Skip to content

chore(deps): bump the npm_and_yarn group across 1 directory with 8 updates - #823

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm_and_yarn-f84895fd2d
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm_and_yarn-f84895fd2d

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the npm_and_yarn group with 8 updates in the / directory:

Package From To
hono 4.13.2 4.13.7
axios 1.19.0 1.20.0
next 16.3.6 16.3.8
@graphql-tools/executor-legacy-ws 1.1.27 1.1.37
compression 1.8.1 1.8.2
fast-copy 3.0.2 3.1.0
proxy-addr 2.0.7 2.0.8
source-map-js 1.2.1 1.2.2

Updates hono from 4.13.2 to 4.13.7

Release notes

Sourced from hono's releases.

v4.13.7

Security fixes

This release includes a fix for the following security issue:

hono/jsx renders plain strings unescaped in boundary components, leading to XSS

Affects: Suspense, ErrorBoundary, and Context.Provider in hono/jsx, and renderToString() / renderToReadableStream() in hono/jsx/dom/server. Fixes missing HTML escaping for a plain string placed directly as a child or fallback of these components, or as the root value of the server rendering functions, so untrusted strings could be emitted as markup. GHSA-hxh3-vqpv-xpqv


Users who render untrusted strings inside Suspense, ErrorBoundary, or Context.Provider, or pass them directly to hono/jsx/dom/server, are strongly encouraged to upgrade to this version.

v4.13.6

What's Changed

Full Changelog: honojs/hono@v4.13.5...v4.13.6

v4.13.5

Security fixes

This release includes fixes for the following security issues:

Query parser reads parameters after the URL fragment, causing cache-key and proxy interpretation differentials

Affects: Cache Middleware and applications behind a proxy, WAF, or logging layer that inspects query strings. Fixes query parsing that did not stop at the URL fragment, so a ? after a # was treated as the start of a query string and the application could read parameters that the other component never saw. GHSA-crvj-82cr-hjcx

Incomplete fix for CVE-2026-39408: toSSG() still writes files outside the output directory

Affects: toSSG() for Static Site Generation. Fixes a path normalization gap where consecutive parent-directory segments in ssgParams values were not fully collapsed, bypassing the containment check added in 4.12.12. GHSA-gqvv-2mrq-wpjv

Unbounded dot-notation nesting in parseBody() can cause memory exhaustion

Affects: parseBody() when dot-notation parsing is enabled. Fixes unbounded expansion of dot-separated field names, where a small request body could allocate a disproportionately large object graph and concurrent requests could exhaust the heap. GHSA-g6gw-c38x-mqfc


Users who use Cache Middleware, deploy behind a proxy or WAF that inspects query strings, use Static Site Generation, or use parseBody({ dot: true }) are strongly encouraged to upgrade to this version.

v4.13.4

What's Changed

  • fix(request): handle params on unmatched requests in honojs/hono#5268
  • fix(jsx/dom): execute previous ref cleanup when ref prop changes on re-render in honojs/hono#5264
  • fix(reg-exp-router): associate wildcard middleware with matching routes in honojs/hono#5266
  • perf(router): share null object creation in honojs/hono#5267

... (truncated)

Commits

Updates axios from 1.19.0 to 1.20.0

Release notes

Sourced from axios's releases.

v1.20.0 — August 19, 2026

This release hardens runtime option handling, adds RFC 9110 status-code aliases, fixes Node.js and XHR reliability issues, and refreshes project tooling and documentation.

⚠️ Breaking Changes & Deprecations

  • HTTP Status Naming: Added ContentTooLarge (413) and UnprocessableContent (422), while retaining PayloadTooLarge and UnprocessableEntity as backward-compatible deprecated aliases. (#11082)

🔒 Security Fixes

  • Runtime Option Handling: Hardened behavioral configuration reads against shared and foreign prototype pollution and normalized unsafe interceptor replacement objects. This also clarifies Fetch redirect and custom implementation behavior, HTTP/2 DNS and proxy handling, CIDR-based NO_PROXY matching, and malformed data URI rejection; see the PR for documented compatibility effects. (#11141)

🐛 Bug Fixes

  • Interceptor Lifecycle: Prevented unbounded handler-array growth by trimming trailing ejected interceptors without changing iteration semantics, and kept interceptor operations safe when the public handlers field is nullish. (#11087, #11118)
  • Request Error Preservation: Prevented custom Error.prepareStackTrace implementations that return non-string values from replacing the original request failure with an unrelated TypeError. (#11109)
  • XHR Reliability: Navigation-canceled requests now reject with ECONNABORTED instead of resolving with status 0, while successful downloads flush their final progress callback during the live loadend dispatch. (#11094, #11121)
  • Node.js Socket Memory: Removed request-context retention from per-socket error listeners, preventing completed response data from being pinned for the lifetime of pooled keep-alive sockets. (#11091)
  • Core Methods and HTTP Errors: Prevented structural method-header buckets from leaking into outgoing headers, standardized invalid DNS lookup and httpVersion failures as AxiosError.ERR_BAD_OPTION_VALUE, and corrected the timeoutErrorMessage merge strategy. (#11096)

🔧 Maintenance & Chores

  • Dependencies: Updated fast-uri, postcss, js-yaml, mocha, development-tooling groups, and GitHub Actions dependencies. (#11092, #11098, #11099, #11106, #11107, #11122, #11123, #11126, #11127, #11133, #11140, #11143, #11144)
  • Documentation: Applied the v1.19.0 documentation updates, added the missing fs import to the README stream example, introduced localized global search, and repaired the interceptor test link. (#11101, #11113, #11097, #11119)
  • Sponsorship: Updated sponsorship links and data and added ScrapingBee as a sponsor. (#11124, #11136, #11137)
  • CI and Release: Switched ESM smoke tests to locked dependencies and synchronized package and runtime version metadata for v1.20.0. (#11128, #11152)

🌟 New Contributors

We are thrilled to welcome our new contributors. Thank you for helping improve axios:

Full Changelog (axios/axios@v1.19.0...v1.20.0)

Changelog

Sourced from axios's changelog.

Changelog

Commits
  • 84a9f3b chore(release): prepare release 1.20.0 (#11152)
  • e6824ee fix: core methodList, HTTP adapter errors, and add tests (#11096)
  • d8a919f fix(xhr): flush final progress during the live loadend dispatch (#11121)
  • 2d2a21a fix(interceptors): tolerate nullish handlers in syncHandlerEntries (#11118)
  • d19040b fix: harden runtime option handling (#11141)
  • e0a02dd chore(deps): bump zizmorcore/zizmor-action from 0.6.1 to 0.6.2 in the github-...
  • d10cb3a chore(deps-dev): bump the development_dependencies group with 4 updates (#11143)
  • 2c94646 chore(deps): bump js-yaml and mocha in /tests/smoke/cjs (#11133)
  • 76c12bc chore(deps-dev): bump js-yaml from 4.3.0 to 4.3.1 (#11140)
  • ba98559 docs: add ScrapingBee sponsor (#11137)
  • Additional commits viewable in compare view

Updates next from 16.3.6 to 16.3.8

Release notes

Sourced from next's releases.

v16.3.8

This release contains security fixes for the following advisories:

High:

Medium:

Low:

v16.3.7

[!NOTE] This release is backporting bug fixes. It does not include all pending features/changes on canary.

Core Changes

  • turbo-tasks-backend: fix strongly consistent read hanging on a canceled task (#98931)

Credits

Huge thanks to @​lukesandberg for helping!

Commits
  • b0fad0d v16.3.8
  • 719e4c6 [lts-active] Scope response cache keys to their source route (#218)
  • e92db45 [lts-active] Fix metadata propagation for deduplicated nested caches (#223)
  • 40c2ba9 [lts-active] Match Next data paths case-sensitively (#196)
  • 2d9f50a [lts-active] Fix MCP middleware DNS rebinding (#213)
  • bd9214f [lts-active] Fix draft mode leaks through cross-request 'use cache' dedupli...
  • 8db4a62 [lts-active][webpack] Ensure dynamicParams is respected in `opengraph-image...
  • e002ad6 [lts-active] fix(next/image): Pin DNS resolution when fetching external image...
  • 4c20699 v16.3.7
  • 2521aec [backport] turbo-tasks-backend: fix strongly consistent read hanging on a can...
  • See full diff in compare view

Updates @graphql-tools/executor-legacy-ws from 1.1.27 to 1.1.37

Changelog

Sourced from @​graphql-tools/executor-legacy-ws's changelog.

1.1.37

Patch Changes

  • Updated dependencies [19f5b33]:
    • @​graphql-tools/utils@​12.0.3

1.1.36

Patch Changes

  • #8480 c2f226e Thanks @​ardatan! - Security: Isolate legacy GraphQL WebSocket executions on a shared buildWSLegacyExecutor().

    A single executor reused across callers kept extensions.connectionParams for the lifetime of the closure and installed one websocket.onmessage handler. A later request could be authenticated with a previous caller's connection_init payload (GHSA-434m-5hcj-pxf3, CWE-613), and an overlapping subscription could receive another operation's data frames because the handler ignored the protocol operation id (GHSA-mp66-8ww2-pcwm, CWE-200).

    Corrected behavior

    • Each execution opens its own socket. connection_init is built from the executor's base connectionParams plus that request's extensions.connectionParams only.
    • data, error, and complete frames are delivered only when id matches the operation that socket started.
    • Operation ids are no longer Date.now().
  • Updated dependencies [b1fbba2, 20d36a5]:

    • @​graphql-tools/utils@​12.0.2

1.1.35

Patch Changes

  • #8426 3831a06 Thanks @​ardatan! - Security: Enable TLS certificate validation by default for legacy GraphQL WebSocket (graphql-ws protocol) connections over wss://.

    buildWSLegacyExecutor() previously hardcoded rejectUnauthorized: false, so Node.js clients accepted any certificate (including self-signed or attacker-controlled ones). Credentials in connectionParams / headers and subscription payloads could be exposed to a network MITM. This addresses GHSA-6fw5-9hq8-w87g (CWE-295).

    Corrected behavior

    • Default is now rejectUnauthorized: true (Node TLS verifies the peer certificate), matching secure-by-default expectations.
    • Connections to endpoints with untrusted/self-signed certificates will fail unless you opt out.

    Opt-out (trusted / local self-signed only)

    buildWSLegacyExecutor(url, WebSocket, {
      rejectUnauthorized: false,
      connectionParams: { /* ... */ },
    })

    Or via UrlLoader / LoadFromUrlOptions when subscriptionsProtocol is LEGACY_WS:

    {
      subscriptionsProtocol: SubscriptionProtocol.LEGACY_WS,
      rejectUnauthorized: false,

... (truncated)

Commits
  • 944121e Upcoming Release Changes (#8483)
  • 3a43b4b Upcoming Release Changes (#8460)
  • c2f226e fix(executor-legacy-ws): isolate per-request auth and subscription results (#...
  • 01167f3 chore(release): update monorepo packages versions (#8427)
  • 3831a06 fix(executor-legacy-ws): enable TLS cert validation by default (GHSA-6fw5-9hq...
  • 8b9b7df chore(release): update monorepo packages versions (#8365)
  • 0f00a44 chore: use HTTPS git URLs for package repository metadata (#8376)
  • 9feabd9 chore(release): update monorepo packages versions (#8327)
  • 07cd760 build(deps): bump the actions-deps group across 1 directory with 7 updates (#...
  • 755d699 build(deps): bump the actions-deps group with 4 updates (#8353)
  • Additional commits viewable in compare view

Updates compression from 1.8.1 to 1.8.2

Release notes

Sourced from compression's releases.

v1.8.2

Important

What's Changed

New Contributors

Full Changelog: expressjs/compression@v1.8.1...v1.8.2

Changelog

Sourced from compression's changelog.

1.8.2

Commits
  • 0f97074 1.8.2 (#287)
  • 151f63e fix: destroy compression stream on response close
  • 0a76495 fix: match Cache-Control no-transform directive case-insensitively (#286)
  • c17b6e5 docs: update outdated Brotli note and fix npm install docs URL (#276)
  • 112911a chore(ci): npm-publish via reusable workflows (#269)
  • 1bf5eb0 build(deps): bump actions/upload-artifact from 5.0.0 to 6.0.0 (#267)
  • d8fe64d build(deps): bump actions/setup-node from 6.0.0 to 6.1.0 (#266)
  • b218ff5 build(deps): bump github/codeql-action from 4.31.5 to 4.31.9 (#265)
  • 8a1cf8e build(deps): bump actions/download-artifact from 6.0.0 to 7.0.0 (#268)
  • 4a19855 build(deps): bump ossf/scorecard-action from 2.4.2 to 2.4.3 (#257)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for compression since your current version.


Updates fast-copy from 3.0.2 to 3.1.0

Release notes

Sourced from fast-copy's releases.

Release 3.1.0

  • [Security] Apply port of #137 to v3 (#138) (359c008)
  • [Maintenance] Upgrade to Yarn 4 (#101) (0078ed5)
  • update CHANGELOG (f1cc924)
Changelog

Sourced from fast-copy's changelog.

3.1.0

  • Add maxDepth option to createCopier / createStrictCopier, bounding the number of nested objects traversed (defaults to 1000, pass Infinity to traverse without a limit)
  • Throw the new MaxDepthExceededError when a value is nested more deeply than maxDepth, instead of exhausting the call stack with a native RangeError; the error extends RangeError, so existing handling continues to work

Backport of the fix released in 4.1.0 for consumers remaining on 3.x.

Notes

  • The State object passed to custom copier methods now includes a depth property. This is maintained internally and should not be modified, but it is a required property on the exported State type, so any code constructing a State directly (such as a test mock) will need to provide it.
Commits

Updates proxy-addr from 2.0.7 to 2.0.8

Release notes

Sourced from proxy-addr's releases.

2.0.8

Important

What's Changed

New Contributors

Full Changelog: jshttp/proxy-addr@v2.0.7...v2.0.8

Changelog

Sourced from proxy-addr's changelog.

2.0.8

Commits
  • a11ad82 2.0.8 (#70)
  • 780911d fix: reject IPv4 trust via mapped IPv6 subnets with a short prefix
  • 92e103e fix(ci): use publised as release trigger event (#71)
  • 3e5ac75 ci: merge coverage via artifacts, disable fail-fast, add Node.js 23-26 (#69)
  • 4b9db81 chore(ci): npm-publish via workflows (#54)
  • 655e895 build(deps-dev): bump eslint-plugin-import from 2.31.0 to 2.32.0 (#39)
  • 50ce4d0 build(deps): bump ossf/scorecard-action from 2.4.2 to 2.4.3 (#45)
  • 0fd347f build(deps): bump actions/upload-artifact from 7.0.0 to 7.0.1 (#63)
  • 6a517fa build(deps): bump github/codeql-action from 4.32.4 to 4.36.0 (#64)
  • 0d45e2a Fix "arugment" typo in README (#61)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for proxy-addr since your current version.


Updates source-map-js from 1.2.1 to 1.2.2

Release notes

Sourced from source-map-js's releases.

v1.2.2

Changelog

Sourced from source-map-js's changelog.

1.2.2

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions
    You can disable automated security fix PRs for this repo from the Security Alerts page.

…dates

Bumps the npm_and_yarn group with 8 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [hono](https://github.com/honojs/hono) | `4.13.2` | `4.13.7` |
| [axios](https://github.com/axios/axios) | `1.19.0` | `1.20.0` |
| [next](https://github.com/vercel/next.js) | `16.3.6` | `16.3.8` |
| [@graphql-tools/executor-legacy-ws](https://github.com/ardatan/graphql-tools/tree/HEAD/packages/executors/legacy-ws) | `1.1.27` | `1.1.37` |
| [compression](https://github.com/expressjs/compression) | `1.8.1` | `1.8.2` |
| [fast-copy](https://github.com/planttheidea/fast-copy) | `3.0.2` | `3.1.0` |
| [proxy-addr](https://github.com/jshttp/proxy-addr) | `2.0.7` | `2.0.8` |
| [source-map-js](https://github.com/7rulnik/source-map-js) | `1.2.1` | `1.2.2` |



Updates `hono` from 4.13.2 to 4.13.7
- [Release notes](https://github.com/honojs/hono/releases)
- [Commits](honojs/hono@v4.13.2...v4.13.7)

Updates `axios` from 1.19.0 to 1.20.0
- [Release notes](https://github.com/axios/axios/releases)
- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md)
- [Commits](axios/axios@v1.19.0...v1.20.0)

Updates `next` from 16.3.6 to 16.3.8
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](vercel/next.js@v16.3.6...v16.3.8)

Updates `@graphql-tools/executor-legacy-ws` from 1.1.27 to 1.1.37
- [Release notes](https://github.com/ardatan/graphql-tools/releases)
- [Changelog](https://github.com/ardatan/graphql-tools/blob/master/packages/executors/legacy-ws/CHANGELOG.md)
- [Commits](https://github.com/ardatan/graphql-tools/commits/@graphql-tools/executor-legacy-ws@1.1.37/packages/executors/legacy-ws)

Updates `compression` from 1.8.1 to 1.8.2
- [Release notes](https://github.com/expressjs/compression/releases)
- [Changelog](https://github.com/expressjs/compression/blob/master/HISTORY.md)
- [Commits](expressjs/compression@v1.8.1...v1.8.2)

Updates `fast-copy` from 3.0.2 to 3.1.0
- [Release notes](https://github.com/planttheidea/fast-copy/releases)
- [Changelog](https://github.com/planttheidea/fast-copy/blob/v3.1.0/CHANGELOG.md)
- [Commits](planttheidea/fast-copy@v3.0.2...v3.1.0)

Updates `proxy-addr` from 2.0.7 to 2.0.8
- [Release notes](https://github.com/jshttp/proxy-addr/releases)
- [Changelog](https://github.com/jshttp/proxy-addr/blob/master/HISTORY.md)
- [Commits](jshttp/proxy-addr@v2.0.7...v2.0.8)

Updates `source-map-js` from 1.2.1 to 1.2.2
- [Release notes](https://github.com/7rulnik/source-map-js/releases)
- [Changelog](https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md)
- [Commits](7rulnik/source-map-js@v1.2.1...v1.2.2)

---
updated-dependencies:
- dependency-name: hono
  dependency-version: 4.13.7
  dependency-type: direct:production
  dependency-group: npm_and_yarn
- dependency-name: axios
  dependency-version: 1.20.0
  dependency-type: direct:production
  dependency-group: npm_and_yarn
- dependency-name: next
  dependency-version: 16.3.8
  dependency-type: direct:production
  dependency-group: npm_and_yarn
- dependency-name: "@graphql-tools/executor-legacy-ws"
  dependency-version: 1.1.37
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: compression
  dependency-version: 1.8.2
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: fast-copy
  dependency-version: 3.1.0
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: proxy-addr
  dependency-version: 2.0.8
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: source-map-js
  dependency-version: 1.2.2
  dependency-type: indirect
  dependency-group: npm_and_yarn
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot requested a review from a team as a code owner October 9, 2026 23:08
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 9, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 10, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Oct 10, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/npm_and_yarn-f84895fd2d branch October 10, 2026 00:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants