Skip to content

chore(deps): bump hono from 4.12.31 to 4.13.0 in /workspaces/scorecard - #4153

Merged
kim-tsao merged 1 commit into
mainfrom
dependabot/npm_and_yarn/workspaces/scorecard/hono-4.13.0
Aug 7, 2026
Merged

chore(deps): bump hono from 4.12.31 to 4.13.0 in /workspaces/scorecard#4153
kim-tsao merged 1 commit into
mainfrom
dependabot/npm_and_yarn/workspaces/scorecard/hono-4.13.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 4, 2026

Copy link
Copy Markdown
Contributor

Bumps hono from 4.12.31 to 4.13.0.

Release notes

Sourced from hono's releases.

v4.13.0

Hono v4.13.0 is now available!

The highlight of this release is performance: a batch of low-level optimizations makes the core request/response path significantly faster — up to 1.25x on common routes in our benchmark. This release also adds first-class support for the HTTP QUERY method, defined in RFC 10008, a new Method Not Allowed middleware, and more.

Performance improvements

This release includes a series of small optimizations: skipping unnecessary Headers allocations, replacing regex tests with indexOf, allocating internal state lazily, and more.

Here is benchmarks/fetch comparing v4.12 and v4.13 (ROUNDS=5 ./compare.sh, Bun 1.4.0, Apple Silicon — each measurement runs in a fresh process, and the variant order is reversed every round to avoid warm-up bias):

Benchmark v4.12 v4.13 Speedup
pingGET / 165.83 ns 163.99 ns 1.01x
queryGET /id/1?name=bun 674.40 ns 616.99 ns 1.09x
jsonGET /user 528.99 ns 422.44 ns 1.25x
bodyPOST /json 1.16 µs 1.00 µs 1.15x

The individual changes:

In addition, the RegExpRouter rewrite described below makes route registration plus the first match roughly 20% faster.

Thanks @​kibertoad for the contributions!

First-class QUERY method support

The QUERY method — a safe, idempotent method that carries a request body — is now a first-class citizen in Hono. You can define QUERY handlers with app.query():

const app = new Hono()
app.query('/search', async (c) => {
const conditions = await c.req.json()
return c.json(await search(conditions))
})

Thanks @​shellhaki!

QUERY support across built-in middleware

The built-in middleware has been updated to handle QUERY requests properly:

... (truncated)

Commits
  • 192768f 4.13.0
  • b0c2d90 Merge pull request #5154 from honojs/next
  • 8f07028 fix(compress): set Vary: Accept-Encoding on negotiated responses (#5137)
  • 8a0b18f feat(reg-exp-router): throw UnsupportedPathError during route registration (#...
  • 3feb355 fix(jsx): allow a function component to return an array (#5179)
  • 5d911d2 feat(utils/headers): add HTTP fields newly registered with IANA (#5153)
  • 30277ae feat(jwt,jwk): add a configurable WWW-Authenticate realm (#5141)
  • 1f707c5 feat(middleware): add method-not-allowed middleware (#5132)
  • 2df0b47 feat(jsx): add React-compatible overloads to useRef (#5063)
  • 3bc96ba feat(cache): add first-class support for QUERY requests (#5119)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [hono](https://github.com/honojs/hono) from 4.12.31 to 4.13.0.
- [Release notes](https://github.com/honojs/hono/releases)
- [Commits](honojs/hono@v4.12.31...v4.13.0)

---
updated-dependencies:
- dependency-name: hono
  dependency-version: 4.13.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 4, 2026
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Aug 4, 2026
@dependabot dependabot Bot added the javascript Pull requests that update javascript code label Aug 4, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner August 4, 2026 07:13
@sonarqubecloud

sonarqubecloud Bot commented Aug 4, 2026

Copy link
Copy Markdown

@kim-tsao
kim-tsao merged commit e632466 into main Aug 7, 2026
28 checks passed
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/workspaces/scorecard/hono-4.13.0 branch August 7, 2026 16:59
@fullsend-ai-retro

fullsend-ai-retro Bot commented Aug 7, 2026

Copy link
Copy Markdown

🤖 Finished Retro · ✅ Success · Started 5:00 PM UTC · Completed 5:08 PM UTC

Commit: 1ffd1ac · View workflow run →

@fullsend-ai-retro

Copy link
Copy Markdown

Retro: PR #4153 — Dependabot hono bump in scorecard

Workflow outcome: This was a trivial Dependabot PR bumping hono 4.12.31→4.13.0 in /workspaces/scorecard. Only yarn.lock changed (3 additions, 3 deletions). The routing logic correctly skipped all code, review, triage, and fix agents across three fullsend.yaml triggers. kim-tsao approved and merged after 3 days. SonarQube passed with zero issues.

One inefficiency: The retro agent was dispatched post-merge (run 31200223436) despite zero agent involvement on this PR. There is no agent workflow to retrospect on — the only substantive observation is that this retro run itself shouldn't have been triggered. This wastes tokens and compute for no actionable output.

No new proposals filed. This finding is extensively covered by existing open issues in fullsend-ai/fullsend:

  • #5817 — Consolidate 22+ overlapping "skip retro/agent dispatch" issues into a single design issue (the meta-issue tracking all related proposals)
  • #5295 — Skip retro dispatch for bot-authored PRs with zero agent involvement
  • #5399 — Skip retro dispatch for merged PRs with zero meaningful agent involvement
  • #3226 — Skip retro agent for bot-authored trivial PRs with no agent interaction
  • #6007 — Fix agent guard misidentifies GitHub App bot PRs as human-authored

This PR provides additional evidence for these issues: a 3-line Dependabot lockfile change with zero agent involvement still triggered a full retro analysis. The agents repo is fullsend-ai/agents (pinned at 4bbe4f5), and the retro agent has no repo-specific harness override in this repo's .fullsend/rhdh/harness/ directory — it uses upstream defaults, so the fix belongs upstream in the dispatch routing logic.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code workspace/scorecard

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant