Commit 2109509
fix(deps): bump hono to 4.12.5 to fix multiple vulnerabilities (#19653)
Fixes Dependabot alerts #1125, #1126, #1127, #1128, #1129, #1130.
- CVE-2026-29045: Arbitrary file access via serveStatic (high)
- Cookie Attribute Injection via setCookie() (medium)
- SSE Control Field Injection via writeSSE() (medium)
@s1gr1d feel free to close this one if you want, but pls dismiss the
alerts accordingly if this is the case
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>1 parent f8336d2 commit 2109509
File tree
4 files changed
+7
-8
lines changed- dev-packages
- cloudflare-integration-tests
- e2e-tests/test-applications/cloudflare-hono
- node-integration-tests
4 files changed
+7
-8
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
16 | 16 | | |
17 | 17 | | |
18 | 18 | | |
19 | | - | |
| 19 | + | |
20 | 20 | | |
21 | 21 | | |
22 | 22 | | |
| |||
Lines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
12 | 12 | | |
13 | 13 | | |
14 | 14 | | |
15 | | - | |
| 15 | + | |
16 | 16 | | |
17 | 17 | | |
18 | 18 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
56 | 56 | | |
57 | 57 | | |
58 | 58 | | |
59 | | - | |
| 59 | + | |
60 | 60 | | |
61 | 61 | | |
62 | 62 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
18604 | 18604 | | |
18605 | 18605 | | |
18606 | 18606 | | |
18607 | | - | |
18608 | | - | |
18609 | | - | |
18610 | | - | |
| 18607 | + | |
| 18608 | + | |
| 18609 | + | |
| 18610 | + | |
18611 | 18611 | | |
18612 | 18612 | | |
18613 | 18613 | | |
| |||
28096 | 28096 | | |
28097 | 28097 | | |
28098 | 28098 | | |
28099 | | - | |
28100 | 28099 | | |
28101 | 28100 | | |
28102 | 28101 | | |
| |||
0 commit comments