chore(deps-dev): bump ip-address from 10.2.0 to 10.4.0 and hono from 4.12.33 to 4.13.0 (#DS-5215) - #1851
Merged
Merged
Conversation
…4.12.33 to 4.13.0 (#DS-5215) Resolves four advisories, all reaching the tree through @angular/cli -> @modelcontextprotocol/sdk: ip-address 10.2.0 -> 10.4.0 (via express-rate-limit and socks) GHSA-mwp4-54f8-5fhr / CVE-2026-69192 (high) - leading-zero octets decoded as decimal, SSRF and trust-boundary bypass GHSA-4xrf-jv44-h6hh / CVE-2026-69198 - a CIDR suffix suppresses special-use classification GHSA-22jq-vg5j-6vgg / CVE-2026-54272 - IPv4-mapped/NAT64 misclassification hono 4.12.33 -> 4.13.0 GHSA-8j4g-w8fx-2239 / CVE-2026-69207 - ReDoS in the CORS middleware via Access-Control-Request-Headers Every parent range (^10.0.1, ^10.2.0, ^4.11.4) already admits the patched release, so this is a lockfile re-resolution via `yarn up -R` - no manifest change and no `resolutions` entry to carry forward.
|
Visit the preview URL for this PR (updated for commit d09ab07): https://koobiq-next--prs-1851-ja012tm3.web.app (expires Sat, 08 Aug 2026 15:57:50 GMT) 🔥 via Firebase Hosting GitHub Action 🌎 Sign: c9e37e518febda70d0317d07e8ceb35ac43c534c |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Resolves four advisories, all reaching the tree through @angular/cli -> @modelcontextprotocol/sdk:
ip-address 10.2.0 -> 10.4.0 (via express-rate-limit and socks)
GHSA-mwp4-54f8-5fhr / CVE-2026-69192 (high) - leading-zero octets decoded
as decimal, SSRF and trust-boundary bypass
GHSA-4xrf-jv44-h6hh / CVE-2026-69198 - a CIDR suffix suppresses
special-use classification
GHSA-22jq-vg5j-6vgg / CVE-2026-54272 - IPv4-mapped/NAT64 misclassification
hono 4.12.33 -> 4.13.0
GHSA-8j4g-w8fx-2239 / CVE-2026-69207 - ReDoS in the CORS middleware via
Access-Control-Request-Headers
Every parent range (^10.0.1, ^10.2.0, ^4.11.4) already admits the patched release, so this is a lockfile re-resolution via
yarn up -R- no manifest change and noresolutionsentry to carry forward.