Skip to content

deps: bump @hono/node-server from 1.19.9 to 1.19.14#142

Merged
jbdevprimary merged 1 commit into
mainfrom
dependabot/npm_and_yarn/hono/node-server-1.19.14
May 15, 2026
Merged

deps: bump @hono/node-server from 1.19.9 to 1.19.14#142
jbdevprimary merged 1 commit into
mainfrom
dependabot/npm_and_yarn/hono/node-server-1.19.14

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github May 14, 2026

Bumps @hono/node-server from 1.19.9 to 1.19.14.

Release notes

Sourced from @​hono/node-server's releases.

v1.19.14

What's Changed

Full Changelog: honojs/node-server@v1.19.13...v1.19.14

v1.19.13

Security Fix

Fixed an issue in Serve Static Middleware where inconsistent handling of repeated slashes (//) between the router and static file resolution could allow middleware to be bypassed. Users of Serve Static Middleware are encouraged to upgrade to this version.

See GHSA-92pp-h63x-v22m for details.

v1.19.12

What's Changed

Full Changelog: honojs/node-server@v1.19.11...v1.19.12

v1.19.11

What's Changed

Full Changelog: honojs/node-server@v1.19.10...v1.19.11

v1.19.10

Security Fix

Fixed an authorization bypass in Serve Static Middleware caused by inconsistent URL decoding (%2F handling) between the router and static file resolution. Users of Serve Static Middleware are encouraged to upgrade to this version.

See GHSA-wc8c-qw6v-h7f6 for details.

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels May 14, 2026
@dependabot dependabot Bot requested a review from jbdevprimary as a code owner May 14, 2026 21:51
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels May 14, 2026
jbdevprimary
jbdevprimary previously approved these changes May 15, 2026
@jbdevprimary jbdevprimary enabled auto-merge (squash) May 15, 2026 07:06
Bumps [@hono/node-server](https://github.com/honojs/node-server) from 1.19.9 to 1.19.14.
- [Release notes](https://github.com/honojs/node-server/releases)
- [Commits](honojs/node-server@v1.19.9...v1.19.14)

---
updated-dependencies:
- dependency-name: "@hono/node-server"
  dependency-version: 1.19.14
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/hono/node-server-1.19.14 branch from 85e6731 to f63a413 Compare May 15, 2026 07:08
@jbdevprimary jbdevprimary merged commit f698e84 into main May 15, 2026
@jbdevprimary jbdevprimary deleted the dependabot/npm_and_yarn/hono/node-server-1.19.14 branch May 15, 2026 07:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant