Skip to content

Bump @hono/node-server from 1.19.9 to 1.19.14#2708

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/hono/node-server-1.19.14
Open

Bump @hono/node-server from 1.19.9 to 1.19.14#2708
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/hono/node-server-1.19.14

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Apr 21, 2026

Bumps @hono/node-server from 1.19.9 to 1.19.14.

Release notes

Sourced from @​hono/node-server's releases.

v1.19.14

What's Changed

Full Changelog: honojs/node-server@v1.19.13...v1.19.14

v1.19.13

Security Fix

Fixed an issue in Serve Static Middleware where inconsistent handling of repeated slashes (//) between the router and static file resolution could allow middleware to be bypassed. Users of Serve Static Middleware are encouraged to upgrade to this version.

See GHSA-92pp-h63x-v22m for details.

v1.19.12

What's Changed

Full Changelog: honojs/node-server@v1.19.11...v1.19.12

v1.19.11

What's Changed

Full Changelog: honojs/node-server@v1.19.10...v1.19.11

v1.19.10

Security Fix

Fixed an authorization bypass in Serve Static Middleware caused by inconsistent URL decoding (%2F handling) between the router and static file resolution. Users of Serve Static Middleware are encouraged to upgrade to this version.

See GHSA-wc8c-qw6v-h7f6 for details.

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Apr 21, 2026
Copilot AI review requested due to automatic review settings April 21, 2026 21:13
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Apr 21, 2026
@dependabot dependabot Bot review requested due to automatic review settings April 21, 2026 21:13
Copilot AI review requested due to automatic review settings April 23, 2026 00:16
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/hono/node-server-1.19.14 branch from e7700b5 to a05f368 Compare April 23, 2026 00:16
@dependabot dependabot Bot review requested due to automatic review settings April 23, 2026 00:16
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/hono/node-server-1.19.14 branch from a05f368 to 638776d Compare April 23, 2026 00:32
@dependabot dependabot Bot requested review from Copilot and removed request for Copilot April 23, 2026 00:32
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/hono/node-server-1.19.14 branch from 638776d to f9f80d0 Compare April 23, 2026 00:40
@dependabot dependabot Bot requested review from Copilot and removed request for Copilot April 23, 2026 00:40
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/hono/node-server-1.19.14 branch from f9f80d0 to ee36778 Compare April 23, 2026 00:50
@dependabot dependabot Bot requested review from Copilot and removed request for Copilot April 23, 2026 00:50
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/hono/node-server-1.19.14 branch from ee36778 to bd592b4 Compare April 23, 2026 01:03
@dependabot dependabot Bot requested review from Copilot and removed request for Copilot April 23, 2026 01:03
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/hono/node-server-1.19.14 branch from bd592b4 to 0aeb0fe Compare April 23, 2026 01:11
@dependabot dependabot Bot review requested due to automatic review settings April 23, 2026 01:11
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/hono/node-server-1.19.14 branch from 0aeb0fe to 99adc1f Compare April 23, 2026 01:20
@dependabot dependabot Bot requested review from Copilot and removed request for Copilot April 23, 2026 01:20
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/hono/node-server-1.19.14 branch from 99adc1f to f973469 Compare April 23, 2026 01:39
@dependabot dependabot Bot requested review from Copilot and removed request for Copilot April 23, 2026 01:39
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/hono/node-server-1.19.14 branch from f973469 to 4636007 Compare April 23, 2026 01:47
@dependabot dependabot Bot review requested due to automatic review settings April 23, 2026 01:47
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/hono/node-server-1.19.14 branch 2 times, most recently from 4260579 to 60bff25 Compare April 24, 2026 17:55
@dependabot dependabot Bot requested review from Copilot and removed request for Copilot April 24, 2026 17:55
Bumps [@hono/node-server](https://github.com/honojs/node-server) from 1.19.9 to 1.19.14.
- [Release notes](https://github.com/honojs/node-server/releases)
- [Commits](honojs/node-server@v1.19.9...v1.19.14)

---
updated-dependencies:
- dependency-name: "@hono/node-server"
  dependency-version: 1.19.14
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Copilot AI review requested due to automatic review settings May 12, 2026 00:41
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/hono/node-server-1.19.14 branch from 60bff25 to 198b04f Compare May 12, 2026 00:41
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant