Skip to content

chore(deps): update dependency hono to v4.12.23#121

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/hono-4.x-lockfile
Open

chore(deps): update dependency hono to v4.12.23#121
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/hono-4.x-lockfile

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented Apr 24, 2026

This PR contains the following updates:

Package Change Age Confidence
hono (source) 4.12.144.12.23 age confidence

Release Notes

honojs/hono (hono)

v4.12.23

Compare Source

What's Changed

Full Changelog: honojs/hono@v4.12.22...v4.12.23

v4.12.22

Compare Source

What's Changed
New Contributors

Full Changelog: honojs/hono@v4.12.21...v4.12.22

v4.12.21

Compare Source

Security fixes

This release includes fixes for the following security issues:

app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded paths

Affects: app.mount(). Fixes prefix stripping using the raw URL pathname instead of the decoded path, where percent-encoded characters in the mount prefix or path could cause the prefix to be removed at the wrong position, resulting in the sub-application receiving an incorrect path. GHSA-2gcr-mfcq-wcc3

IP Restriction bypasses static deny rules for non-canonical IPv6

Affects: hono/ip-restriction. Fixes IP address comparison using string equality, where non-canonical IPv6 representations of a denied address — such as compressed forms or hex-notation IPv4-mapped addresses — could bypass static deny rules. GHSA-xrhx-7g5j-rcj5

Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injection

Affects: hono/cookie. Fixes missing validation of sameSite and priority options against injection characters (;, \r, \n), where user-controlled input passed to either option could inject additional attributes into the Set-Cookie response header. GHSA-3hrh-pfw6-9m5x

JWT middleware accepts any Authorization scheme, not only Bearer

Affects: hono/jwt, hono/jwk. Fixes missing scheme validation in the Authorization header, where any two-part header value was accepted regardless of the scheme name, allowing non-Bearer schemes to pass JWT authentication. GHSA-f577-qrjj-4474


Users who use app.mount(), hono/ip-restriction, hono/cookie, or hono/jwt/hono/jwk are encouraged to upgrade to this version.

v4.12.20

Compare Source

What's Changed
New Contributors

Full Changelog: honojs/hono@v4.12.19...v4.12.20

v4.12.19

Compare Source

What's Changed

New Contributors

Full Changelog: honojs/hono@v4.12.18...v4.12.19

v4.12.18

Compare Source

v4.12.17

Compare Source

v4.12.16

Compare Source

Security fixes

This release includes fixes for the following security issues:

Unvalidated JSX Tag Names in hono/jsx May Allow HTML Injection

Affects: hono/jsx. Fixes missing validation of JSX tag names when using jsx() or createElement(), which could allow HTML injection if untrusted input is used as the tag name. GHSA-69xw-7hcm-h432

bodyLimit() can be bypassed for chunked / unknown-length requests

Affects: Body Limit Middleware. Fixes late enforcement for request bodies without a reliable Content-Length (e.g. chunked requests), where oversized requests could reach handlers and return successful responses before being rejected. GHSA-9vqf-7f2p-gf9v

v4.12.15

Compare Source

What's Changed
New Contributors

Full Changelog: honojs/hono@v4.12.14...v4.12.15


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.12.15 Update dependency hono to v4.12.15 Apr 25, 2026
@renovate renovate Bot changed the title Update dependency hono to v4.12.15 chore(deps): update dependency hono to v4.12.15 Apr 27, 2026
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.12.15 Update dependency hono to v4.12.15 Apr 29, 2026
@renovate renovate Bot force-pushed the renovate/hono-4.x-lockfile branch from f719c0d to 69dc401 Compare April 29, 2026 15:56
@renovate renovate Bot changed the title Update dependency hono to v4.12.15 Update dependency hono to v4.12.16 Apr 30, 2026
@renovate renovate Bot force-pushed the renovate/hono-4.x-lockfile branch from 69dc401 to a50e754 Compare April 30, 2026 11:01
@renovate renovate Bot changed the title Update dependency hono to v4.12.16 chore(deps): update dependency hono to v4.12.16 May 2, 2026
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.12.16 Update dependency hono to v4.12.16 May 4, 2026
@renovate renovate Bot changed the title Update dependency hono to v4.12.16 Update dependency hono to v4.12.17 May 5, 2026
@renovate renovate Bot force-pushed the renovate/hono-4.x-lockfile branch from a50e754 to 2aa8112 Compare May 5, 2026 11:31
@renovate renovate Bot changed the title Update dependency hono to v4.12.17 Update dependency hono to v4.12.18 May 6, 2026
@renovate renovate Bot force-pushed the renovate/hono-4.x-lockfile branch 2 times, most recently from 2544c6c to a89159b Compare May 12, 2026 17:13
@renovate renovate Bot changed the title Update dependency hono to v4.12.18 chore(deps): update dependency hono to v4.12.18 May 13, 2026
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.12.18 Update dependency hono to v4.12.18 May 15, 2026
@renovate renovate Bot changed the title Update dependency hono to v4.12.18 Update dependency hono to v4.12.19 May 16, 2026
@renovate renovate Bot force-pushed the renovate/hono-4.x-lockfile branch from a89159b to 1320933 Compare May 16, 2026 12:59
@renovate renovate Bot changed the title Update dependency hono to v4.12.19 chore(deps): update dependency hono to v4.12.19 May 17, 2026
@renovate renovate Bot force-pushed the renovate/hono-4.x-lockfile branch from 1320933 to ea653ea Compare May 18, 2026 16:08
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.12.19 chore(deps): update dependency hono to v4.12.21 May 19, 2026
@renovate renovate Bot force-pushed the renovate/hono-4.x-lockfile branch from ea653ea to 065850e Compare May 19, 2026 16:07
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.12.21 chore(deps): update dependency hono to v4.12.22 May 22, 2026
@renovate renovate Bot force-pushed the renovate/hono-4.x-lockfile branch from 065850e to ddbee39 Compare May 22, 2026 10:41
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.12.22 chore(deps): update dependency hono to v4.12.23 May 25, 2026
@renovate renovate Bot force-pushed the renovate/hono-4.x-lockfile branch from ddbee39 to b4541c5 Compare May 25, 2026 05:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants