Skip to content

Bump @hono/node-server from 1.19.9 to 1.19.14#2708

Open
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/npm_and_yarn/hono/node-server-1.19.14
Open

Bump @hono/node-server from 1.19.9 to 1.19.14#2708
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/npm_and_yarn/hono/node-server-1.19.14

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Apr 21, 2026

Bumps @hono/node-server from 1.19.9 to 1.19.14.

Release notes

Sourced from @​hono/node-server's releases.

v1.19.14

What's Changed

Full Changelog: honojs/node-server@v1.19.13...v1.19.14

v1.19.13

Security Fix

Fixed an issue in Serve Static Middleware where inconsistent handling of repeated slashes (//) between the router and static file resolution could allow middleware to be bypassed. Users of Serve Static Middleware are encouraged to upgrade to this version.

See GHSA-92pp-h63x-v22m for details.

v1.19.12

What's Changed

Full Changelog: honojs/node-server@v1.19.11...v1.19.12

v1.19.11

What's Changed

Full Changelog: honojs/node-server@v1.19.10...v1.19.11

v1.19.10

Security Fix

Fixed an authorization bypass in Serve Static Middleware caused by inconsistent URL decoding (%2F handling) between the router and static file resolution. Users of Serve Static Middleware are encouraged to upgrade to this version.

See GHSA-wc8c-qw6v-h7f6 for details.

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Apr 21, 2026
Copilot AI review requested due to automatic review settings April 21, 2026 21:13
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Apr 21, 2026
@dependabot dependabot Bot review requested due to automatic review settings April 21, 2026 21:13
Copilot AI review requested due to automatic review settings April 23, 2026 00:16
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/hono/node-server-1.19.14 branch from e7700b5 to a05f368 Compare April 23, 2026 00:16
@dependabot dependabot Bot review requested due to automatic review settings April 23, 2026 00:16
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/hono/node-server-1.19.14 branch from a05f368 to 638776d Compare April 23, 2026 00:32
@dependabot dependabot Bot requested review from Copilot and removed request for Copilot April 23, 2026 00:32
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/hono/node-server-1.19.14 branch from 638776d to f9f80d0 Compare April 23, 2026 00:40
@dependabot dependabot Bot requested review from Copilot and removed request for Copilot April 23, 2026 00:40
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/hono/node-server-1.19.14 branch from f9f80d0 to ee36778 Compare April 23, 2026 00:50
@dependabot dependabot Bot requested review from Copilot and removed request for Copilot April 23, 2026 00:50
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/hono/node-server-1.19.14 branch from ee36778 to bd592b4 Compare April 23, 2026 01:03
@dependabot dependabot Bot requested review from Copilot and removed request for Copilot April 23, 2026 01:03
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/hono/node-server-1.19.14 branch from bd592b4 to 0aeb0fe Compare April 23, 2026 01:11
@dependabot dependabot Bot review requested due to automatic review settings April 23, 2026 01:11
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/hono/node-server-1.19.14 branch from 0aeb0fe to 99adc1f Compare April 23, 2026 01:20
@dependabot dependabot Bot requested review from Copilot and removed request for Copilot April 23, 2026 01:20
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/hono/node-server-1.19.14 branch from 99adc1f to f973469 Compare April 23, 2026 01:39
@dependabot dependabot Bot requested review from Copilot and removed request for Copilot April 23, 2026 01:39
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/hono/node-server-1.19.14 branch from f973469 to 4636007 Compare April 23, 2026 01:47
@dependabot dependabot Bot review requested due to automatic review settings April 23, 2026 01:47
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/hono/node-server-1.19.14 branch from 4636007 to 4260579 Compare April 23, 2026 14:40
Bumps [@hono/node-server](https://github.com/honojs/node-server) from 1.19.9 to 1.19.14.
- [Release notes](https://github.com/honojs/node-server/releases)
- [Commits](honojs/node-server@v1.19.9...v1.19.14)

---
updated-dependencies:
- dependency-name: "@hono/node-server"
  dependency-version: 1.19.14
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/hono/node-server-1.19.14 branch from 4260579 to 60bff25 Compare April 24, 2026 17:55
@dependabot dependabot Bot requested review from Copilot and removed request for Copilot April 24, 2026 17:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants