Skip to content

chore(deps): update dependency hono to v4.13.1 - #256

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/hono-4.x
Open

chore(deps): update dependency hono to v4.13.1#256
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/hono-4.x

Conversation

@renovate

@renovate renovate Bot commented Feb 26, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
hono (source) 4.12.144.13.1 age confidence

Release Notes

honojs/hono (hono)

v4.13.1

Compare Source

v4.13.0

Compare Source

Hono v4.13.0 is now available!

The highlight of this release is performance: a batch of low-level optimizations makes the core request/response path significantly faster — up to 1.25x on common routes in our benchmark. This release also adds first-class support for the HTTP QUERY method, defined in RFC 10008, a new Method Not Allowed middleware, and more.

Performance improvements

This release includes a series of small optimizations: skipping unnecessary Headers allocations, replacing regex tests with indexOf, allocating internal state lazily, and more.

Here is benchmarks/fetch comparing v4.12 and v4.13 (ROUNDS=5 ./compare.sh, Bun 1.4.0, Apple Silicon — each measurement runs in a fresh process, and the variant order is reversed every round to avoid warm-up bias):

Benchmark v4.12 v4.13 Speedup
pingGET / 165.83 ns 163.99 ns 1.01x
queryGET /id/1?name=bun 674.40 ns 616.99 ns 1.09x
jsonGET /user 528.99 ns 422.44 ns 1.25x
bodyPOST /json 1.16 µs 1.00 µs 1.15x

The individual changes:

  • perf(context): iterate the header record with for..in #​5118
  • perf(url): replace regex tests with indexOf #​5121
  • perf(context): skip Headers creation when there are no headers to merge #​5122
  • perf(urls): refactor tryDecodeURIComponent #​5158
  • perf(request): allocate #validatedData lazily #​5175
  • perf(request): probe the body cache without allocating #​5176

In addition, the RegExpRouter rewrite described below makes route registration plus the first match roughly 20% faster.

Thanks @​kibertoad for the contributions!

First-class QUERY method support

The QUERY method — a safe, idempotent method that carries a request body — is now a first-class citizen in Hono. You can define QUERY handlers with app.query():

const app = new Hono()

app.query('/search', async (c) => {
  const conditions = await c.req.json()
  return c.json(await search(conditions))
})

Thanks @​shellhaki!

QUERY support across built-in middleware

The built-in middleware has been updated to handle QUERY requests properly:

Cache Middleware

The Cache Middleware now caches QUERY responses. Following RFC 10008 Section 2.7, the cache key incorporates a SHA-256 digest of the request content and its representation metadata, so different query bodies are cached separately:

app.query(
  '/search',
  cache({
    cacheName: 'search-cache',
    cacheControl: 'max-age=3600',
  })
)

Note: To support this, the internal cache key format has changed for all methods, including GET. Cached entries are now stored under an internal URL of the form /.hono/cache?__hono_cache_key=.... If you purge cache entries by URL outside of the middleware (e.g. calling caches.delete() with the original request URL), you will need to update that logic. Existing cache entries stored with the old format will simply be re-fetched.

ETag Middleware

The ETag Middleware now handles conditional requests for QUERY, returning 304 Not Modified when If-None-Match matches.

CORS Middleware

The CORS Middleware now includes QUERY in the default Access-Control-Allow-Methods, which is now GET, HEAD, PUT, POST, DELETE, PATCH, QUERY. If you specify allowMethods explicitly, nothing changes for you.

Thanks @​usualoma and @​Cherry!

Method Not Allowed Middleware

The new Method Not Allowed Middleware returns a 405 Method Not Allowed response with a proper Allow header when the request path matches a registered route but the method does not:

import { methodNotAllowed } from 'hono/method-not-allowed'

const app = new Hono()

app.use(methodNotAllowed({ app }))

app.get('/hello', (c) => c.text('Hello!'))
app.post('/hello', (c) => c.text('Posted!'))

// PUT /hello -> 405 Method Not Allowed
// Allow: GET, HEAD, POST

You can customize the response with the onMethodNotAllowed option:

app.use(
  methodNotAllowed({
    app,
    onMethodNotAllowed: (c, methods) =>
      c.json({ error: 'Method Not Allowed' }, 405, { Allow: methods.join(', ') }),
  })
)

Thanks @​usualoma!

RegExpRouter throws UnsupportedPathError at registration time

The RegExpRouter now detects unsupported path combinations when routes are registered, instead of at the first matching request. This means misconfigured routes fail fast at startup rather than at runtime. As a bonus, registration plus the first match is roughly 20% faster.

Thanks @​usualoma!

Other improvements

  • hono/utils/headers has been synced with the IANA HTTP Field Name Registry, adding newly registered fields such as Accept-Query. Thanks @​akahoshi1421!
  • The JWT and JWK middleware now accept a realm option for the WWW-Authenticate challenge on 401 responses, and challenge values are properly escaped. Thanks @​arhxam!
  • JSX: useRef and RefObject are now aligned with React 19. Note that this is a type-level change — RefObject<T> is now { current: T }, so type a nullable ref as RefObject<T | null>, and pass useRef(undefined) instead of useRef(). Thanks @​ashunar0!
  • JSX: a function component can now return an array of children without throwing during server-side rendering. Thanks @​natsuki-engr!
  • The Compress Middleware now sets Vary: Accept-Encoding on negotiated responses. Thanks @​arhxam!

All changes

Full Changelog: honojs/hono@v4.12.34...v4.13.0

Thank you to all contributors!

v4.12.34

Compare Source

v4.12.33

Compare Source

What's Changed

  • fix(cookie): relax name validation when parsing Cookie header in #​5164
  • chore: bump @hono/node-server in #​5167
  • fix(jsx): handle useSyncExternalStore subscription and snapshot changes in #​5166
  • chore: remove undici in favor of global fetch in #​5168

Full Changelog: honojs/hono@v4.12.32...v4.12.33

v4.12.32

Compare Source

What's Changed

  • ci: enable reports for type & bundle size check in #​5148
  • fix(aws-lambda): add jwt and lambda authorizer types for API Gateway v2 in #​5142
  • fix(sse): emit empty id field to reset Last-Event-ID in #​5138
  • test(cloudflare-workers): add coverage for onClose, onError, send, and close in Cloudflare Workers websocket adapter in #​5145
  • fix: use Object.create(null) when parsing query, headers, and params in #​5161
  • fix(secure-headers): keep CSP callbacks scoped to their header in #​5147

Full Changelog: honojs/hono@v4.12.31...v4.12.32

v4.12.31

Compare Source

v4.12.30

Compare Source

What's Changed

  • chore(benchmark/routers): bump deps in #​5107
  • chore(benchmark): remove not used benchmarks in #​5108
  • chore: update to ts6 in prep for ts7 in #​5104
  • fix(cache): deduplicate Cache-Control directives case-insensitively in #​5025
  • fix(compress): do not compress 206 Partial Content responses in #​5020
  • fix(client): replaceUrlParam should not match a param that prefixes another in #​5096
  • fix(method-override): set duplex when forwarding a stream body in query mode in #​5110

Full Changelog: honojs/hono@v4.12.29...v4.12.30

v4.12.29

Compare Source

What's Changed

New Contributors

Full Changelog: honojs/hono@v4.12.28...v4.12.29

v4.12.28

Compare Source

What's Changed

New Contributors

Full Changelog: honojs/hono@v4.12.27...v4.12.28

v4.12.27

Compare Source

Security fixes

This release includes fixes for the following security issues:

hono/jsx does not isolate context per request

Affects: hono/jsx, hono/jsx-renderer. During SSR, context was stored process-wide instead of per request, so useContext()/useRequestContext() read after an await in an async component could return another concurrent request's value — leading to cross-request data disclosure or authorization checks against the wrong request. GHSA-hvrm-45r6-mjfj

Server-Side XSS via JSX escaping bypass in cx()

Affects: hono/css. cx() marked its composed class name as already-escaped without escaping the input, so untrusted input passed as a class name could break out of the JSX class attribute during SSR and inject markup (XSS). GHSA-w62v-xxxg-mg59

API Gateway v1 adapter can drop a repeated request header value

Affects: hono/aws-lambda. The API Gateway v1 (and VPC Lattice) adapter de-duplicated repeated header values by substring instead of exact match, dropping a value that is a substring of another (e.g. 203.0.113.1 dropped when 203.0.113.10 is present) — affecting logic such as X-Forwarded-For-based IP restriction. GHSA-xgm2-5f3f-mvvc


Users of hono/jsx/hono/jsx-renderer, hono/css (cx()), or the hono/aws-lambda API Gateway v1 / VPC Lattice adapters are encouraged to upgrade.

v4.12.26

Compare Source

What's Changed

Full Changelog: honojs/hono@v4.12.25...v4.12.26

v4.12.25

Compare Source

Security fixes

This release includes fixes for the following security issues:

CORS Middleware reflects any Origin with credentials when origin defaults to the wildcard

Affects: hono/cors. Fixes the wildcard origin reflecting the request Origin and sending Access-Control-Allow-Credentials: true when credentials: true is set without an explicit origin, where any site a logged-in user visited could make credentialed cross-origin requests and read responses from cookie-authenticated endpoints. GHSA-88fw-hqm2-52qc

Body Limit Middleware can be bypassed on AWS Lambda by understating Content-Length

Affects: hono/body-limit on AWS Lambda (hono/aws-lambda, hono/lambda-edge). Fixes the request being built with the client-declared Content-Length while the body is delivered fully buffered, where a client could declare a small Content-Length with a much larger body and slip past the configured size limit. GHSA-rv63-4mwf-qqc2

Path traversal in serve-static on Windows via encoded backslash (%5C)

Affects: serveStatic on Windows (Node, Bun, Deno adapters). Fixes the path guard allowing a lone backslash, where an encoded backslash (%5C) decoded to \ was treated as a separator by the Windows path resolver, letting a single URL segment escape into a middleware-guarded subtree. GHSA-wwfh-h76j-fc44

AWS Lambda adapter merges multiple Set-Cookie headers into one value, dropping cookies on ALB single-header and Lattice

Affects: hono/aws-lambda. Fixes multiple Set-Cookie response headers being joined into one comma-separated value for ALB single-header responses and VPC Lattice v2, where the value could not be split back into individual cookies and clients silently dropped or misparsed them. GHSA-j6c9-x7qj-28xf

Lambda@​Edge adapter keeps only the last value of a repeated request header, dropping the rest

Affects: hono/lambda-edge. Fixes repeated request headers being written with overwrite instead of append, where only the last value of a header such as X-Forwarded-For reached the application and the remaining values were silently dropped. GHSA-wgpf-jwqj-8h8p

v4.12.24

Compare Source

What's Changed

Full Changelog: honojs/hono@v4.12.23...v4.12.24

v4.12.23

Compare Source

What's Changed

Full Changelog: honojs/hono@v4.12.22...v4.12.23

v4.12.22

Compare Source

What's Changed

New Contributors

Full Changelog: honojs/hono@v4.12.21...v4.12.22

v4.12.21

Compare Source

Security fixes

This release includes fixes for the following security issues:

app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded paths

Affects: app.mount(). Fixes prefix stripping using the raw URL pathname instead of the decoded path, where percent-encoded characters in the mount prefix or path could cause the prefix to be removed at the wrong position, resulting in the sub-application receiving an incorrect path. GHSA-2gcr-mfcq-wcc3

IP Restriction bypasses static deny rules for non-canonical IPv6

Affects: hono/ip-restriction. Fixes IP address comparison using string equality, where non-canonical IPv6 representations of a denied address — such as compressed forms or hex-notation IPv4-mapped addresses — could bypass static deny rules. GHSA-xrhx-7g5j-rcj5

Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injection

Affects: hono/cookie. Fixes missing validation of sameSite and priority options against injection characters (;, \r, \n), where user-controlled input passed to either option could inject additional attributes into the Set-Cookie response header. GHSA-3hrh-pfw6-9m5x

JWT middleware accepts any Authorization scheme, not only Bearer

Affects: hono/jwt, hono/jwk. Fixes missing scheme validation in the Authorization header, where any two-part header value was accepted regardless of the scheme name, allowing non-Bearer schemes to pass JWT authentication. GHSA-f577-qrjj-4474


Users who use app.mount(), hono/ip-restriction, hono/cookie, or hono/jwt/hono/jwk are encouraged to upgrade to this version.

v4.12.20

Compare Source

What's Changed

New Contributors

Full Changelog: honojs/hono@v4.12.19...v4.12.20

v4.12.19

Compare Source

What's Changed

New Contributors

Full Changelog: honojs/hono@v4.12.18...v4.12.19

v4.12.18

Compare Source

Security fixes

This release includes fixes for the following security issues:

Cache Middleware ignores Vary: Authorization / Vary: Cookie leading to cross-user cache leakage

Affects: Cache Middleware. Fixes missing cache-skip handling for Vary: Authorization and Vary: Cookie, where a response cached for one authenticated user could be served to other users. GHSA-p77w-8qqv-26rm

CSS Declaration Injection via Style Object Values in JSX SSR

Affects: hono/jsx. Fixes a missing CSS-context escape for style object values and property names, where untrusted input could inject additional CSS declarations. The impact is limited to CSS and does not allow JavaScript execution. GHSA-qp7p-654g-cw7p

Improper validation of NumericDate claims (exp, nbf, iat) in JWT verify()

Affects: hono/utils/jwt. Fixes improper validation of exp, nbf, and iat claims, where falsy, non-finite, or non-numeric values could silently bypass time-based checks instead of being rejected per RFC 7519. GHSA-hm8q-7f3q-5f36


Users who use the JWT helper, hono/jsx, or the Cache middleware are strongly encouraged to upgrade to this version.

v4.12.17

Compare Source

What's Changed

New Contributors

Full Changelog: honojs/hono@v4.12.16...v4.12.17

v4.12.16

Compare Source

Security fixes

This release includes fixes for the following security issues:

Unvalidated JSX Tag Names in hono/jsx May Allow HTML Injection

Affects: hono/jsx. Fixes missing validation of JSX tag names when using jsx() or createElement(), which could allow HTML injection if untrusted input is used as the tag name. GHSA-69xw-7hcm-h432

bodyLimit() can be bypassed for chunked / unknown-length requests

Affects: Body Limit Middleware. Fixes late enforcement for request bodies without a reliable Content-Length (e.g. chunked requests), where oversized requests could reach handlers and return successful responses before being rejected. GHSA-9vqf-7f2p-gf9v

v4.12.15

Compare Source

What's Changed

New Contributors

Full Changelog: honojs/hono@v4.12.14...v4.12.15


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the bump label Feb 26, 2026
@renovate
renovate Bot force-pushed the renovate/hono-4.x branch 3 times, most recently from c9c00e4 to 10755fd Compare February 28, 2026 12:28
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.12.3 chore(deps): update dependency hono to v4.12.4 Mar 3, 2026
@renovate
renovate Bot force-pushed the renovate/hono-4.x branch from 10755fd to c0e4287 Compare March 3, 2026 13:42
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.12.4 chore(deps): update dependency hono to v4.12.5 Mar 4, 2026
@renovate
renovate Bot force-pushed the renovate/hono-4.x branch 2 times, most recently from 6b9a9d1 to 29cb5c1 Compare March 10, 2026 06:19
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.12.5 chore(deps): update dependency hono to v4.12.6 Mar 10, 2026
@renovate
renovate Bot force-pushed the renovate/hono-4.x branch from 29cb5c1 to 781107f Compare March 10, 2026 14:01
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.12.6 chore(deps): update dependency hono to v4.12.7 Mar 10, 2026
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.12.7 chore(deps): update dependency hono to v4.12.8 Mar 15, 2026
@renovate
renovate Bot force-pushed the renovate/hono-4.x branch from 781107f to 5a4607f Compare March 15, 2026 02:00
@renovate
renovate Bot force-pushed the renovate/hono-4.x branch from 5a4607f to 6fa01c5 Compare March 23, 2026 13:04
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.12.8 chore(deps): update dependency hono to v4.12.9 Mar 23, 2026
@renovate
renovate Bot force-pushed the renovate/hono-4.x branch from 6fa01c5 to 56e33ef Compare April 2, 2026 13:58
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.12.9 chore(deps): update dependency hono to v4.12.10 Apr 2, 2026
@renovate
renovate Bot force-pushed the renovate/hono-4.x branch from 56e33ef to 84d3442 Compare April 6, 2026 09:40
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.12.10 chore(deps): update dependency hono to v4.12.11 Apr 6, 2026
@renovate
renovate Bot force-pushed the renovate/hono-4.x branch from 84d3442 to 0dcc9e4 Compare April 7, 2026 05:41
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.12.11 chore(deps): update dependency hono to v4.12.12 Apr 7, 2026
@renovate
renovate Bot force-pushed the renovate/hono-4.x branch from 0dcc9e4 to 26944c7 Compare April 15, 2026 05:42
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.12.12 chore(deps): update dependency hono to v4.12.13 Apr 15, 2026
@renovate
renovate Bot force-pushed the renovate/hono-4.x branch from 26944c7 to 3d6076c Compare April 15, 2026 08:53
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.12.13 chore(deps): update dependency hono to v4.12.14 Apr 15, 2026
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.12.14 chore(deps): update dependency hono to v4.12.14 - autoclosed Apr 20, 2026
@renovate renovate Bot closed this Apr 20, 2026
@renovate
renovate Bot deleted the renovate/hono-4.x branch April 20, 2026 22:32
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.12.14 - autoclosed chore(deps): update dependency hono to v4.12.15 Apr 24, 2026
@renovate
renovate Bot force-pushed the renovate/hono-4.x branch from 161ea4e to 6f72394 Compare May 19, 2026 16:40
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.12.19 chore(deps): update dependency hono to v4.12.21 May 19, 2026
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.12.21 chore(deps): update dependency hono to v4.12.22 May 22, 2026
@renovate
renovate Bot force-pushed the renovate/hono-4.x branch 2 times, most recently from 0da1139 to 8e9f37e Compare May 25, 2026 06:00
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.12.22 chore(deps): update dependency hono to v4.12.23 May 25, 2026
@renovate
renovate Bot force-pushed the renovate/hono-4.x branch from 8e9f37e to 70c0029 Compare June 8, 2026 14:11
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.12.23 chore(deps): update dependency hono to v4.12.24 Jun 8, 2026
@renovate
renovate Bot force-pushed the renovate/hono-4.x branch from 70c0029 to 6cb87bd Compare June 9, 2026 06:59
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.12.24 chore(deps): update dependency hono to v4.12.25 Jun 9, 2026
@renovate
renovate Bot force-pushed the renovate/hono-4.x branch from 6cb87bd to 374d034 Compare June 18, 2026 13:11
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.12.25 chore(deps): update dependency hono to v4.12.26 Jun 18, 2026
@renovate
renovate Bot force-pushed the renovate/hono-4.x branch from 374d034 to 47581e1 Compare June 23, 2026 05:29
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.12.26 chore(deps): update dependency hono to v4.12.27 Jun 23, 2026
@renovate
renovate Bot force-pushed the renovate/hono-4.x branch from 47581e1 to 85a6403 Compare July 6, 2026 15:04
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.12.27 chore(deps): update dependency hono to v4.12.28 Jul 6, 2026
@renovate
renovate Bot force-pushed the renovate/hono-4.x branch from 85a6403 to ecacbf3 Compare July 10, 2026 18:46
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.12.28 chore(deps): update dependency hono to v4.12.29 Jul 10, 2026
@renovate
renovate Bot force-pushed the renovate/hono-4.x branch from ecacbf3 to d96e1c3 Compare July 13, 2026 01:35
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.12.29 chore(deps): update dependency hono to v4.12.30 Jul 13, 2026
@renovate
renovate Bot force-pushed the renovate/hono-4.x branch from d96e1c3 to ddab811 Compare July 19, 2026 02:38
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.12.30 chore(deps): update dependency hono to v4.12.31 Jul 19, 2026
@renovate
renovate Bot force-pushed the renovate/hono-4.x branch from ddab811 to f0d88a4 Compare July 24, 2026 17:05
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.12.31 chore(deps): update dependency hono to v4.12.32 Jul 24, 2026
@renovate
renovate Bot force-pushed the renovate/hono-4.x branch from f0d88a4 to 9d1ef74 Compare July 31, 2026 15:49
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.12.32 chore(deps): update dependency hono to v4.12.33 Jul 31, 2026
@renovate
renovate Bot force-pushed the renovate/hono-4.x branch from 9d1ef74 to a0d1e8a Compare August 3, 2026 03:25
@renovate renovate Bot changed the title chore(deps): update dependency hono to v4.12.33 chore(deps): update dependency hono to v4.12.34 Aug 3, 2026
@renovate
renovate Bot force-pushed the renovate/hono-4.x branch from a0d1e8a to be40446 Compare August 4, 2026 01:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants