Repository navigation
chore(deps): update dependency hono to v4.13.13 - #117
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
renovate
Bot
force-pushed
the
renovate/hono-4.x-lockfile
branch
2 times, most recently
from
September 4, 2026 19:22
a625c32 to
e740079
Compare
renovate
Bot
force-pushed
the
renovate/hono-4.x-lockfile
branch
from
September 4, 2026 20:32
e740079 to
196264b
Compare
renovate
Bot
force-pushed
the
renovate/hono-4.x-lockfile
branch
from
September 15, 2026 08:25
196264b to
5333d84
Compare
renovate
Bot
force-pushed
the
renovate/hono-4.x-lockfile
branch
from
September 24, 2026 19:30
5333d84 to
8d5e71c
Compare
renovate
Bot
force-pushed
the
renovate/hono-4.x-lockfile
branch
2 times, most recently
from
September 29, 2026 12:36
d2fc4b1 to
4e974f0
Compare
renovate
Bot
force-pushed
the
renovate/hono-4.x-lockfile
branch
from
October 1, 2026 04:24
4e974f0 to
0222cb3
Compare
renovate
Bot
force-pushed
the
renovate/hono-4.x-lockfile
branch
from
October 3, 2026 20:51
0222cb3 to
c0fcbf5
Compare
renovate
Bot
force-pushed
the
renovate/hono-4.x-lockfile
branch
from
October 4, 2026 04:41
c0fcbf5 to
2acc6d7
Compare
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



This PR contains the following updates:
4.12.33→4.13.13Release Notes
honojs/hono (hono)
v4.13.13Compare Source
Mount Middleware
app.mount()is now available as the Mount Middleware,hono/mount. It is just a handler, so you register it withapp.all():app.mount()still works in v4 but is deprecated and will be removed in v5. Migrating is a one-line change:What's Changed
app.mountin #5221Full Changelog: honojs/hono@v4.13.12...v4.13.13
v4.13.12Compare Source
What's Changed
Full Changelog: honojs/hono@v4.13.11...v4.13.12
v4.13.11Compare Source
Security fixes
serveStaticdecodes the request path a second time, leading to bypass of middleware on static pathsAffects:
hono/serve-staticand the adapters built on it (hono/bun,hono/deno,hono/cloudflare-workers,@hono/bun,@hono/deno,@hono/cloudflare-workers). FixesserveStaticdecoding an already-decoded path, where a crafted request could be routed as one path and served as another, skipping middleware mounted on a static prefix. GHSA-5r4p-p66f-jhc7serveStaticnow rejects request paths that still contain%after decoding. To serve files whose names contain a literal%, setallowPercentInPath: true.The same fix ships in
@hono/node-serverv2.1.3.v4.13.10Compare Source
Adapters are now separate packages
The runtime adapters are now published as their own packages:
@hono/bun,@hono/deno,@hono/cloudflare-workers,@hono/aws-lambda,@hono/lambda-edge,@hono/netlify,@hono/vercel, and@hono/service-worker.@hono/denois also on JSR.hono/<adapter>still works in v4 but is deprecated and will be removed in v5. Migrating is an import change:hono/cloudflare-pages is deprecated without a replacement package; Cloudflare recommends Workers with static assets.
What's Changed
cr.ymlby the pnpm migration in #54561.0.0-rc.1in #5459adapters/*in #5466Full Changelog: honojs/hono@v4.13.9...v4.13.10
v4.13.9Compare Source
What's Changed
Full Changelog: honojs/hono@v4.13.8...v4.13.9
v4.13.8Compare Source
What's Changed
Full Changelog: honojs/hono@v4.13.7...v4.13.8
v4.13.7Compare Source
v4.13.6Compare Source
v4.13.5Compare Source
v4.13.4Compare Source
v4.13.3Compare Source
What's Changed
Full Changelog: honojs/hono@v4.13.2...v4.13.3
v4.13.2Compare Source
What's Changed
Full Changelog: honojs/hono@v4.13.1...v4.13.2
v4.13.1Compare Source
v4.13.0Compare Source
Hono v4.13.0 is now available!
The highlight of this release is performance: a batch of low-level optimizations makes the core request/response path significantly faster — up to 1.25x on common routes in our benchmark. This release also adds first-class support for the HTTP QUERY method, defined in RFC 10008, a new Method Not Allowed middleware, and more.
Performance improvements
This release includes a series of small optimizations: skipping unnecessary
Headersallocations, replacing regex tests withindexOf, allocating internal state lazily, and more.Here is
benchmarks/fetchcomparing v4.12 and v4.13 (ROUNDS=5 ./compare.sh, Bun 1.4.0, Apple Silicon — each measurement runs in a fresh process, and the variant order is reversed every round to avoid warm-up bias):ping—GET /query—GET /id/1?name=bunjson—GET /userbody—POST /jsonThe individual changes:
for..in#5118indexOf#5121Headerscreation when there are no headers to merge #5122tryDecodeURIComponent#5158#validatedDatalazily #5175In addition, the RegExpRouter rewrite described below makes route registration plus the first match roughly 20% faster.
Thanks @kibertoad for the contributions!
First-class QUERY method support
The QUERY method — a safe, idempotent method that carries a request body — is now a first-class citizen in Hono. You can define QUERY handlers with
app.query():Thanks @shellhaki!
QUERY support across built-in middleware
The built-in middleware has been updated to handle QUERY requests properly:
Cache Middleware
The Cache Middleware now caches QUERY responses. Following RFC 10008 Section 2.7, the cache key incorporates a SHA-256 digest of the request content and its representation metadata, so different query bodies are cached separately:
Note: To support this, the internal cache key format has changed for all methods, including GET. Cached entries are now stored under an internal URL of the form
/.hono/cache?__hono_cache_key=.... If you purge cache entries by URL outside of the middleware (e.g. callingcaches.delete()with the original request URL), you will need to update that logic. Existing cache entries stored with the old format will simply be re-fetched.ETag Middleware
The ETag Middleware now handles conditional requests for QUERY, returning
304 Not ModifiedwhenIf-None-Matchmatches.CORS Middleware
The CORS Middleware now includes QUERY in the default
Access-Control-Allow-Methods, which is nowGET, HEAD, PUT, POST, DELETE, PATCH, QUERY. If you specifyallowMethodsexplicitly, nothing changes for you.Thanks @usualoma and @Cherry!
Method Not Allowed Middleware
The new Method Not Allowed Middleware returns a
405 Method Not Allowedresponse with a properAllowheader when the request path matches a registered route but the method does not:You can customize the response with the
onMethodNotAllowedoption:Thanks @usualoma!
RegExpRouter throws
UnsupportedPathErrorat registration timeThe RegExpRouter now detects unsupported path combinations when routes are registered, instead of at the first matching request. This means misconfigured routes fail fast at startup rather than at runtime. As a bonus, registration plus the first match is roughly 20% faster.
Thanks @usualoma!
Other improvements
hono/utils/headershas been synced with the IANA HTTP Field Name Registry, adding newly registered fields such asAccept-Query. Thanks @akahoshi1421!realmoption for theWWW-Authenticatechallenge on401responses, and challenge values are properly escaped. Thanks @arhxam!useRefandRefObjectare now aligned with React 19. Note that this is a type-level change —RefObject<T>is now{ current: T }, so type a nullable ref asRefObject<T | null>, and passuseRef(undefined)instead ofuseRef(). Thanks @ashunar0!Vary: Accept-Encodingon negotiated responses. Thanks @arhxam!All changes
fetchby @yusukebe in #5113indexOfby @yusukebe in #5121tryDecodeURIComponentby @yusukebe in #5158envfield initializer by @kibertoad in #5174#validatedDatalazily by @kibertoad in #5175fetchby @yusukebe in #5184envfield initializer by @yusukebe in #5186Full Changelog: honojs/hono@v4.12.34...v4.13.0
Thank you to all contributors!
v4.12.34Compare Source
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.