Skip to content

Commit 42f2a9f

Browse files
Update dependency hono to ^4.13.8 (#235)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [hono](https://hono.dev) ([source](https://redirect.github.com/honojs/hono)) | [`^4.12.31` → `^4.13.8`](https://renovatebot.com/diffs/npm/hono/4.12.31/4.13.8) | ![age](https://developer.mend.io/api/mc/badges/age/npm/hono/4.13.8?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/hono/4.12.31/4.13.8?slim=true) | ⚠️ Renovate does not enforce Minimum Release Age for `bump`, `lockfileUpdate`, or `rollback` updates, so these are raised without a Minimum Release Age check. You will need to manually validate the Minimum Release Age for these package(s). --- ### Release Notes <details> <summary>honojs/hono (hono)</summary> ### [`v4.13.8`](https://redirect.github.com/honojs/hono/releases/tag/v4.13.8) [Compare Source](https://redirect.github.com/honojs/hono/compare/v4.13.7...v4.13.8) #### What's Changed - docs: fix typos in code comments and link third-party middleware section in [#&#8203;5343](https://redirect.github.com/honojs/hono/pull/5343) - perf(jsx/dom): reduce lookup work for large keyed updates in [#&#8203;5340](https://redirect.github.com/honojs/hono/pull/5340) - fix(aws-lambda): respect backpressure when streaming the response body in [#&#8203;5351](https://redirect.github.com/honojs/hono/pull/5351) - fix(accepts, language): skip accept entries with quality 0 when matching in [#&#8203;5311](https://redirect.github.com/honojs/hono/pull/5311) - fix(accept): treat the q parameter name as case-insensitive in [#&#8203;5349](https://redirect.github.com/honojs/hono/pull/5349) - fix(accept): clamp a negative q to 0, not 1 in [#&#8203;5357](https://redirect.github.com/honojs/hono/pull/5357) - fix(request): keep the request media type when reusing a cached body in [#&#8203;5366](https://redirect.github.com/honojs/hono/pull/5366) - docs(combine): fix except() JSDoc param and add missing [@&#8203;returns](https://redirect.github.com/returns) in [#&#8203;5346](https://redirect.github.com/honojs/hono/pull/5346) - perf(jsx/dom): optimize matching-head child lookup during reconciliation in [#&#8203;5329](https://redirect.github.com/honojs/hono/pull/5329) **Full Changelog**: <honojs/hono@v4.13.7...v4.13.8> ### [`v4.13.7`](https://redirect.github.com/honojs/hono/compare/v4.13.6...eebdf7be39abf0a872671835ccce0c4f03ea497a) [Compare Source](https://redirect.github.com/honojs/hono/compare/v4.13.6...v4.13.7) ### [`v4.13.6`](https://redirect.github.com/honojs/hono/compare/v4.13.5...v4.13.6) [Compare Source](https://redirect.github.com/honojs/hono/compare/v4.13.5...v4.13.6) ### [`v4.13.5`](https://redirect.github.com/honojs/hono/compare/v4.13.4...06880c4a2b04de9dd74217f26dd831209b9c01f1) [Compare Source](https://redirect.github.com/honojs/hono/compare/v4.13.4...v4.13.5) ### [`v4.13.4`](https://redirect.github.com/honojs/hono/compare/v4.13.3...017000d6ad5bc6a65dd0f9215a4fdfea6ea80aea) [Compare Source](https://redirect.github.com/honojs/hono/compare/v4.13.3...v4.13.4) ### [`v4.13.3`](https://redirect.github.com/honojs/hono/releases/tag/v4.13.3) [Compare Source](https://redirect.github.com/honojs/hono/compare/v4.13.2...v4.13.3) #### What's Changed - fix(client): prevent URL corruption when replaceUrlParam contains $ replacement tokens in [#&#8203;5227](https://redirect.github.com/honojs/hono/pull/5227) - fix(etag): copy pending stream bytes in [#&#8203;5239](https://redirect.github.com/honojs/hono/pull/5239) - fix(etag): avoid skipping headers when filtering 304 response headers in [#&#8203;5234](https://redirect.github.com/honojs/hono/pull/5234) - fix(cors): append Origin to Vary header on OPTIONS preflight in [#&#8203;5235](https://redirect.github.com/honojs/hono/pull/5235) - docs(context): add custom headers append option example to Context JSDoc in [#&#8203;5248](https://redirect.github.com/honojs/hono/pull/5248) - fix(trie-router): match suffix wildcard routes in [#&#8203;5236](https://redirect.github.com/honojs/hono/pull/5236) - fix(pattern-router/linear-router): prevent prefix overmatch on wildcard routes in [#&#8203;5252](https://redirect.github.com/honojs/hono/pull/5252) - fix(csrf): exempt OPTIONS request from CSRF validation in [#&#8203;5250](https://redirect.github.com/honojs/hono/pull/5250) - fix(utils/ipaddr): avoid truncation on embedded IPv4 addresses in expand IPv6 in [#&#8203;5247](https://redirect.github.com/honojs/hono/pull/5247) - feat(pretty-json): support structured JSON content-types (+json) in [#&#8203;5226](https://redirect.github.com/honojs/hono/pull/5226) **Full Changelog**: <honojs/hono@v4.13.2...v4.13.3> ### [`v4.13.2`](https://redirect.github.com/honojs/hono/releases/tag/v4.13.2) [Compare Source](https://redirect.github.com/honojs/hono/compare/v4.13.1...v4.13.2) #### What's Changed - fix(secure-headers): output standard empty parentheses () instead of none for disabled Permissions-Policy directives in [#&#8203;5197](https://redirect.github.com/honojs/hono/pull/5197) - fix(jsx): render async children of document metadata tags instead of \[object Promise] in [#&#8203;5204](https://redirect.github.com/honojs/hono/pull/5204) - fix(etag): resolve incorrect incremental hashing for chunked responses in [#&#8203;5199](https://redirect.github.com/honojs/hono/pull/5199) - fix(client): serialize multiple cookies correctly in [#&#8203;5202](https://redirect.github.com/honojs/hono/pull/5202) - fix(etag): stabilize digest across stream chunks in [#&#8203;5205](https://redirect.github.com/honojs/hono/pull/5205) - fix(url): strip trailing question mark correctly for optional params with regex quantifiers in [#&#8203;5209](https://redirect.github.com/honojs/hono/pull/5209) - perf(cors): pre-join static array header options during initialization in [#&#8203;5210](https://redirect.github.com/honojs/hono/pull/5210) - fix(client): send falsy JSON bodies in [#&#8203;5215](https://redirect.github.com/honojs/hono/pull/5215) - feat(secure-headers): add missing W3C Permissions-Policy directives in [#&#8203;5214](https://redirect.github.com/honojs/hono/pull/5214) **Full Changelog**: <honojs/hono@v4.13.1...v4.13.2> ### [`v4.13.1`](https://redirect.github.com/honojs/hono/compare/v4.13.0...v4.13.1) [Compare Source](https://redirect.github.com/honojs/hono/compare/v4.13.0...v4.13.1) ### [`v4.13.0`](https://redirect.github.com/honojs/hono/releases/tag/v4.13.0) [Compare Source](https://redirect.github.com/honojs/hono/compare/v4.12.34...v4.13.0) Hono v4.13.0 is now available! The highlight of this release is performance: a batch of low-level optimizations makes the core request/response path significantly faster — up to 1.25x on common routes in our benchmark. This release also adds first-class support for the HTTP QUERY method, defined in [RFC 10008](https://www.rfc-editor.org/rfc/rfc10008.html), a new Method Not Allowed middleware, and more. #### Performance improvements This release includes a series of small optimizations: skipping unnecessary `Headers` allocations, replacing regex tests with `indexOf`, allocating internal state lazily, and more. Here is [`benchmarks/fetch`](https://redirect.github.com/honojs/hono/tree/main/benchmarks/fetch) comparing v4.12 and v4.13 (`ROUNDS=5 ./compare.sh`, Bun 1.4.0, Apple Silicon — each measurement runs in a fresh process, and the variant order is reversed every round to avoid warm-up bias): | Benchmark | v4.12 | v4.13 | Speedup | | ------------------------------ | --------: | --------: | --------: | | `ping` — `GET /` | 165.83 ns | 163.99 ns | 1.01x | | `query` — `GET /id/1?name=bun` | 674.40 ns | 616.99 ns | **1.09x** | | `json` — `GET /user` | 528.99 ns | 422.44 ns | **1.25x** | | `body` — `POST /json` | 1.16 µs | 1.00 µs | **1.15x** | The individual changes: - perf(context): iterate the header record with `for..in` [#&#8203;5118](https://redirect.github.com/honojs/hono/pull/5118) - perf(url): replace regex tests with `indexOf` [#&#8203;5121](https://redirect.github.com/honojs/hono/pull/5121) - perf(context): skip `Headers` creation when there are no headers to merge [#&#8203;5122](https://redirect.github.com/honojs/hono/pull/5122) - perf(urls): refactor `tryDecodeURIComponent` [#&#8203;5158](https://redirect.github.com/honojs/hono/pull/5158) - perf(request): allocate `#validatedData` lazily [#&#8203;5175](https://redirect.github.com/honojs/hono/pull/5175) - perf(request): probe the body cache without allocating [#&#8203;5176](https://redirect.github.com/honojs/hono/pull/5176) In addition, the RegExpRouter rewrite described below makes route registration plus the first match roughly 20% faster. Thanks [@&#8203;kibertoad](https://redirect.github.com/kibertoad) for the contributions! #### First-class QUERY method support The QUERY method — a safe, idempotent method that carries a request body — is now a first-class citizen in Hono. You can define QUERY handlers with `app.query()`: ```ts const app = new Hono() app.query('/search', async (c) => { const conditions = await c.req.json() return c.json(await search(conditions)) }) ``` Thanks [@&#8203;shellhaki](https://redirect.github.com/shellhaki)! #### QUERY support across built-in middleware The built-in middleware has been updated to handle QUERY requests properly: ##### Cache Middleware The Cache Middleware now caches QUERY responses. Following RFC 10008 Section 2.7, the cache key incorporates a SHA-256 digest of the request content and its representation metadata, so different query bodies are cached separately: ```ts app.query( '/search', cache({ cacheName: 'search-cache', cacheControl: 'max-age=3600', }) ) ``` **Note**: To support this, the internal cache key format has changed for all methods, including GET. Cached entries are now stored under an internal URL of the form `/.hono/cache?__hono_cache_key=...`. If you purge cache entries by URL outside of the middleware (e.g. calling `caches.delete()` with the original request URL), you will need to update that logic. Existing cache entries stored with the old format will simply be re-fetched. ##### ETag Middleware The ETag Middleware now handles conditional requests for QUERY, returning `304 Not Modified` when `If-None-Match` matches. ##### CORS Middleware The CORS Middleware now includes QUERY in the default `Access-Control-Allow-Methods`, which is now `GET, HEAD, PUT, POST, DELETE, PATCH, QUERY`. If you specify `allowMethods` explicitly, nothing changes for you. Thanks [@&#8203;usualoma](https://redirect.github.com/usualoma) and [@&#8203;Cherry](https://redirect.github.com/Cherry)! #### Method Not Allowed Middleware The new Method Not Allowed Middleware returns a `405 Method Not Allowed` response with a proper `Allow` header when the request path matches a registered route but the method does not: ```ts import { methodNotAllowed } from 'hono/method-not-allowed' const app = new Hono() app.use(methodNotAllowed({ app })) app.get('/hello', (c) => c.text('Hello!')) app.post('/hello', (c) => c.text('Posted!')) // PUT /hello -> 405 Method Not Allowed // Allow: GET, HEAD, POST ``` You can customize the response with the `onMethodNotAllowed` option: ```ts app.use( methodNotAllowed({ app, onMethodNotAllowed: (c, methods) => c.json({ error: 'Method Not Allowed' }, 405, { Allow: methods.join(', ') }), }) ) ``` Thanks [@&#8203;usualoma](https://redirect.github.com/usualoma)! #### RegExpRouter throws `UnsupportedPathError` at registration time The RegExpRouter now detects unsupported path combinations when routes are registered, instead of at the first matching request. This means misconfigured routes fail fast at startup rather than at runtime. As a bonus, registration plus the first match is roughly 20% faster. Thanks [@&#8203;usualoma](https://redirect.github.com/usualoma)! #### Other improvements - `hono/utils/headers` has been synced with the IANA HTTP Field Name Registry, adding newly registered fields such as `Accept-Query`. Thanks [@&#8203;akahoshi1421](https://redirect.github.com/akahoshi1421)! - The JWT and JWK middleware now accept a `realm` option for the `WWW-Authenticate` challenge on `401` responses, and challenge values are properly escaped. Thanks [@&#8203;arhxam](https://redirect.github.com/arhxam)! - JSX: `useRef` and `RefObject` are now aligned with React 19. Note that this is a type-level change — `RefObject<T>` is now `{ current: T }`, so type a nullable ref as `RefObject<T | null>`, and pass `useRef(undefined)` instead of `useRef()`. Thanks [@&#8203;ashunar0](https://redirect.github.com/ashunar0)! - JSX: a function component can now return an array of children without throwing during server-side rendering. Thanks [@&#8203;natsuki-engr](https://redirect.github.com/natsuki-engr)! - The Compress Middleware now sets `Vary: Accept-Encoding` on negotiated responses. Thanks [@&#8203;arhxam](https://redirect.github.com/arhxam)! #### All changes - perf(hono-base): avoid rest parameter in `fetch` by [@&#8203;yusukebe](https://redirect.github.com/yusukebe) in [#&#8203;5113](https://redirect.github.com/honojs/hono/pull/5113) - perf(context): iterate the header record with for..in by [@&#8203;yusukebe](https://redirect.github.com/yusukebe) in [#&#8203;5118](https://redirect.github.com/honojs/hono/pull/5118) - perf(url/request): replace regex tests with `indexOf` by [@&#8203;yusukebe](https://redirect.github.com/yusukebe) in [#&#8203;5121](https://redirect.github.com/honojs/hono/pull/5121) - perf(context): skip Headers creation when there are no headers to merge by [@&#8203;yusukebe](https://redirect.github.com/yusukebe) in [#&#8203;5122](https://redirect.github.com/honojs/hono/pull/5122) - perf(urls): refactor `tryDecodeURIComponent` by [@&#8203;yusukebe](https://redirect.github.com/yusukebe) in [#&#8203;5158](https://redirect.github.com/honojs/hono/pull/5158) - chore(benchmarks): correct src path on Windows, add json and middleware cases by [@&#8203;kibertoad](https://redirect.github.com/kibertoad) in [#&#8203;5173](https://redirect.github.com/honojs/hono/pull/5173) - perf(context): drop the throwaway `env` field initializer by [@&#8203;kibertoad](https://redirect.github.com/kibertoad) in [#&#8203;5174](https://redirect.github.com/honojs/hono/pull/5174) - perf(request): allocate `#validatedData` lazily by [@&#8203;kibertoad](https://redirect.github.com/kibertoad) in [#&#8203;5175](https://redirect.github.com/honojs/hono/pull/5175) - perf(request): probe the body cache without allocating by [@&#8203;kibertoad](https://redirect.github.com/kibertoad) in [#&#8203;5176](https://redirect.github.com/honojs/hono/pull/5176) - chore(benchmarks): stabilize measurements by forcing mitata batching by [@&#8203;yusukebe](https://redirect.github.com/yusukebe) in [#&#8203;5183](https://redirect.github.com/honojs/hono/pull/5183) - perf(hono-base): restore the rest parameter in `fetch` by [@&#8203;yusukebe](https://redirect.github.com/yusukebe) in [#&#8203;5184](https://redirect.github.com/honojs/hono/pull/5184) - perf(context): restore the `env` field initializer by [@&#8203;yusukebe](https://redirect.github.com/yusukebe) in [#&#8203;5186](https://redirect.github.com/honojs/hono/pull/5186) - feat: add first-class QUERY method support by [@&#8203;shellhaki](https://redirect.github.com/shellhaki) in [#&#8203;5070](https://redirect.github.com/honojs/hono/pull/5070) - feat(etag): support conditional requests for the QUERY method by [@&#8203;Cherry](https://redirect.github.com/Cherry) in [#&#8203;5111](https://redirect.github.com/honojs/hono/pull/5111) - feat(cors): allow QUERY by default as a first-class method by [@&#8203;usualoma](https://redirect.github.com/usualoma) in [#&#8203;5115](https://redirect.github.com/honojs/hono/pull/5115) - feat(cache): add first-class support for QUERY requests by [@&#8203;usualoma](https://redirect.github.com/usualoma) in [#&#8203;5119](https://redirect.github.com/honojs/hono/pull/5119) - feat(jsx): add React-compatible overloads to useRef by [@&#8203;ashunar0](https://redirect.github.com/ashunar0) in [#&#8203;5063](https://redirect.github.com/honojs/hono/pull/5063) - feat(middleware): add method-not-allowed middleware by [@&#8203;usualoma](https://redirect.github.com/usualoma) in [#&#8203;5132](https://redirect.github.com/honojs/hono/pull/5132) - feat(jwt,jwk): add a configurable WWW-Authenticate realm by [@&#8203;arhxam](https://redirect.github.com/arhxam) in [#&#8203;5141](https://redirect.github.com/honojs/hono/pull/5141) - feat(utils/headers): sync HTTP field types with the IANA registry by [@&#8203;akahoshi1421](https://redirect.github.com/akahoshi1421) in [#&#8203;5153](https://redirect.github.com/honojs/hono/pull/5153) - fix(jsx): allow a function component to return an array by [@&#8203;natsuki-engr](https://redirect.github.com/natsuki-engr) in [#&#8203;5179](https://redirect.github.com/honojs/hono/pull/5179) - feat(reg-exp-router): throw UnsupportedPathError during route registration by [@&#8203;usualoma](https://redirect.github.com/usualoma) in [#&#8203;5171](https://redirect.github.com/honojs/hono/pull/5171) - fix(compress): set Vary: Accept-Encoding on negotiated responses by [@&#8203;arhxam](https://redirect.github.com/arhxam) in [#&#8203;5137](https://redirect.github.com/honojs/hono/pull/5137) **Full Changelog**: <honojs/hono@v4.12.34...v4.13.0> Thank you to all contributors! ### [`v4.12.34`](https://redirect.github.com/honojs/hono/compare/v4.12.33...v4.12.34) [Compare Source](https://redirect.github.com/honojs/hono/compare/v4.12.33...v4.12.34) ### [`v4.12.33`](https://redirect.github.com/honojs/hono/releases/tag/v4.12.33) [Compare Source](https://redirect.github.com/honojs/hono/compare/v4.12.32...v4.12.33) #### What's Changed - fix(cookie): relax name validation when parsing Cookie header in [#&#8203;5164](https://redirect.github.com/honojs/hono/pull/5164) - chore: bump `@hono/node-server` in [#&#8203;5167](https://redirect.github.com/honojs/hono/pull/5167) - fix(jsx): handle useSyncExternalStore subscription and snapshot changes in [#&#8203;5166](https://redirect.github.com/honojs/hono/pull/5166) - chore: remove undici in favor of global fetch in [#&#8203;5168](https://redirect.github.com/honojs/hono/pull/5168) **Full Changelog**: <honojs/hono@v4.12.32...v4.12.33> ### [`v4.12.32`](https://redirect.github.com/honojs/hono/releases/tag/v4.12.32) [Compare Source](https://redirect.github.com/honojs/hono/compare/v4.12.31...v4.12.32) #### What's Changed - ci: enable reports for type & bundle size check in [#&#8203;5148](https://redirect.github.com/honojs/hono/pull/5148) - fix(aws-lambda): add jwt and lambda authorizer types for API Gateway v2 in [#&#8203;5142](https://redirect.github.com/honojs/hono/pull/5142) - fix(sse): emit empty id field to reset Last-Event-ID in [#&#8203;5138](https://redirect.github.com/honojs/hono/pull/5138) - test(cloudflare-workers): add coverage for onClose, onError, send, and close in Cloudflare Workers websocket adapter in [#&#8203;5145](https://redirect.github.com/honojs/hono/pull/5145) - fix: use `Object.create(null)` when parsing query, headers, and params in [#&#8203;5161](https://redirect.github.com/honojs/hono/pull/5161) - fix(secure-headers): keep CSP callbacks scoped to their header in [#&#8203;5147](https://redirect.github.com/honojs/hono/pull/5147) **Full Changelog**: <honojs/hono@v4.12.31...v4.12.32> </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/CodeForBreakfast/commy). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMCIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZS9uZWVkcy1yZXZpZXciXX0=--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
1 parent 258feaa commit 42f2a9f

2 files changed

Lines changed: 3 additions & 3 deletions

File tree

‎bun.lock‎

Lines changed: 2 additions & 2 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎package.json‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -33,7 +33,7 @@
3333
},
3434
"overrides": {
3535
"undici": "^7.29.1",
36-
"hono": "^4.12.31",
36+
"hono": "^4.13.8",
3737
"ws": "^8.21.3",
3838
"fast-uri": "^4.2.1"
3939
},

0 commit comments

Comments
 (0)