Skip to content

chore(deps): update dependency hono to v4.13.13 - #117

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/hono-4.x-lockfile
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/hono-4.x-lockfile

Conversation

@renovate

@renovate renovate Bot commented Aug 30, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
hono (source) 4.12.33 → 4.13.13 age confidence

Release Notes

honojs/hono (hono)

v4.13.13

Compare Source

Mount Middleware

app.mount() is now available as the Mount Middleware, hono/mount. It is just a handler, so you register it with app.all():

import { Router as IttyRouter } from 'itty-router'
import { Hono } from 'hono'
import { mount } from 'hono/mount'

const ittyRouter = IttyRouter()
ittyRouter.get('/hello', () => new Response('Hello from itty-router'))

const app = new Hono()
app.all('/itty-router/*', mount(ittyRouter.handle))

app.mount() still works in v4 but is deprecated and will be removed in v5. Migrating is a one-line change:

- app.mount('/itty-router', ittyRouter.handle)
+ app.all('/itty-router/*', mount(ittyRouter.handle))

What's Changed

  • test(client): simulate network error for undefined route in parseResponse test in #​5439
  • docs(request): fix jsdoc comments for some getters in #​5445
  • fix(jsx): allow JSXNode function component results in #​5476
  • feat(mount): introduce Mount Middleware and deprecate app.mount in #​5221

Full Changelog: honojs/hono@v4.13.12...v4.13.13

v4.13.12

Compare Source

What's Changed

  • fix(build): keep internal types private in bundled d.ts and avoid a self-referencing JSX.IntrinsicElements in #​5485
  • test(build): type-check the bundled declarations from a consumer project in #​5486
  • fix(etag): correctly match mixed-case header name in retainedHeader option in #​5475
  • fix(jsx): add px to numeric gridGap, gridRowGap and gridColumnGap in #​5487
  • fix(combine): return a Response from a short-circuiting middleware in some() in #​5391
  • chore(deps): upgrade vite-plus to 1.0.0 in #​5464

Full Changelog: honojs/hono@v4.13.11...v4.13.12

v4.13.11

Compare Source

Security fixes

serveStatic decodes the request path a second time, leading to bypass of middleware on static paths

Affects: hono/serve-static and the adapters built on it (hono/bun, hono/deno, hono/cloudflare-workers, @hono/bun, @hono/deno, @hono/cloudflare-workers). Fixes serveStatic decoding an already-decoded path, where a crafted request could be routed as one path and served as another, skipping middleware mounted on a static prefix. GHSA-5r4p-p66f-jhc7

serveStatic now rejects request paths that still contain % after decoding. To serve files whose names contain a literal %, set allowPercentInPath: true.

The same fix ships in @hono/node-server v2.1.3.

v4.13.10

Compare Source

Adapters are now separate packages

The runtime adapters are now published as their own packages: @hono/bun, @hono/deno, @hono/cloudflare-workers, @hono/aws-lambda, @hono/lambda-edge, @hono/netlify, @hono/vercel, and @hono/service-worker. @hono/deno is also on JSR.

hono/<adapter> still works in v4 but is deprecated and will be removed in v5. Migrating is an import change:

- import { serveStatic } from 'hono/bun'
+ import { serveStatic } from '@hono/bun'

hono/cloudflare-pages is deprecated without a replacement package; Cloudflare recommends Workers with static assets.

What's Changed

  • chore: migrate the package manager from bun to pnpm in #​5433
  • chore(package.json): invoke package scripts through pnpm instead of bun in #​5434
  • chore: replace prettier with oxfmt in #​5435
  • chore(deps): upgrade vitest to 5.0.1 in #​5437
  • chore: let oxfmt sort imports instead of eslint in #​5442
  • chore: replace eslint with oxlint in #​5443
  • chore: introduce Vite+ in #​5444
  • fix(types): allow returning a Blob as a response body in #​5446
  • chore: convert build scripts into plugins in #​5448
  • chore: stop editorconfig-checker from checking Markdown indent size in #​5455
  • ci: remove empty step left in cr.yml by the pnpm migration in #​5456
  • chore(deps): upgrade vite-plus to 1.0.0-rc.1 in #​5459
  • feat(adapters): add @​hono/bun as a workspace package in #​5447
  • chore(adapters/bun): ship ESM only in #​5462
  • feat(adapters): add the seven adapters as workspace packages in #​5463
  • feat(adapters/deno): publish to JSR in #​5465
  • test: move adapter runtime tests into adapters/* in #​5466

Full Changelog: honojs/hono@v4.13.9...v4.13.10

v4.13.9

Compare Source

What's Changed

  • fix(jsx): replace Suspense and ErrorBoundary content across newlines in #​5380
  • fix(accepts): match media types and language tags case-insensitively in #​5376
  • fix(linear-router): don't match an empty path segment as a param in #​5373
  • fix(pretty-json): don't break responses with unparseable JSON bodies in #​5377
  • fix(jwt): throw JwtTokenInvalid when the signature is not valid base64url in #​5379
  • fix(aws-lambda): treat binary +xml archive media types as binary in #​5424
  • fix(aws-lambda): preserve empty query parameters in #​5292
  • fix(lambda-edge): sync content type detection with aws-lambda in #​5426
  • fix(lambda-edge): fail with a descriptive error on a malformed event in #​5358

Full Changelog: honojs/hono@v4.13.8...v4.13.9

v4.13.8

Compare Source

What's Changed

  • docs: fix typos in code comments and link third-party middleware section in #​5343
  • perf(jsx/dom): reduce lookup work for large keyed updates in #​5340
  • fix(aws-lambda): respect backpressure when streaming the response body in #​5351
  • fix(accepts, language): skip accept entries with quality 0 when matching in #​5311
  • fix(accept): treat the q parameter name as case-insensitive in #​5349
  • fix(accept): clamp a negative q to 0, not 1 in #​5357
  • fix(request): keep the request media type when reusing a cached body in #​5366
  • docs(combine): fix except() JSDoc param and add missing @​returns in #​5346
  • perf(jsx/dom): optimize matching-head child lookup during reconciliation in #​5329

Full Changelog: honojs/hono@v4.13.7...v4.13.8

v4.13.7

Compare Source

v4.13.6

Compare Source

v4.13.5

Compare Source

v4.13.4

Compare Source

v4.13.3

Compare Source

What's Changed

  • fix(client): prevent URL corruption when replaceUrlParam contains $ replacement tokens in #​5227
  • fix(etag): copy pending stream bytes in #​5239
  • fix(etag): avoid skipping headers when filtering 304 response headers in #​5234
  • fix(cors): append Origin to Vary header on OPTIONS preflight in #​5235
  • docs(context): add custom headers append option example to Context JSDoc in #​5248
  • fix(trie-router): match suffix wildcard routes in #​5236
  • fix(pattern-router/linear-router): prevent prefix overmatch on wildcard routes in #​5252
  • fix(csrf): exempt OPTIONS request from CSRF validation in #​5250
  • fix(utils/ipaddr): avoid truncation on embedded IPv4 addresses in expand IPv6 in #​5247
  • feat(pretty-json): support structured JSON content-types (+json) in #​5226

Full Changelog: honojs/hono@v4.13.2...v4.13.3

v4.13.2

Compare Source

What's Changed

  • fix(secure-headers): output standard empty parentheses () instead of none for disabled Permissions-Policy directives in #​5197
  • fix(jsx): render async children of document metadata tags instead of [object Promise] in #​5204
  • fix(etag): resolve incorrect incremental hashing for chunked responses in #​5199
  • fix(client): serialize multiple cookies correctly in #​5202
  • fix(etag): stabilize digest across stream chunks in #​5205
  • fix(url): strip trailing question mark correctly for optional params with regex quantifiers in #​5209
  • perf(cors): pre-join static array header options during initialization in #​5210
  • fix(client): send falsy JSON bodies in #​5215
  • feat(secure-headers): add missing W3C Permissions-Policy directives in #​5214

Full Changelog: honojs/hono@v4.13.1...v4.13.2

v4.13.1

Compare Source

v4.13.0

Compare Source

Hono v4.13.0 is now available!

The highlight of this release is performance: a batch of low-level optimizations makes the core request/response path significantly faster — up to 1.25x on common routes in our benchmark. This release also adds first-class support for the HTTP QUERY method, defined in RFC 10008, a new Method Not Allowed middleware, and more.

Performance improvements

This release includes a series of small optimizations: skipping unnecessary Headers allocations, replacing regex tests with indexOf, allocating internal state lazily, and more.

Here is benchmarks/fetch comparing v4.12 and v4.13 (ROUNDS=5 ./compare.sh, Bun 1.4.0, Apple Silicon — each measurement runs in a fresh process, and the variant order is reversed every round to avoid warm-up bias):

Benchmark v4.12 v4.13 Speedup
ping — GET / 165.83 ns 163.99 ns 1.01x
query — GET /id/1?name=bun 674.40 ns 616.99 ns 1.09x
json — GET /user 528.99 ns 422.44 ns 1.25x
body — POST /json 1.16 µs 1.00 µs 1.15x

The individual changes:

  • perf(context): iterate the header record with for..in #​5118
  • perf(url): replace regex tests with indexOf #​5121
  • perf(context): skip Headers creation when there are no headers to merge #​5122
  • perf(urls): refactor tryDecodeURIComponent #​5158
  • perf(request): allocate #validatedData lazily #​5175
  • perf(request): probe the body cache without allocating #​5176

In addition, the RegExpRouter rewrite described below makes route registration plus the first match roughly 20% faster.

Thanks @​kibertoad for the contributions!

First-class QUERY method support

The QUERY method — a safe, idempotent method that carries a request body — is now a first-class citizen in Hono. You can define QUERY handlers with app.query():

const app = new Hono()

app.query('/search', async (c) => {
  const conditions = await c.req.json()
  return c.json(await search(conditions))
})

Thanks @​shellhaki!

QUERY support across built-in middleware

The built-in middleware has been updated to handle QUERY requests properly:

Cache Middleware

The Cache Middleware now caches QUERY responses. Following RFC 10008 Section 2.7, the cache key incorporates a SHA-256 digest of the request content and its representation metadata, so different query bodies are cached separately:

app.query(
  '/search',
  cache({
    cacheName: 'search-cache',
    cacheControl: 'max-age=3600',
  })
)

Note: To support this, the internal cache key format has changed for all methods, including GET. Cached entries are now stored under an internal URL of the form /.hono/cache?__hono_cache_key=.... If you purge cache entries by URL outside of the middleware (e.g. calling caches.delete() with the original request URL), you will need to update that logic. Existing cache entries stored with the old format will simply be re-fetched.

ETag Middleware

The ETag Middleware now handles conditional requests for QUERY, returning 304 Not Modified when If-None-Match matches.

CORS Middleware

The CORS Middleware now includes QUERY in the default Access-Control-Allow-Methods, which is now GET, HEAD, PUT, POST, DELETE, PATCH, QUERY. If you specify allowMethods explicitly, nothing changes for you.

Thanks @​usualoma and @​Cherry!

Method Not Allowed Middleware

The new Method Not Allowed Middleware returns a 405 Method Not Allowed response with a proper Allow header when the request path matches a registered route but the method does not:

import { methodNotAllowed } from 'hono/method-not-allowed'

const app = new Hono()

app.use(methodNotAllowed({ app }))

app.get('/hello', (c) => c.text('Hello!'))
app.post('/hello', (c) => c.text('Posted!'))

// PUT /hello -> 405 Method Not Allowed
// Allow: GET, HEAD, POST

You can customize the response with the onMethodNotAllowed option:

app.use(
  methodNotAllowed({
    app,
    onMethodNotAllowed: (c, methods) =>
      c.json({ error: 'Method Not Allowed' }, 405, { Allow: methods.join(', ') }),
  })
)

Thanks @​usualoma!

RegExpRouter throws UnsupportedPathError at registration time

The RegExpRouter now detects unsupported path combinations when routes are registered, instead of at the first matching request. This means misconfigured routes fail fast at startup rather than at runtime. As a bonus, registration plus the first match is roughly 20% faster.

Thanks @​usualoma!

Other improvements

  • hono/utils/headers has been synced with the IANA HTTP Field Name Registry, adding newly registered fields such as Accept-Query. Thanks @​akahoshi1421!
  • The JWT and JWK middleware now accept a realm option for the WWW-Authenticate challenge on 401 responses, and challenge values are properly escaped. Thanks @​arhxam!
  • JSX: useRef and RefObject are now aligned with React 19. Note that this is a type-level change — RefObject<T> is now { current: T }, so type a nullable ref as RefObject<T | null>, and pass useRef(undefined) instead of useRef(). Thanks @​ashunar0!
  • JSX: a function component can now return an array of children without throwing during server-side rendering. Thanks @​natsuki-engr!
  • The Compress Middleware now sets Vary: Accept-Encoding on negotiated responses. Thanks @​arhxam!

All changes

Full Changelog: honojs/hono@v4.12.34...v4.13.0

Thank you to all contributors!

v4.12.34

Compare Source


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@socket-security

socket-security Bot commented Aug 30, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedhono@​4.12.33 ⏵ 4.13.1399100 +219796 +2100

View full report

@renovate
renovate Bot force-pushed the renovate/hono-4.x-lockfile branch 2 times, most recently from a625c32 to e740079 Compare September 4, 2026 19:22
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.13.5 chore(deps): update dependency hono to v4.13.6 Sep 4, 2026
@renovate
renovate Bot force-pushed the renovate/hono-4.x-lockfile branch from e740079 to 196264b Compare September 4, 2026 20:32
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.13.6 chore(deps): update dependency hono to v4.13.7 Sep 4, 2026
@renovate
renovate Bot force-pushed the renovate/hono-4.x-lockfile branch from 196264b to 5333d84 Compare September 15, 2026 08:25
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.13.7 chore(deps): update dependency hono to v4.13.8 Sep 15, 2026
@renovate
renovate Bot force-pushed the renovate/hono-4.x-lockfile branch from 5333d84 to 8d5e71c Compare September 24, 2026 19:30
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.13.8 chore(deps): update dependency hono to v4.13.9 Sep 24, 2026
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.13.9 chore(deps): update dependency hono to v4.13.10 Sep 28, 2026
@renovate
renovate Bot force-pushed the renovate/hono-4.x-lockfile branch 2 times, most recently from d2fc4b1 to 4e974f0 Compare September 29, 2026 12:36
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.13.10 chore(deps): update dependency hono to v4.13.11 Sep 29, 2026
@renovate
renovate Bot force-pushed the renovate/hono-4.x-lockfile branch from 4e974f0 to 0222cb3 Compare October 1, 2026 04:24
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.13.11 chore(deps): update dependency hono to v4.13.12 Oct 1, 2026
@renovate
renovate Bot force-pushed the renovate/hono-4.x-lockfile branch from 0222cb3 to c0fcbf5 Compare October 3, 2026 20:51
@renovate
renovate Bot force-pushed the renovate/hono-4.x-lockfile branch from c0fcbf5 to 2acc6d7 Compare October 4, 2026 04:41
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.13.12 chore(deps): update dependency hono to v4.13.13 Oct 4, 2026
@sonarqubecloud

sonarqubecloud Bot commented Oct 4, 2026

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants