Skip to content

Bump hono from 4.13.7 to 4.13.11 - #136

Merged
Krakabek merged 1 commit into
mainfrom
dependabot/npm_and_yarn/hono-4.13.10
Sep 29, 2026
Merged

Krakabek merged 1 commit into
mainfrom
dependabot/npm_and_yarn/hono-4.13.10

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Bumps hono from 4.13.7 to 4.13.11.

Release notes

Sourced from hono's releases.

v4.13.11

Security fixes

serveStatic decodes the request path a second time, leading to bypass of middleware on static paths

Affects: hono/serve-static and the adapters built on it (hono/bun, hono/deno, hono/cloudflare-workers, @hono/bun, @hono/deno, @hono/cloudflare-workers). Fixes serveStatic decoding an already-decoded path, where a crafted request could be routed as one path and served as another, skipping middleware mounted on a static prefix. GHSA-5r4p-p66f-jhc7

serveStatic now rejects request paths that still contain % after decoding. To serve files whose names contain a literal %, set allowPercentInPath: true.

The same fix ships in @hono/node-server v2.1.3.

v4.13.10

Adapters are now separate packages

The runtime adapters are now published as their own packages: @hono/bun, @hono/deno, @hono/cloudflare-workers, @hono/aws-lambda, @hono/lambda-edge, @hono/netlify, @hono/vercel, and @hono/service-worker. @hono/deno is also on JSR.

hono/<adapter> still works in v4 but is deprecated and will be removed in v5. Migrating is an import change:

- import { serveStatic } from 'hono/bun'
+ import { serveStatic } from '@hono/bun'

hono/cloudflare-pages is deprecated without a replacement package; Cloudflare recommends Workers with static assets.

What's Changed

Full Changelog: honojs/hono@v4.13.9...v4.13.10

v4.13.9

What's Changed

  • fix(jsx): replace Suspense and ErrorBoundary content across newlines in honojs/hono#5380

... (truncated)

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 28, 2026
@dependabot dependabot Bot changed the title Bump hono from 4.13.7 to 4.13.10 Bump hono from 4.13.7 to 4.13.11 Sep 29, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/hono-4.13.10 branch from 67c906d to df7f21b Compare September 29, 2026 13:52
Bumps [hono](https://github.com/honojs/hono) from 4.13.7 to 4.13.11.
- [Release notes](https://github.com/honojs/hono/releases)
- [Commits](honojs/hono@v4.13.7...v4.13.11)

---
updated-dependencies:
- dependency-name: hono
  dependency-version: 4.13.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/hono-4.13.10 branch from df7f21b to 3c81a7a Compare September 29, 2026 13:57
@Krakabek
Krakabek merged commit 38bc223 into main Sep 29, 2026
1 check passed
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/hono-4.13.10 branch September 29, 2026 14:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Development

Successfully merging this pull request may close these issues.

1 participant