)"
srcset="https://cursor.com/assets/images/open-in-web-light.png"><img
alt="Open in Web" width="114" height="28"
src="https://cursor.com/assets/images/open-in-web-dark.png"></picture></a>&nbsp;<a
href="https://cursor.com/background-agent?bcId=bc-65d9f024-2af5-4bbe-8318-35ae4db127d2&cursor_ref=pr_footer&cursor_cta=open_in_cursor"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://cursor.com/assets/images/open-in-cursor-dark.png"><source
media="(prefers-color-scheme: light)"
srcset="https://cursor.com/assets/images/open-in-cursor-light.png"><img
alt="Open in Cursor" width="131" height="28"
src="https://cursor.com/assets/images/open-in-cursor-dark.png"></picture></a>&nbsp;</div>

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/hono-4.12.34 branch 4 times, most recently from 8df1731 to 59b3913 Compare August 26, 2026 14:23
Bumps [hono](https://github.com/honojs/hono) from 4.12.23 to 4.12.34.
- [Release notes](https://github.com/honojs/hono/releases)
- [Commits](honojs/hono@v4.12.23...v4.12.34)

---
updated-dependencies:
- dependency-name: hono
  dependency-version: 4.12.34
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/hono-4.12.34 branch from 59b3913 to 9e7bf83 Compare August 29, 2026 00:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code package:api size/M

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants