Scheduled `bun audit` found **3** advisories against the lockfile. | Advisory | Severity | Vulnerable versions | | --- | --- | --- | | [Hono: Incomplete fix for CVE-2026-39408: `toSSG()` still writes files outside the output directory](https://github.com/advisories/GHSA-gqvv-2mrq-wpjv) | moderate | <4.13.5 | | [Hono: Unbounded dot-notation nesting in `parseBody()` can cause memory exhaustion](https://github.com/advisories/GHSA-g6gw-c38x-mqfc) | moderate | <4.13.5 | | [Hono: Query parser reads parameters after the URL fragment, causing cache-key and proxy interpretation differentials](https://github.com/advisories/GHSA-crvj-82cr-hjcx) | moderate | <4.13.5 | **Workflow run:** https://github.com/Coriou/up-vector/actions/runs/34829406595
Scheduled
bun auditfound 3 advisories against the lockfile.toSSG()still writes files outside the output directoryparseBody()can cause memory exhaustionWorkflow run: https://github.com/Coriou/up-vector/actions/runs/34829406595