Repository navigation
build(deps): bump @hono/node-server from 1.19.14 to 2.1.3 - #319
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [@hono/node-server](https://github.com/honojs/node-server) from 1.19.14 to 2.1.3. - [Release notes](https://github.com/honojs/node-server/releases) - [Commits](honojs/node-server@v1.19.14...v2.1.3) --- updated-dependencies: - dependency-name: "@hono/node-server" dependency-version: 2.1.3 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
|
Codex usage limits have been reached for code reviews. Please check with the admins of this repo to increase the limits by adding credits. |
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Repository: arkorlab/arkor/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Code Coverage OverviewLanguages: TypeScript TypeScript / code-coverage/arkorThe overall line coverage in commit 87e909a in the TypeScript / code-coverage/create-arkorThe overall line coverage in commit 87e909a in the TypeScript / code-coverage/cli-internalThe overall line coverage in commit 87e909a in the TypeScript / code-coverage/studio-appThe overall line coverage in commit 87e909a in the Updated |
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
Bumps @hono/node-server from 1.19.14 to 2.1.3.
Release notes
Sourced from @hono/node-server's releases.
... (truncated)
Commits
720ac782.1.39821792Merge commit from fork35bca952.1.290a2600fix(listener): avoid mutating response headers when setting Content-Length (#...fe7467ctest(request): accept asynchronous body read errors (#403)64dc09edocs(readm): update the benchmark (#394)8f505aechore: add better benchmarks (#391)2469b1afix: type error in early hints and add typecheck to CI (#390)3f958daci: add autofix.ci (#392)73c03ad2.1.1Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for
@hono/node-serversince your current version.Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)Summary by cubic
Upgrades
@hono/node-serverfrom 1.19.14 to 2.1.3 inpackages/arkor. The major bump includes a security fix forserveStaticpath double-decoding (GHSA-rmxm-3fg6-px4f) and raises the required Node.js version to >=20.Migration
serveStaticnow rejects paths still containing%after decoding; setallowPercentInPath: trueto serve files with literal%in their names.Written for commit 87e909a. Summary will update on new commits.