Skip to content

Bump hono from 4.12.12 to 4.12.21 - #240

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/hono-4.12.21
Closed

Bump hono from 4.12.12 to 4.12.21#240
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/hono-4.12.21

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 4, 2026

Copy link
Copy Markdown
Contributor

Bumps hono from 4.12.12 to 4.12.21.

Release notes

Sourced from hono's releases.

v4.12.21

Security fixes

This release includes fixes for the following security issues:

app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded paths

Affects: app.mount(). Fixes prefix stripping using the raw URL pathname instead of the decoded path, where percent-encoded characters in the mount prefix or path could cause the prefix to be removed at the wrong position, resulting in the sub-application receiving an incorrect path. GHSA-2gcr-mfcq-wcc3

IP Restriction bypasses static deny rules for non-canonical IPv6

Affects: hono/ip-restriction. Fixes IP address comparison using string equality, where non-canonical IPv6 representations of a denied address — such as compressed forms or hex-notation IPv4-mapped addresses — could bypass static deny rules. GHSA-xrhx-7g5j-rcj5

Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injection

Affects: hono/cookie. Fixes missing validation of sameSite and priority options against injection characters (;, \r, \n), where user-controlled input passed to either option could inject additional attributes into the Set-Cookie response header. GHSA-3hrh-pfw6-9m5x

JWT middleware accepts any Authorization scheme, not only Bearer

Affects: hono/jwt, hono/jwk. Fixes missing scheme validation in the Authorization header, where any two-part header value was accepted regardless of the scheme name, allowing non-Bearer schemes to pass JWT authentication. GHSA-f577-qrjj-4474


Users who use app.mount(), hono/ip-restriction, hono/cookie, or hono/jwt/hono/jwk are encouraged to upgrade to this version.

v4.12.20

What's Changed

New Contributors

Full Changelog: honojs/hono@v4.12.19...v4.12.20

v4.12.19

What's Changed

New Contributors

Full Changelog: honojs/hono@v4.12.18...v4.12.19

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [hono](https://github.com/honojs/hono) from 4.12.12 to 4.12.21.
- [Release notes](https://github.com/honojs/hono/releases)
- [Commits](honojs/hono@v4.12.12...v4.12.21)

---
updated-dependencies:
- dependency-name: hono
  dependency-version: 4.12.21
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jun 4, 2026
@netlify

netlify Bot commented Jun 4, 2026

Copy link
Copy Markdown

Deploy Preview for servicestart ready!

Name Link
🔨 Latest commit eb1658c
🔍 Latest deploy log https://app.netlify.com/projects/servicestart/deploys/6a21e7e1d8e354000830487e
😎 Deploy Preview https://deploy-preview-240--servicestart.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
🤖 Make changes Run an agent on this branch

To edit notification comments on pull requests, go to your Netlify project configuration.

@greptile-apps

greptile-apps Bot commented Jun 4, 2026

Copy link
Copy Markdown
Contributor

Greptile Summary

This PR bumps hono from 4.12.12 to 4.12.21, a patch-level update that includes four security fixes and several bug fixes across intermediate releases.

  • Security fixes in 4.12.21: patches app.mount() prefix-stripping with percent-encoded paths (GHSA-2gcr-mfcq-wcc3), non-canonical IPv6 bypass in hono/ip-restriction (GHSA-xrhx-7g5j-rcj5), Set-Cookie header injection via unsanitized sameSite/priority in hono/cookie (GHSA-3hrh-pfw6-9m5x), and JWT middleware accepting non-Bearer schemes (GHSA-f577-qrjj-4474).
  • Other changes: fixes to route base-path preservation (4.12.20), serveStatic optional params, duplicate-cookie handling, stream abort handling, and new bearerAuth generic typing (4.12.13–4.12.19).

Confidence Score: 5/5

Safe to merge — this is a straightforward patch bump that delivers security hardening with no breaking changes expected.

The change touches only the hono version in package.json and the corresponding lock file. All intermediate releases are patch-level with no API removals, and the security advisories fixed here directly benefit the project's use of hono middleware.

No files require special attention.

Important Files Changed

Filename Overview
package.json Bumps hono dependency from ^4.12.12 to ^4.12.21, picking up 4 security fixes and several bug fixes.
pnpm-lock.yaml Lock file updated to resolve hono to 4.12.21 and align @hono/zod-validator peer dependency.

Flowchart

%%{init: {'theme': 'neutral'}}%%
flowchart TD
    A[hono 4.12.12] -->|bump| B[hono 4.12.21]
    B --> C[GHSA-2gcr-mfcq-wcc3\napp.mount percent-encode fix]
    B --> D[GHSA-xrhx-7g5j-rcj5\nIPv6 restriction bypass fix]
    B --> E[GHSA-3hrh-pfw6-9m5x\nSet-Cookie injection fix]
    B --> F[GHSA-f577-qrjj-4474\nJWT Bearer scheme fix]
    B --> G[Bug fixes\n4.12.13 - 4.12.20]
Loading

Reviews (1): Last reviewed commit: "Bump hono from 4.12.12 to 4.12.21" | Re-trigger Greptile

@dependabot @github

dependabot Bot commented on behalf of github Jun 19, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #242.

@dependabot dependabot Bot closed this Jun 19, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/hono-4.12.21 branch June 19, 2026 23:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants