Skip to content

fix(deps): bump transitive hono to patch high-sev vulnerabilities - #1

Merged
idapixl merged 1 commit into
masterfrom
fix/hono-dependabot-blindspot
Jul 9, 2026
Merged

fix(deps): bump transitive hono to patch high-sev vulnerabilities#1
idapixl merged 1 commit into
masterfrom
fix/hono-dependabot-blindspot

Conversation

@idapixl

@idapixl idapixl commented Jul 9, 2026

Copy link
Copy Markdown
Contributor

Summary

  • hono (peerDependency of @modelcontextprotocol/sdk, range ^4.11.4) was locked to the vulnerable 4.12.23
  • GitHub's dependency graph never generated a Dependabot alert for this — same blind spot found and fixed in tools-graph on 2026-07-06
  • npm audit fix bumps it in-range to 4.12.28, matching the version already in use by tools-threads/tools-journal/tools-vitals/tools-maintenance/tools-graph

Verification

  • npm audit: 0 vulnerabilities (was 1 high)
  • npm run build: tsc exits 0
  • Only package-lock.json changed

Found during scheduled ecosystem health check (2026-07-09). No open Dependabot alert exists for this repo to auto-close — GitHub's advisory database update lags behind npm's, which is why this went undetected.

🤖 Generated with Claude Code

hono <=4.12.24 (peerDependency of @modelcontextprotocol/sdk, range
^4.11.4) was resolved to the vulnerable 4.12.23 in the lockfile.
GitHub's dependency graph never generated a Dependabot alert for it
(same blind spot found in tools-graph on 2026-07-06). npm audit fix
resolves it in-range to 4.12.28.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Copilot AI review requested due to automatic review settings July 9, 2026 16:23

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request.


💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@idapixl
idapixl merged commit 1c6c2ef into master Jul 9, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants