Skip to content

Bump hono from 4.13.8 to 4.13.11 in /starter-kits/javascript/typescript-hono in the npm group across 1 directory - #89

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/starter-kits/javascript/typescript-hono/npm-2969ace3be
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/starter-kits/javascript/typescript-hono/npm-2969ace3be

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the npm group with 1 update in the /starter-kits/javascript/typescript-hono directory: hono.

Updates hono from 4.13.8 to 4.13.11

Release notes

Sourced from hono's releases.

v4.13.11

Security fixes

serveStatic decodes the request path a second time, leading to bypass of middleware on static paths

Affects: hono/serve-static and the adapters built on it (hono/bun, hono/deno, hono/cloudflare-workers, @hono/bun, @hono/deno, @hono/cloudflare-workers). Fixes serveStatic decoding an already-decoded path, where a crafted request could be routed as one path and served as another, skipping middleware mounted on a static prefix. GHSA-5r4p-p66f-jhc7

serveStatic now rejects request paths that still contain % after decoding. To serve files whose names contain a literal %, set allowPercentInPath: true.

The same fix ships in @hono/node-server v2.1.3.

v4.13.10

Adapters are now separate packages

The runtime adapters are now published as their own packages: @hono/bun, @hono/deno, @hono/cloudflare-workers, @hono/aws-lambda, @hono/lambda-edge, @hono/netlify, @hono/vercel, and @hono/service-worker. @hono/deno is also on JSR.

hono/<adapter> still works in v4 but is deprecated and will be removed in v5. Migrating is an import change:

- import { serveStatic } from 'hono/bun'
+ import { serveStatic } from '@hono/bun'

hono/cloudflare-pages is deprecated without a replacement package; Cloudflare recommends Workers with static assets.

What's Changed

Full Changelog: honojs/hono@v4.13.9...v4.13.10

v4.13.9

What's Changed

  • fix(jsx): replace Suspense and ErrorBoundary content across newlines in honojs/hono#5380

... (truncated)

Commits

@dependabot
dependabot Bot requested a review from a team as a code owner October 6, 2026 06:08
@dependabot
dependabot Bot requested a review from kailan October 6, 2026 06:08
Bumps the npm group with 1 update in the /starter-kits/javascript/typescript-hono directory: [hono](https://github.com/honojs/hono).


Updates `hono` from 4.13.8 to 4.13.11
- [Release notes](https://github.com/honojs/hono/releases)
- [Commits](honojs/hono@v4.13.8...v4.13.11)

---
updated-dependencies:
- dependency-name: hono
  dependency-version: 4.13.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title Bump hono from 4.13.8 to 4.13.10 in /starter-kits/javascript/typescript-hono in the npm group across 1 directory Bump hono from 4.13.8 to 4.13.11 in /starter-kits/javascript/typescript-hono in the npm group across 1 directory Oct 6, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/starter-kits/javascript/typescript-hono/npm-2969ace3be branch from e56ee97 to 8a3dbd3 Compare October 6, 2026 18:05

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants