Skip to content

chore(deps): update dependency hono to v4.12.25#256

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/hono-4.x
Open

chore(deps): update dependency hono to v4.12.25#256
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/hono-4.x

Conversation

@renovate

@renovate renovate Bot commented Feb 26, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
hono (source) 4.12.144.12.25 age confidence

Release Notes

honojs/hono (hono)

v4.12.25

Compare Source

v4.12.24

Compare Source

v4.12.23

Compare Source

What's Changed

Full Changelog: honojs/hono@v4.12.22...v4.12.23

v4.12.22

Compare Source

What's Changed
New Contributors

Full Changelog: honojs/hono@v4.12.21...v4.12.22

v4.12.21

Compare Source

Security fixes

This release includes fixes for the following security issues:

app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded paths

Affects: app.mount(). Fixes prefix stripping using the raw URL pathname instead of the decoded path, where percent-encoded characters in the mount prefix or path could cause the prefix to be removed at the wrong position, resulting in the sub-application receiving an incorrect path. GHSA-2gcr-mfcq-wcc3

IP Restriction bypasses static deny rules for non-canonical IPv6

Affects: hono/ip-restriction. Fixes IP address comparison using string equality, where non-canonical IPv6 representations of a denied address — such as compressed forms or hex-notation IPv4-mapped addresses — could bypass static deny rules. GHSA-xrhx-7g5j-rcj5

Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injection

Affects: hono/cookie. Fixes missing validation of sameSite and priority options against injection characters (;, \r, \n), where user-controlled input passed to either option could inject additional attributes into the Set-Cookie response header. GHSA-3hrh-pfw6-9m5x

JWT middleware accepts any Authorization scheme, not only Bearer

Affects: hono/jwt, hono/jwk. Fixes missing scheme validation in the Authorization header, where any two-part header value was accepted regardless of the scheme name, allowing non-Bearer schemes to pass JWT authentication. GHSA-f577-qrjj-4474


Users who use app.mount(), hono/ip-restriction, hono/cookie, or hono/jwt/hono/jwk are encouraged to upgrade to this version.

v4.12.20

Compare Source

What's Changed
New Contributors

Full Changelog: honojs/hono@v4.12.19...v4.12.20

v4.12.19

Compare Source

What's Changed

New Contributors

Full Changelog: honojs/hono@v4.12.18...v4.12.19

v4.12.18

Compare Source

v4.12.17

Compare Source

v4.12.16

Compare Source

Security fixes

This release includes fixes for the following security issues:

Unvalidated JSX Tag Names in hono/jsx May Allow HTML Injection

Affects: hono/jsx. Fixes missing validation of JSX tag names when using jsx() or createElement(), which could allow HTML injection if untrusted input is used as the tag name. GHSA-69xw-7hcm-h432

bodyLimit() can be bypassed for chunked / unknown-length requests

Affects: Body Limit Middleware. Fixes late enforcement for request bodies without a reliable Content-Length (e.g. chunked requests), where oversized requests could reach handlers and return successful responses before being rejected. GHSA-9vqf-7f2p-gf9v

v4.12.15

Compare Source

What's Changed
New Contributors

Full Changelog: honojs/hono@v4.12.14...v4.12.15


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the bump label Feb 26, 2026
@renovate renovate Bot force-pushed the renovate/hono-4.x branch 3 times, most recently from c9c00e4 to 10755fd Compare February 28, 2026 12:28
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.12.3 chore(deps): update dependency hono to v4.12.4 Mar 3, 2026
@renovate renovate Bot force-pushed the renovate/hono-4.x branch from 10755fd to c0e4287 Compare March 3, 2026 13:42
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.12.4 chore(deps): update dependency hono to v4.12.5 Mar 4, 2026
@renovate renovate Bot force-pushed the renovate/hono-4.x branch 2 times, most recently from 6b9a9d1 to 29cb5c1 Compare March 10, 2026 06:19
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.12.5 chore(deps): update dependency hono to v4.12.6 Mar 10, 2026
@renovate renovate Bot force-pushed the renovate/hono-4.x branch from 29cb5c1 to 781107f Compare March 10, 2026 14:01
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.12.6 chore(deps): update dependency hono to v4.12.7 Mar 10, 2026
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.12.7 chore(deps): update dependency hono to v4.12.8 Mar 15, 2026
@renovate renovate Bot force-pushed the renovate/hono-4.x branch from 781107f to 5a4607f Compare March 15, 2026 02:00
@renovate renovate Bot force-pushed the renovate/hono-4.x branch from 5a4607f to 6fa01c5 Compare March 23, 2026 13:04
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.12.8 chore(deps): update dependency hono to v4.12.9 Mar 23, 2026
@renovate renovate Bot force-pushed the renovate/hono-4.x branch from 6fa01c5 to 56e33ef Compare April 2, 2026 13:58
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.12.9 chore(deps): update dependency hono to v4.12.10 Apr 2, 2026
@renovate renovate Bot force-pushed the renovate/hono-4.x branch from 56e33ef to 84d3442 Compare April 6, 2026 09:40
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.12.10 chore(deps): update dependency hono to v4.12.11 Apr 6, 2026
@renovate renovate Bot force-pushed the renovate/hono-4.x branch from 84d3442 to 0dcc9e4 Compare April 7, 2026 05:41
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.12.11 chore(deps): update dependency hono to v4.12.12 Apr 7, 2026
@renovate renovate Bot force-pushed the renovate/hono-4.x branch from 0dcc9e4 to 26944c7 Compare April 15, 2026 05:42
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.12.12 chore(deps): update dependency hono to v4.12.13 Apr 15, 2026
@renovate renovate Bot force-pushed the renovate/hono-4.x branch from 26944c7 to 3d6076c Compare April 15, 2026 08:53
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.12.13 chore(deps): update dependency hono to v4.12.14 Apr 15, 2026
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.12.14 chore(deps): update dependency hono to v4.12.14 - autoclosed Apr 20, 2026
@renovate renovate Bot closed this Apr 20, 2026
@renovate renovate Bot deleted the renovate/hono-4.x branch April 20, 2026 22:32
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.12.14 - autoclosed chore(deps): update dependency hono to v4.12.15 Apr 24, 2026
@renovate renovate Bot reopened this Apr 24, 2026
@renovate renovate Bot force-pushed the renovate/hono-4.x branch 2 times, most recently from 3d6076c to 0d8d4bd Compare April 24, 2026 09:31
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.12.15 chore(deps): update dependency hono to v4.12.16 Apr 30, 2026
@renovate renovate Bot force-pushed the renovate/hono-4.x branch 2 times, most recently from bc158d9 to ccd429a Compare May 5, 2026 12:38
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.12.16 chore(deps): update dependency hono to v4.12.17 May 5, 2026
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.12.17 chore(deps): update dependency hono to v4.12.18 May 6, 2026
@renovate renovate Bot force-pushed the renovate/hono-4.x branch from ccd429a to c646e56 Compare May 6, 2026 14:30
@renovate renovate Bot force-pushed the renovate/hono-4.x branch from c646e56 to 161ea4e Compare May 16, 2026 13:37
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.12.18 chore(deps): update dependency hono to v4.12.19 May 16, 2026
@renovate renovate Bot force-pushed the renovate/hono-4.x branch from 161ea4e to 6f72394 Compare May 19, 2026 16:40
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.12.19 chore(deps): update dependency hono to v4.12.21 May 19, 2026
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.12.21 chore(deps): update dependency hono to v4.12.22 May 22, 2026
@renovate renovate Bot force-pushed the renovate/hono-4.x branch 2 times, most recently from 0da1139 to 8e9f37e Compare May 25, 2026 06:00
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.12.22 chore(deps): update dependency hono to v4.12.23 May 25, 2026
@renovate renovate Bot force-pushed the renovate/hono-4.x branch from 8e9f37e to 70c0029 Compare June 8, 2026 14:11
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.12.23 chore(deps): update dependency hono to v4.12.24 Jun 8, 2026
@renovate renovate Bot force-pushed the renovate/hono-4.x branch from 70c0029 to 6cb87bd Compare June 9, 2026 06:59
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.12.24 chore(deps): update dependency hono to v4.12.25 Jun 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants