Skip to content

fix: bump hono override to ^4.12.7 (GHSA-v8w9-8mx6-g223)#423

Merged
Daghis merged 1 commit intomainfrom
fix/bump-hono-4.12.7
Mar 13, 2026
Merged

fix: bump hono override to ^4.12.7 (GHSA-v8w9-8mx6-g223)#423
Daghis merged 1 commit intomainfrom
fix/bump-hono-4.12.7

Conversation

@Daghis
Copy link
Owner

@Daghis Daghis commented Mar 13, 2026

Summary

Test plan

  • npm run check passes (typecheck, lint, format)
  • CI passes

🤖 Generated with Claude Code

Addresses Dependabot alert #39 (prototype pollution via parseBody
with dot notation). Not exploitable in this project since we don't
use parseBody({ dot: true }), but bumping to clear the alert.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@codecov-commenter
Copy link

codecov-commenter commented Mar 13, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 82.43%. Comparing base (9326a16) to head (4eafefd).
⚠️ Report is 1 commits behind head on main.
✅ All tests successful. No failed tests found.

Impacted file tree graph

@@           Coverage Diff           @@
##             main     #423   +/-   ##
=======================================
  Coverage   82.43%   82.43%           
=======================================
  Files          49       49           
  Lines        7003     7003           
  Branches     2110     2110           
=======================================
  Hits         5773     5773           
  Misses        482      482           
  Partials      748      748           
Flag Coverage Δ
unittests 82.22% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

🚀 New features to boost your workflow:
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@Daghis Daghis merged commit d37b790 into main Mar 13, 2026
19 checks passed
@Daghis Daghis deleted the fix/bump-hono-4.12.7 branch March 13, 2026 18:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants