Skip to content

H-6747: Update @hono/node-server and body-parser - #9148

Merged
CiaranMn merged 3 commits into
mainfrom
cm/dep-updates
Aug 3, 2026
Merged

CiaranMn merged 3 commits into
mainfrom
cm/dep-updates

Conversation

@CiaranMn

@CiaranMn CiaranMn commented Aug 3, 2026

Copy link
Copy Markdown
Member

🌟 What is the purpose of this PR?

Addressing security advisories.

@CiaranMn
CiaranMn requested review from TimDiekmann and Copilot August 3, 2026 10:19

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request.

@vercel

vercel Bot commented Aug 3, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
hash Ready Ready Preview Aug 3, 2026 2:00pm
hashdotdesign-tokens Ready Ready Preview Aug 3, 2026 2:00pm
petrinaut Ready Ready Preview Aug 3, 2026 2:00pm

@cursor

cursor Bot commented Aug 3, 2026 •

Copy link
Copy Markdown

PR Summary

Low Risk
Lockfile-only patch/minor dependency bumps for known advisories; no runtime or API changes in repo source.

Overview
Bumps transitive dependencies in yarn.lock to address security advisories, with no application code changes.

@hono/node-server is updated from 1.19.14 to 1.19.17 (includes a backported fix related to advisory GHSA-frvp-7c67-39w9, which the repo already documents in preflight allow-list config). The legacy body-parser@~1.20.3 resolution moves from 1.20.4 to 1.20.6, pulling qs from ~6.14.0 to ~6.15.1.

Reviewed by Cursor Bugbot for commit 97f7ea0. Bugbot is set up for automated code reviews on this repo. Configure here.

@github-actions github-actions Bot added the area/deps Relates to third-party dependencies (area) label Aug 3, 2026
@github-actions

github-actions Bot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

Dependency Review

The following issues were found:
  • ❌ 1 vulnerable package(s)
  • ✅ 0 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ✅ 0 package(s) with unknown licenses.
See the Details below.

Vulnerabilities

yarn.lock

NameVersionVulnerabilitySeverityPatched Version
@hono/node-server1.19.17Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)moderate2.0.5

OpenSSF Scorecard

PackageVersionScoreDetails
npm/@hono/node-server 1.19.17 UnknownUnknown
npm/body-parser 1.20.6 🟢 8
Details
CheckScoreReason
Code-Review🟢 8Found 12/15 approved changesets -- score normalized to 8
Dependency-Update-Tool🟢 10update tool detected
Maintained🟢 1019 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10
Pinned-Dependencies🟢 6dependency not pinned by hash detected -- score normalized to 6
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Binary-Artifacts🟢 10no binaries found in the repo
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
Vulnerabilities🟢 100 existing vulnerabilities detected
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
SAST🟢 9SAST tool detected but not run on all commits
Fuzzing⚠️ 0project is not fuzzed
Security-Policy🟢 10security policy file detected
Branch-Protection⚠️ 1branch protection is not maximal on development and all release branches
CI-Tests🟢 929 out of 30 merged PRs checked by a CI test -- score normalized to 9
Contributors🟢 10project has 32 contributing companies or organizations

Scanned Files

  • yarn.lock

Copilot AI review requested due to automatic review settings August 3, 2026 13:46

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request.

@vercel
vercel Bot temporarily deployed to Preview – hashdotdesign-tokens August 3, 2026 13:49 Inactive
@vercel
vercel Bot temporarily deployed to Preview – petrinaut August 3, 2026 13:51 Inactive
@CiaranMn
CiaranMn added this pull request to the merge queue Aug 3, 2026
Merged via the queue into main with commit c15069f Aug 3, 2026
52 checks passed
@CiaranMn
CiaranMn deleted the cm/dep-updates branch August 3, 2026 14:29

This branch was successfully deployed

1 active and 2 inactive deployments
Preview – hash — 97f7ea0a Deployed Aug 3, 2026 by vercel[bot]
Preview – petrinaut — 97f7ea0a Deployed Aug 3, 2026 by vercel[bot]
Preview – hashdotdesign-tokens — 97f7ea0a Deployed Aug 3, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/deps Relates to third-party dependencies (area)

Development

Successfully merging this pull request may close these issues.

3 participants