Skip to content

fix(deps): bump hono to 4.12.14 / @hono/node-server to 1.19.14#67613

Merged
hxy91819 merged 1 commit into
mainfrom
security/dependabot-hono-jsx-html-injection
Apr 16, 2026
Merged

fix(deps): bump hono to 4.12.14 / @hono/node-server to 1.19.14#67613
hxy91819 merged 1 commit into
mainfrom
security/dependabot-hono-jsx-html-injection

Conversation

@hxy91819

@hxy91819 hxy91819 commented Apr 16, 2026

Copy link
Copy Markdown
Member

Summary

  • Bump hono pnpm override from 4.12.12 → 4.12.14 and @hono/node-server from 1.19.13 → 1.19.14
  • Picks up the latest patch releases for both packages

Testing

  • Override bumps are lockfile-only; no source changes required.
  • CI will validate that the lockfile resolves cleanly and the existing test suite passes.

@greptile-apps

greptile-apps Bot commented Apr 16, 2026

Copy link
Copy Markdown
Contributor

Greptile Summary

This PR bumps hono from 4.12.12 → 4.12.14 and @hono/node-server from 1.19.13 → 1.19.14 via pnpm overrides to address GHSA-458j-xx4x-4375 (HTML injection via improper JSX attribute name handling in hono/jsx SSR). The lockfile is updated consistently across all snapshot entries — @buape/carbon, @modelcontextprotocol/sdk, and direct hono snapshots — with no source code changes required.

Confidence Score: 5/5

Safe to merge — minimal, focused security patch with consistent lockfile updates and no source changes.

All pnpm override pins and lockfile snapshot entries are updated consistently. No source code changes, no logic risk. Addresses a known moderate-severity CVE with the first-patched versions indicated by the advisory.

No files require special attention.

Reviews (1): Last reviewed commit: "fix(deps): bump hono to 4.12.14 and @hon..." | Re-trigger Greptile

@openclaw-barnacle openclaw-barnacle Bot added size: XS maintainer Maintainer-authored PR labels Apr 16, 2026
@hxy91819 hxy91819 changed the title fix(deps): bump hono to 4.12.14 / @hono/node-server to 1.19.14 (GHSA-458j-xx4x-4375) fix(deps): bump hono to 4.12.14 / @hono/node-server to 1.19.14 Apr 16, 2026
@hxy91819 hxy91819 merged commit fbccc18 into main Apr 16, 2026
49 of 53 checks passed
@hxy91819 hxy91819 deleted the security/dependabot-hono-jsx-html-injection branch April 16, 2026 10:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

maintainer Maintainer-authored PR size: XS

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant