Skip to content

fix(deps): bump hono 4.12.21→4.12.28 (clears 18 Dependabot security alerts)#50

Open
mastermanas805 wants to merge 1 commit into
masterfrom
fix/hono-security-bump
Open

fix(deps): bump hono 4.12.21→4.12.28 (clears 18 Dependabot security alerts)#50
mastermanas805 wants to merge 1 commit into
masterfrom
fix/hono-security-bump

Conversation

@mastermanas805

Copy link
Copy Markdown
Member

Summary

Bumps hono from 4.12.21 → 4.12.28 and @hono/node-server 1.19.9 → 1.19.14 (transitive, pulled in via @modelcontextprotocol/sdk).

Clears all 18 open Dependabot security alerts:

Alert Severity Fixed in
CORS middleware reflects any Origin with credentials high 4.12.25
Body limit bypass on AWS Lambda medium 4.12.25
Lambda@Edge drops repeated request headers medium 4.12.25
Set-Cookie header merge bug on ALB single-header medium 4.12.25
Path traversal via encoded backslash on Windows medium 4.12.25
Alerts #1#13 low–medium already fixed (ip-address/fast-uri/qs were at safe versions; alerts were stale)

Test plan

  • npm test — 497 pass, 0 fail, coverage unchanged
  • npm audit — 0 vulnerabilities after update

🤖 Generated with Claude Code

…9.14

Clears 5 open Dependabot security alerts (alerts #14#18):
- CORS middleware reflects any Origin with credentials (high)
- Body limit bypass on AWS Lambda (medium)
- Lambda@Edge drops repeated headers (medium)
- Set-Cookie header merge on ALB (medium)
- Path traversal via encoded backslash on Windows (medium)

Also resolves alerts #1#13 which were already fixed by the 4.12.21
install but had not been dismissed by Dependabot (ip-address 10.2.0,
fast-uri 3.1.2, qs 6.15.2 were already at safe versions).

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant