Skip to content

fix(deps): bump hono, vitest and js-yaml for security advisories - #133

Merged
gnacho merged 1 commit into
mainfrom
chore/security-bumps
Sep 19, 2026
Merged

gnacho merged 1 commit into
mainfrom
chore/security-bumps

Conversation

@gnacho

@gnacho gnacho commented Sep 19, 2026

Copy link
Copy Markdown
Owner

Addresses the 6 open Dependabot alerts (1 high): hono 4.13.8 (parseBody nesting DoS, query parser fragment differential, toSSG incomplete fix), vitest 4.1.11 with @vitest/mocker 4.1.11 (path traversal in redirect mock) and transitive js-yaml 4.3.2 (CPU use via empty merge sources).

Server tests 107/107, tsc and build pass on the bumped versions.

hono 4.13.8 (parseBody nesting exhaustion, query parser fragment
differential, toSSG incomplete fix), vitest 4.1.11 (mocker path
traversal) and transitive js-yaml 4.3.2 (CPU use via empty merge
sources). Server tests and build pass on the bumped versions.
@gnacho
gnacho merged commit a7379b0 into main Sep 19, 2026
4 checks passed
@gnacho
gnacho deleted the chore/security-bumps branch September 19, 2026 20:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant