Skip to content

deps: bump hono from 4.11.5 to 4.12.18 - #66

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/hono-4.12.18
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/hono-4.12.18

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 9, 2026

Copy link
Copy Markdown
Contributor

Bumps hono from 4.11.5 to 4.12.18.

Release notes

Sourced from hono's releases.

v4.12.18

Security fixes

This release includes fixes for the following security issues:

Cache Middleware ignores Vary: Authorization / Vary: Cookie leading to cross-user cache leakage

Affects: Cache Middleware. Fixes missing cache-skip handling for Vary: Authorization and Vary: Cookie, where a response cached for one authenticated user could be served to other users. GHSA-p77w-8qqv-26rm

CSS Declaration Injection via Style Object Values in JSX SSR

Affects: hono/jsx. Fixes a missing CSS-context escape for style object values and property names, where untrusted input could inject additional CSS declarations. The impact is limited to CSS and does not allow JavaScript execution. GHSA-qp7p-654g-cw7p

Improper validation of NumericDate claims (exp, nbf, iat) in JWT verify()

Affects: hono/utils/jwt. Fixes improper validation of exp, nbf, and iat claims, where falsy, non-finite, or non-numeric values could silently bypass time-based checks instead of being rejected per RFC 7519. GHSA-hm8q-7f3q-5f36


Users who use the JWT helper, hono/jsx, or the Cache middleware are strongly encouraged to upgrade to this version.

v4.12.17

What's Changed

New Contributors

Full Changelog: honojs/hono@v4.12.16...v4.12.17

v4.12.16

Security fixes

This release includes fixes for the following security issues:

Unvalidated JSX Tag Names in hono/jsx May Allow HTML Injection

Affects: hono/jsx. Fixes missing validation of JSX tag names when using jsx() or createElement(), which could allow HTML injection if untrusted input is used as the tag name. GHSA-69xw-7hcm-h432

bodyLimit() can be bypassed for chunked / unknown-length requests

Affects: Body Limit Middleware. Fixes late enforcement for request bodies without a reliable Content-Length (e.g. chunked requests), where oversized requests could reach handlers and return successful responses before being rejected. GHSA-9vqf-7f2p-gf9v

v4.12.15

What's Changed

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [hono](https://github.com/honojs/hono) from 4.11.5 to 4.12.18.
- [Release notes](https://github.com/honojs/hono/releases)
- [Commits](honojs/hono@v4.11.5...v4.12.18)

---
updated-dependencies:
- dependency-name: hono
  dependency-version: 4.12.18
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github May 9, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@robotlearning123

Copy link
Copy Markdown
Member

Backlog-loop verification: checks/tests green except pre-existing base failures (delta: failing checks at head vs base: 1 vs 1, same check claude-review). Independent review: REQUEST_CHANGES.

Refs. Head 174b7a88535598d992b1c1c7300b0d047c62840c (dependabot/npm_and_yarn/hono-4.12.18, 1 commit) vs base ce7da5b151473a7c01b688d116284ba60056c5be = current origin/main tip, so this is an exact baseline comparison. git diff --stat ce7da5b HEAD = package-lock.json | 19 ++++++------------- (1 file, +6/−13); the only dependency version that changes is hono 4.11.5 → 4.12.18.

Check delta: 1 failing check at head vs 1 at base — same check, claude-review. gh pr view 66 --json statusCheckRollup = 8 SUCCESS + 1 FAILURE (claude-review). There is no base-side PR rollup of its own, and the same workflow is red repo-wide, independent of this diff: the "Claude Code Review" workflow has 59 all-time runs, all pull_request events — 52 failure / 2 action_required / 5 success; all 5 successes are 2026-01-28/29 and no run has succeeded since. It currently fails on every other open PR that ran it (#48, #50, #51, #53, #54, #55, #56, #59, #60, #63, #65, #68, #69, #70, #72, #73, #75 — 17 others; #71 has no check; #74 is closed). The failure is an actor-policy condition, not code — verbatim annotation on this head:

Action failed with error: Workflow initiated by non-human actor: dependabot (type: Bot). Add bot to allowed_bots list or use '*' to allow all bots.

Measured gates, base vs head (executed at both refs on 2026-09-23; node v22.22.0 / npm 10.9.4):

gate base ce7da5b head 174b7a8
npm ci exit 0 exit 0
npm test 57 pass / 0 fail 57 pass / 0 fail
npm run typecheck exit 0 exit 0
npm run build exit 0 exit 0
npm audit --package-lock-only totals 19 (1 low / 8 moderate / 10 high) 19 (1 low / 8 moderate / 10 high)
hono advisories in range (npm audit via count) 37 19
hono installed 4.11.5 4.12.18

npm view hono version = 4.13.8; hono is still flagged HIGH at head (audit range <=4.13.4). Net: −18 hono advisories, zero regressions — the PR is a strict improvement on dependency advisory count and neutral on every other measured gate.

Independent review — REQUEST_CHANGES (grok, headless, exit 0, pinned to head 174b7a8). Findings below, each re-verified here against primary sources (GitHub advisory API, npm registry, installed SDK tarball):

  1. [confirmed, substantive] The bump does not land on a fully patched hono. 4.12.18 is itself inside the affected range of later advisories: GHSA-hvrm-45r6-mjfj (medium, pub 2026-07-21, >= 4.11.8, < 4.12.27) and GHSA-54fx-42gc-7vw4 (medium, pub 2026-08-07, >= 4.12.0, < 4.12.34) — neither range covers the outgoing 4.11.5, so this bump newly enters both; GHSA-88fw-hqm2-52qc is HIGH (CORS middleware reflects any Origin with credentials, pub 2026-06-16, < 4.12.25); GHSA-gqvv-2mrq-wpjv / GHSA-g6gw-c38x-mqfc / GHSA-crvj-82cr-hjcx (all medium, all pub 2026-09-08, all < 4.13.5). Computed over the full advisory set affecting npm:hono (50 advisories): 4.11.5 → 37 in range; 4.12.18 → 19 in range (incl. the HIGH); 4.13.5 → 0; 4.13.8 → 0. @hono/node-server's peer range is hono: ^4 (package-lock.json:675), so retargeting the single hoisted entry to >= 4.13.5 is range-compatible.

  2. [confirmed, context] The test suite cannot validate this pin either way. package.json:32 = "test": "tsx --test test/*.test.ts"; a transitive lockfile pin is invisible to it. The only SDK surface imported repo-wide is @modelcontextprotocol/sdk/server/mcp.js + .../server/stdio.js (packages/mcp/src/index.ts:13-14), and neither file references hono (checked in the installed 1.25.3 tarball). Refinement: the SDK does import hono elsewhere (dist/esm/server/streamableHttp.js:9 imports getRequestListener from @hono/node-server), so the accurate claim is "hono is not on the code path this repo imports", not "the SDK never uses hono". This is not a blocker for a dependabot lockfile PR — but "tests green" carries no information about this pin.

  3. [confirmed] Unrelated lockfile churn rides along. Root version 0.1.0 → 0.2.0 at package-lock.json:3 and :9 (base package.json is already 0.2.0, so this repairs pre-existing drift); 8 "peer": true removals — exactly: @opentelemetry/api, @typescript-eslint/parser, acorn, eslint, express, tinyglobby/node_modules/picomatch, typescript, zod (base lines 896 / 1093 / 1311 / 2011 / 2248 / 4324 / 4420 / 4722); and one "peer": true addition for hono (head line 2644; hono's only edge is the peer at :675). No other resolved version changes.

Proportionality: finding 1 is the substantive one; finding 3 is the same regenerated-lockfile churn seen on sibling dependabot PRs (e.g. #65), not specific to this PR; finding 2 is context.

Recommended action (evidence-backed; not executed — this head is a foreign dependabot branch, review-only): retarget the single hoisted hono entry to the latest in-range release (>= 4.13.5, i.e. 4.13.8), which by the computed advisory set clears all remaining in-range advisories; alternatively merge as-is and accept partial remediation (19 advisories incl. one HIGH remain). The claude-review failure needs an owner decision on the repo's actor policy before any merge can go green.

Cross-PR note (verified). PR #65 (fast-uri) carries the same lockfile churn (root version + peer flags) and 9 of its 10 diff hunks sit at identical base coordinates. Both PRs are individually MERGEABLE, and a 3-way merge of the two heads is clean (git merge-tree --write-tree 3352908a 174b7a8 exit 0) — still, whichever lands first rewrites main's lockfile, so re-check the other's mergeability afterwards.

Evidence provenance: every number above was re-verified on 2026-09-23 by direct execution at both refs (fresh detached worktrees; node v22.22.0 / npm 10.9.4); advisory data from the GitHub advisory API, version data from the npm registry. Review-only pass on a foreign (dependabot) head: no merge, no approval, no push, no branch write.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant