Skip to content

build(deps): bump hono from 4.12.0 to 4.12.19 in /ui in the npm_and_yarn group across 1 directory#2097

Merged
SamMorrowDrums merged 1 commit into
mainfrom
dependabot/npm_and_yarn/ui/npm_and_yarn-ccf8cbde5a
May 18, 2026
Merged

build(deps): bump hono from 4.12.0 to 4.12.19 in /ui in the npm_and_yarn group across 1 directory#2097
SamMorrowDrums merged 1 commit into
mainfrom
dependabot/npm_and_yarn/ui/npm_and_yarn-ccf8cbde5a

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Feb 25, 2026

Bumps the npm_and_yarn group with 1 update in the /ui directory: hono.

Updates hono from 4.12.0 to 4.12.19

Release notes

Sourced from hono's releases.

v4.12.19

What's Changed

New Contributors

Full Changelog: honojs/hono@v4.12.18...v4.12.19

v4.12.18

Security fixes

This release includes fixes for the following security issues:

Cache Middleware ignores Vary: Authorization / Vary: Cookie leading to cross-user cache leakage

Affects: Cache Middleware. Fixes missing cache-skip handling for Vary: Authorization and Vary: Cookie, where a response cached for one authenticated user could be served to other users. GHSA-p77w-8qqv-26rm

CSS Declaration Injection via Style Object Values in JSX SSR

Affects: hono/jsx. Fixes a missing CSS-context escape for style object values and property names, where untrusted input could inject additional CSS declarations. The impact is limited to CSS and does not allow JavaScript execution. GHSA-qp7p-654g-cw7p

Improper validation of NumericDate claims (exp, nbf, iat) in JWT verify()

Affects: hono/utils/jwt. Fixes improper validation of exp, nbf, and iat claims, where falsy, non-finite, or non-numeric values could silently bypass time-based checks instead of being rejected per RFC 7519. GHSA-hm8q-7f3q-5f36


Users who use the JWT helper, hono/jsx, or the Cache middleware are strongly encouraged to upgrade to this version.

v4.12.17

What's Changed

New Contributors

Full Changelog: honojs/hono@v4.12.16...v4.12.17

v4.12.16

... (truncated)

Commits
  • 7e62bcd 4.12.19
  • e2f252a fix(stream): upgrade @hono/node-server to v2 and fix abort handling (#4940)
  • 54f2f0c feat(request): add bytes() (#4921)
  • e59db59 feat(cache): key cache entries by configured vary headers (#4915)
  • 48a7ccb feat(bearer-auth): make bearerAuth generic for typed context in verifyToken (...
  • ff7522f fix(cookie): return the first cookie when there are multiple cookies with the...
  • 26f8c33 fix(serveStatic): make options parameter optional in all adapters (#4934)
  • 16c4e38 ci: pin GitHub Actions to SHAs (#4932)
  • f10dee8 4.12.18
  • a5bd9eb Merge commit from fork
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Feb 25, 2026
@dependabot dependabot Bot requested a review from a team as a code owner February 25, 2026 18:10
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Feb 25, 2026
Copy link
Copy Markdown

@abrahamjohn2170-max abrahamjohn2170-max left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Let’s grow together

@SamMorrowDrums
Copy link
Copy Markdown
Collaborator

@dependabot recreate

SamMorrowDrums
SamMorrowDrums previously approved these changes May 18, 2026
Copy link
Copy Markdown
Collaborator

@SamMorrowDrums SamMorrowDrums left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Transitive hono patch incl. security fix. We don't use hono directly.

@SamMorrowDrums
Copy link
Copy Markdown
Collaborator

@dependabot squash and merge

@dependabot dependabot Bot changed the title build(deps): bump hono from 4.12.0 to 4.12.2 in /ui in the npm_and_yarn group across 1 directory build(deps): bump hono from 4.12.0 to 4.12.19 in /ui in the npm_and_yarn group across 1 directory May 18, 2026
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/ui/npm_and_yarn-ccf8cbde5a branch from 838ba86 to e514aec Compare May 18, 2026 14:17
@SamMorrowDrums
Copy link
Copy Markdown
Collaborator

@dependabot rebase

@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/ui/npm_and_yarn-ccf8cbde5a branch from e514aec to 946a25a Compare May 18, 2026 14:30
@SamMorrowDrums
Copy link
Copy Markdown
Collaborator

@dependabot rebase

Bumps the npm_and_yarn group with 1 update in the /ui directory: [hono](https://github.com/honojs/hono).


Updates `hono` from 4.12.0 to 4.12.19
- [Release notes](https://github.com/honojs/hono/releases)
- [Commits](honojs/hono@v4.12.0...v4.12.19)

---
updated-dependencies:
- dependency-name: hono
  dependency-version: 4.12.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/ui/npm_and_yarn-ccf8cbde5a branch from 946a25a to 241545f Compare May 18, 2026 15:59
Copy link
Copy Markdown
Collaborator

@SamMorrowDrums SamMorrowDrums left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-approving after rebase. hono 4.12.0→4.12.19 patch+minor in /ui (transitive dep of @modelcontextprotocol/ext-apps).

@SamMorrowDrums SamMorrowDrums merged commit ea9d0c8 into main May 18, 2026
17 checks passed
@SamMorrowDrums SamMorrowDrums deleted the dependabot/npm_and_yarn/ui/npm_and_yarn-ccf8cbde5a branch May 18, 2026 16:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants