chore(deps): bump the npm_and_yarn group across 2 directories with 15 updates - #690
chore(deps): bump the npm_and_yarn group across 2 directories with 15 updates#690dependabot[bot] wants to merge 1 commit into
Conversation
… updates Bumps the npm_and_yarn group with 15 updates in the / directory: | Package | From | To | | --- | --- | --- | | [@hono/node-server](https://github.com/honojs/node-server) | `1.19.14` | `2.0.10` | | [hono](https://github.com/honojs/hono) | `4.12.25` | `4.12.27` | | [axios](https://github.com/axios/axios) | `1.16.0` | `1.18.0` | | [next](https://github.com/vercel/next.js) | `16.2.10` | `16.2.11` | | [adm-zip](https://github.com/cthackers/adm-zip) | `0.5.10` | `0.5.18` | | [brace-expansion](https://github.com/juliangruber/brace-expansion) | `1.1.14` | `1.1.16` | | [engine.io](https://github.com/socketio/socket.io) | `6.5.4` | `6.5.5` | | [fast-uri](https://github.com/fastify/fast-uri) | `3.1.2` | `3.1.4` | | [http-proxy-middleware](https://github.com/chimurai/http-proxy-middleware) | `3.0.5` | `3.0.7` | | [js-yaml](https://github.com/nodeca/js-yaml) | `3.14.2` | `3.15.0` | | [morgan](https://github.com/expressjs/morgan) | `1.10.1` | `1.11.0` | | [shell-quote](https://github.com/ljharb/shell-quote) | `1.8.4` | `1.10.0` | | [sigstore](https://github.com/sigstore/sigstore-js) | `3.0.0` | `3.1.0` | | [undici](https://github.com/nodejs/undici) | `6.25.0` | `6.27.0` | | [websocket-driver](https://github.com/faye/websocket-driver-node) | `0.7.4` | `0.7.5` | Bumps the npm_and_yarn group with 1 update in the /e2e/hono directory: [@hono/node-server](https://github.com/honojs/node-server). Updates `@hono/node-server` from 1.19.14 to 2.0.10 - [Release notes](https://github.com/honojs/node-server/releases) - [Commits](honojs/node-server@v1.19.14...v2.0.10) Updates `hono` from 4.12.25 to 4.12.27 - [Release notes](https://github.com/honojs/hono/releases) - [Commits](honojs/hono@v4.12.25...v4.12.27) Updates `axios` from 1.16.0 to 1.18.0 - [Release notes](https://github.com/axios/axios/releases) - [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md) - [Commits](axios/axios@v1.16.0...v1.18.0) Updates `next` from 16.2.10 to 16.2.11 - [Release notes](https://github.com/vercel/next.js/releases) - [Commits](vercel/next.js@v16.2.10...v16.2.11) Updates `adm-zip` from 0.5.10 to 0.5.18 - [Release notes](https://github.com/cthackers/adm-zip/releases) - [Changelog](https://github.com/cthackers/adm-zip/blob/master/history.md) - [Commits](cthackers/adm-zip@v0.5.10...v0.5.18) Updates `brace-expansion` from 1.1.14 to 1.1.16 - [Release notes](https://github.com/juliangruber/brace-expansion/releases) - [Commits](juliangruber/brace-expansion@v1.1.14...v1.1.16) Updates `engine.io` from 6.5.4 to 6.5.5 - [Release notes](https://github.com/socketio/socket.io/releases) - [Changelog](https://github.com/socketio/socket.io/blob/main/CHANGELOG.md) - [Commits](https://github.com/socketio/socket.io/commits) Updates `fast-uri` from 3.1.2 to 3.1.4 - [Release notes](https://github.com/fastify/fast-uri/releases) - [Commits](fastify/fast-uri@v3.1.2...v3.1.4) Updates `http-proxy-middleware` from 3.0.5 to 3.0.7 - [Release notes](https://github.com/chimurai/http-proxy-middleware/releases) - [Changelog](https://github.com/chimurai/http-proxy-middleware/blob/v3.0.7/CHANGELOG.md) - [Commits](chimurai/http-proxy-middleware@v3.0.5...v3.0.7) Updates `js-yaml` from 3.14.2 to 3.15.0 - [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md) - [Commits](nodeca/js-yaml@3.14.2...3.15.0) Updates `morgan` from 1.10.1 to 1.11.0 - [Release notes](https://github.com/expressjs/morgan/releases) - [Changelog](https://github.com/expressjs/morgan/blob/master/HISTORY.md) - [Commits](expressjs/morgan@1.10.1...1.11.0) Updates `shell-quote` from 1.8.4 to 1.10.0 - [Changelog](https://github.com/ljharb/shell-quote/blob/main/CHANGELOG.md) - [Commits](ljharb/shell-quote@v1.8.4...v1.10.0) Updates `sigstore` from 3.0.0 to 3.1.0 - [Release notes](https://github.com/sigstore/sigstore-js/releases) - [Commits](https://github.com/sigstore/sigstore-js/compare/sigstore@3.0.0...sigstore@3.1.0) Updates `undici` from 6.25.0 to 6.27.0 - [Release notes](https://github.com/nodejs/undici/releases) - [Commits](nodejs/undici@v6.25.0...v6.27.0) Updates `websocket-driver` from 0.7.4 to 0.7.5 - [Changelog](https://github.com/faye/websocket-driver-node/blob/main/CHANGELOG.md) - [Commits](faye/websocket-driver-node@0.7.4...0.7.5) Updates `@hono/node-server` from 1.19.14 to 2.0.11 - [Release notes](https://github.com/honojs/node-server/releases) - [Commits](honojs/node-server@v1.19.14...v2.0.10) --- updated-dependencies: - dependency-name: "@hono/node-server" dependency-version: 2.0.10 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: hono dependency-version: 4.12.27 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: axios dependency-version: 1.18.0 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: next dependency-version: 16.2.11 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: adm-zip dependency-version: 0.5.18 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: brace-expansion dependency-version: 1.1.16 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: engine.io dependency-version: 6.5.5 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: fast-uri dependency-version: 3.1.4 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: http-proxy-middleware dependency-version: 3.0.7 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: js-yaml dependency-version: 3.15.0 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: morgan dependency-version: 1.11.0 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: shell-quote dependency-version: 1.10.0 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: sigstore dependency-version: 3.1.0 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: undici dependency-version: 6.27.0 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: websocket-driver dependency-version: 0.7.5 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: "@hono/node-server" dependency-version: 2.0.11 dependency-type: direct:production dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using default effort and found 2 potential issues.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit dd60470. Configure here.
| "dependencies": { | ||
| "@highlight-run/hono": "workspace:*", | ||
| "@hono/node-server": "^1.13.7", | ||
| "@hono/node-server": "^2.0.11", |
There was a problem hiding this comment.
Root resolution blocks node-server v2
High Severity
This change bumps e2e/hono to @hono/node-server v2 for the WebSocket DoS fix, but the root package.json resolutions entry still forces @hono/node-server to ^1.19.13. Yarn applies that override workspace-wide, so the Hono e2e app keeps resolving to 1.19.14 and never receives the v2 security release.
Reviewed by Cursor Bugbot for commit dd60470. Configure here.
| "dependencies": { | ||
| "@highlight-run/hono": "workspace:*", | ||
| "@hono/node-server": "^1.13.7", | ||
| "@hono/node-server": "^2.0.11", |
There was a problem hiding this comment.
Lockfile range mismatches package.json
Medium Severity
e2e/hono/package.json requests @hono/node-server at ^2.0.11, but the highlight-hono-example workspace entry in yarn.lock still records npm:^2.0.10. That mismatch can fail yarn install --immutable in CI and leaves the lockfile out of sync with the manifest.
Additional Locations (1)
Reviewed by Cursor Bugbot for commit dd60470. Configure here.
|
Looks like these dependencies are updatable in another way, so this is no longer needed. |


Bumps the npm_and_yarn group with 15 updates in the / directory:
1.19.142.0.104.12.254.12.271.16.01.18.016.2.1016.2.110.5.100.5.181.1.141.1.166.5.46.5.53.1.23.1.43.0.53.0.73.14.23.15.01.10.11.11.01.8.41.10.03.0.03.1.06.25.06.27.00.7.40.7.5Bumps the npm_and_yarn group with 1 update in the /e2e/hono directory: @hono/node-server.
Updates
@hono/node-serverfrom 1.19.14 to 2.0.10Release notes
Sourced from @hono/node-server's releases.
... (truncated)
Commits
7c1457e2.0.103a21938Merge commit from fork98420212.0.951f3bf5fix: recover complete request bodies after client disconnect (#375)fdb87bafix(serve-static): correct Range header parsing edge cases (#372)912e3fdfix(websocket): polyfill missing ErrorEvent global (#371)114c15e2.0.85db2d5dci(release): add--no-git-checksoption forpnpm stage publish(#369)a528a772.0.7b2d610cchore: bumpsupertest(#368)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for
@hono/node-serversince your current version.Updates
honofrom 4.12.25 to 4.12.27Release notes
Sourced from hono's releases.
Commits
97c6fe14.12.27aa92177Merge commit from forkcd3f6f7Merge commit from forkd4853a8fix(jsx): make merged context-isolation tests pass tsc type check (#5037)6735feafix(jsx): cast awaitedFallback through unknown to fix Deno type check (#5036)fab3b13Merge commit from fork9f0dadfci: use npm Staged publishing (#5035)27b79924.12.26d29982cchore: replace arg and glob with Bun native APIs in build script16215d5chore: remove unused devcontainer and gitpod configs (#5029)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for hono since your current version.
Updates
axiosfrom 1.16.0 to 1.18.0Release notes
Sourced from axios's releases.
... (truncated)
Changelog
Sourced from axios's changelog.
... (truncated)
Commits
2d06f96chore(release): prepare release 1.18.0 (#11003)32fc489fix: malformed http urls (#11000)b40ce49chore(deps-dev): bump the development_dependencies group with 10 updates (#10...fe964f9docs: mark proxy config as Node.js only (#10995)5f229d2chore(deps): bump actions/checkout from 6.0.2 to 6.0.3 in the github-actions ...fae9d4edocs: clarify package update PR policy (#10992)28ab2cechore(deps-dev): bump the development_dependencies group with 2 updates (#10989)a8e4f13fix(core): keep default validateStatus when request passes undefined (#10899)614f455docs: publish v1.17.0 release notes (#10988)6bb12c1fix: custom auth headers not stripped on cross-origin redirects (#10892)Updates
nextfrom 16.2.10 to 16.2.11Release notes
Sourced from next's releases.
Commits
9beca08v16.2.113c48c7a[16.x] Fix Turbopack middleware matcher with i18n single localeac1eff3[16.x] Improve performance of checking valid MPA form submissions9a4651e[16.x] EnforceserverActions.bodySizeLimitfor Server Actions in Edge runtimeb512063[16.x] Set correct origin for internal redirects in custom serverd303326[16.x] Ensure exotic rewrite param values are properly encoded73b9487[16.x] fix(fetch-cache): key fetch(Request, init) by the effective requestbf9d17f[16.x] fix(incremental-cache): byte-exact fetch cache key for binary bodiesfe28768[16.x] fix(next/image): improve performance of detectContentType()d8afb8d[16.x] Performance improvements when decoding React Server function payloadsUpdates
adm-zipfrom 0.5.10 to 0.5.18Release notes
Sourced from adm-zip's releases.
... (truncated)
Commits
8592b15Incremented version4c61451Merge pull request #563 from JohnJunior/fix/empty-dir-versionafd618eFixed jsdocs7d41d71Fixed sanitize bugedd43edUpdate author and bug report email in package.json83ac9f3Add security section to README692ae21Enhance security policy with vulnerability reporting details46279d7Merge pull request #562 from mielverkerken/masterb091814Merge pull request #551 from matt-fidd/webpack-crashe5b2dd8Merge pull request #564 from JohnJunior/fix/issue-555-data-descriptorUpdates
brace-expansionfrom 1.1.14 to 1.1.16Release notes
Sourced from brace-expansion's releases.
Commits
447763a1.1.16d74e630fix: v1 backport for CVE-2026-13149 (#122)2203f4f1.1.150b09384Backport v5.0.6 change to v1 (#111)Updates
engine.iofrom 6.5.4 to 6.5.5Commits
Updates
fast-urifrom 3.1.2 to 3.1.4Release notes
Sourced from fast-uri's releases.
Commits
6aeece6Bumped v3.1.42d50fbafix: reject literal backslash in URI authority0549fe3Bumped v3.1.32a6d357Merge commit from forkUpdates
http-proxy-middlewarefrom 3.0.5 to 3.0.7Release notes
Sourced from http-proxy-middleware's releases.
... (truncated)
Changelog
Sourced from http-proxy-middleware's changelog.
Commits
8cc4ebachore(package.json): v3.0.7 (#1261)c13a99cfix(fixRequestBody): harden form-data stringification (#1259)ea0bb98chore(package.json): v3.0.6 (#1256)f377520fix(router): harden proxy-table matching (#1254)f6be2c6chore(yarn.lock): bump to follow-redirects 1.16.0a36f009ci(publish.yml): npm stage publish3471790ci(github actions): update publish.yml for 3.x branchbcf1864build(vscode): use workspace version of TypeScript (#1173)48ed092docs(examples): fix websocket example (#1170)0fe7c24chore(package.json): bump dev-deps (#1171)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for http-proxy-middleware since your current version.
Updates
js-yamlfrom 3.14.2 to 3.15.0Changelog
Sourced from js-yaml's changelog.
... (truncated)
Commits
c34b6c43.15.0 released21e13d3dist rebuild4165c62Add v3-legacy tag for publishd8ff750Add package lock24f13e7AddedmaxTotalMergeKeys(10000) loader option (v5 backport)Updates
morganfrom 1.10.1 to 1.11.0Release notes
Sourced from morgan's releases.