Skip to content

chore(deps): Bump @hono/node-server from 1.19.9 to 1.19.13#11

Open
dependabot[bot] wants to merge 15 commits into
mainfrom
dependabot/npm_and_yarn/hono/node-server-1.19.13
Open

chore(deps): Bump @hono/node-server from 1.19.9 to 1.19.13#11
dependabot[bot] wants to merge 15 commits into
mainfrom
dependabot/npm_and_yarn/hono/node-server-1.19.13

Conversation

@dependabot
Copy link
Copy Markdown

@dependabot dependabot Bot commented on behalf of github Apr 21, 2026

Bumps @hono/node-server from 1.19.9 to 1.19.13.

Release notes

Sourced from @​hono/node-server's releases.

v1.19.13

Security Fix

Fixed an issue in Serve Static Middleware where inconsistent handling of repeated slashes (//) between the router and static file resolution could allow middleware to be bypassed. Users of Serve Static Middleware are encouraged to upgrade to this version.

See GHSA-92pp-h63x-v22m for details.

v1.19.12

What's Changed

Full Changelog: honojs/node-server@v1.19.11...v1.19.12

v1.19.11

What's Changed

Full Changelog: honojs/node-server@v1.19.10...v1.19.11

v1.19.10

Security Fix

Fixed an authorization bypass in Serve Static Middleware caused by inconsistent URL decoding (%2F handling) between the router and static file resolution. Users of Serve Static Middleware are encouraged to upgrade to this version.

See GHSA-wc8c-qw6v-h7f6 for details.

Commits

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

lionello and others added 10 commits April 14, 2026 12:24
The Cloudflare Origin CA API requires the dedicated Origin CA Key
(CLOUDFLARE_API_USER_SERVICE_KEY), not a regular API token. Without it,
Pulumi fails with error 1016 "User is not authorized to perform this action".

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Cloudflare free plan requires all Durable Objects to use
new_sqlite_classes. Collapsed 6 migrations into one since this is a
fresh deployment with no existing DO data.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Apr 21, 2026
raphaeltm and others added 5 commits April 21, 2026 15:37
Bumps [@hono/node-server](https://github.com/honojs/node-server) from 1.19.9 to 1.19.13.
- [Release notes](https://github.com/honojs/node-server/releases)
- [Commits](honojs/node-server@v1.19.9...v1.19.13)

---
updated-dependencies:
- dependency-name: "@hono/node-server"
  dependency-version: 1.19.13
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/hono/node-server-1.19.13 branch from 66dbee6 to f07af0c Compare May 20, 2026 09:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants