Skip to content

Bump hono from 4.13.5 to 4.13.7 - #297

Merged
MattIPv4 merged 1 commit into
masterfrom
dependabot/npm_and_yarn/hono-4.13.7
Oct 3, 2026
Merged

MattIPv4 merged 1 commit into
masterfrom
dependabot/npm_and_yarn/hono-4.13.7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Bumps hono from 4.13.5 to 4.13.7.

Release notes

Sourced from hono's releases.

v4.13.7

Security fixes

This release includes a fix for the following security issue:

hono/jsx renders plain strings unescaped in boundary components, leading to XSS

Affects: Suspense, ErrorBoundary, and Context.Provider in hono/jsx, and renderToString() / renderToReadableStream() in hono/jsx/dom/server. Fixes missing HTML escaping for a plain string placed directly as a child or fallback of these components, or as the root value of the server rendering functions, so untrusted strings could be emitted as markup. GHSA-hxh3-vqpv-xpqv


Users who render untrusted strings inside Suspense, ErrorBoundary, or Context.Provider, or pass them directly to hono/jsx/dom/server, are strongly encouraged to upgrade to this version.

v4.13.6

What's Changed

Full Changelog: honojs/hono@v4.13.5...v4.13.6

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 3, 2026
@dependabot dependabot Bot changed the title Bump hono from 4.13.5 to 4.13.7 bump hono from 4.13.5 to 4.13.7 Oct 3, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/hono-4.13.7 branch from 4b57159 to 9265223 Compare October 3, 2026 21:54
@dependabot dependabot Bot changed the title bump hono from 4.13.5 to 4.13.7 Bump hono from 4.13.5 to 4.13.7 Oct 3, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/hono-4.13.7 branch from 9265223 to 4ee4f5f Compare October 3, 2026 22:08
@MattIPv4

MattIPv4 commented Oct 3, 2026

Copy link
Copy Markdown
Member

@dependabot rebase

Bumps [hono](https://github.com/honojs/hono) from 4.13.5 to 4.13.7.
- [Release notes](https://github.com/honojs/hono/releases)
- [Commits](honojs/hono@v4.13.5...v4.13.7)

---
updated-dependencies:
- dependency-name: hono
  dependency-version: 4.13.7
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/hono-4.13.7 branch from 4ee4f5f to f4bb196 Compare October 3, 2026 22:34
@MattIPv4
MattIPv4 merged commit c24a263 into master Oct 3, 2026
8 checks passed
@MattIPv4
MattIPv4 deleted the dependabot/npm_and_yarn/hono-4.13.7 branch October 3, 2026 22:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant