chore(deps): update dependency hono to v4.13.1 - #44
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
renovate
Bot
force-pushed
the
renovate/hono-4.x-lockfile
branch
from
July 6, 2026 14:55
03776fa to
900d768
Compare
renovate
Bot
force-pushed
the
renovate/hono-4.x-lockfile
branch
from
July 10, 2026 11:41
900d768 to
13e26d6
Compare
renovate
Bot
force-pushed
the
renovate/hono-4.x-lockfile
branch
from
July 13, 2026 03:08
13e26d6 to
11bd843
Compare
renovate
Bot
force-pushed
the
renovate/hono-4.x-lockfile
branch
2 times, most recently
from
July 24, 2026 12:05
e396741 to
9036f0e
Compare
renovate
Bot
force-pushed
the
renovate/hono-4.x-lockfile
branch
from
July 31, 2026 15:40
9036f0e to
107140d
Compare
renovate
Bot
force-pushed
the
renovate/hono-4.x-lockfile
branch
2 times, most recently
from
August 4, 2026 02:51
0926112 to
73560d8
Compare
renovate
Bot
force-pushed
the
renovate/hono-4.x-lockfile
branch
from
August 7, 2026 10:09
73560d8 to
4d5e98c
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
4.12.25→4.13.1Release Notes
honojs/hono (hono)
v4.13.1Compare Source
v4.13.0Compare Source
Hono v4.13.0 is now available!
The highlight of this release is performance: a batch of low-level optimizations makes the core request/response path significantly faster — up to 1.25x on common routes in our benchmark. This release also adds first-class support for the HTTP QUERY method, defined in RFC 10008, a new Method Not Allowed middleware, and more.
Performance improvements
This release includes a series of small optimizations: skipping unnecessary
Headersallocations, replacing regex tests withindexOf, allocating internal state lazily, and more.Here is
benchmarks/fetchcomparing v4.12 and v4.13 (ROUNDS=5 ./compare.sh, Bun 1.4.0, Apple Silicon — each measurement runs in a fresh process, and the variant order is reversed every round to avoid warm-up bias):ping—GET /query—GET /id/1?name=bunjson—GET /userbody—POST /jsonThe individual changes:
for..in#5118indexOf#5121Headerscreation when there are no headers to merge #5122tryDecodeURIComponent#5158#validatedDatalazily #5175In addition, the RegExpRouter rewrite described below makes route registration plus the first match roughly 20% faster.
Thanks @kibertoad for the contributions!
First-class QUERY method support
The QUERY method — a safe, idempotent method that carries a request body — is now a first-class citizen in Hono. You can define QUERY handlers with
app.query():Thanks @shellhaki!
QUERY support across built-in middleware
The built-in middleware has been updated to handle QUERY requests properly:
Cache Middleware
The Cache Middleware now caches QUERY responses. Following RFC 10008 Section 2.7, the cache key incorporates a SHA-256 digest of the request content and its representation metadata, so different query bodies are cached separately:
Note: To support this, the internal cache key format has changed for all methods, including GET. Cached entries are now stored under an internal URL of the form
/.hono/cache?__hono_cache_key=.... If you purge cache entries by URL outside of the middleware (e.g. callingcaches.delete()with the original request URL), you will need to update that logic. Existing cache entries stored with the old format will simply be re-fetched.ETag Middleware
The ETag Middleware now handles conditional requests for QUERY, returning
304 Not ModifiedwhenIf-None-Matchmatches.CORS Middleware
The CORS Middleware now includes QUERY in the default
Access-Control-Allow-Methods, which is nowGET, HEAD, PUT, POST, DELETE, PATCH, QUERY. If you specifyallowMethodsexplicitly, nothing changes for you.Thanks @usualoma and @Cherry!
Method Not Allowed Middleware
The new Method Not Allowed Middleware returns a
405 Method Not Allowedresponse with a properAllowheader when the request path matches a registered route but the method does not:You can customize the response with the
onMethodNotAllowedoption:Thanks @usualoma!
RegExpRouter throws
UnsupportedPathErrorat registration timeThe RegExpRouter now detects unsupported path combinations when routes are registered, instead of at the first matching request. This means misconfigured routes fail fast at startup rather than at runtime. As a bonus, registration plus the first match is roughly 20% faster.
Thanks @usualoma!
Other improvements
hono/utils/headershas been synced with the IANA HTTP Field Name Registry, adding newly registered fields such asAccept-Query. Thanks @akahoshi1421!realmoption for theWWW-Authenticatechallenge on401responses, and challenge values are properly escaped. Thanks @arhxam!useRefandRefObjectare now aligned with React 19. Note that this is a type-level change —RefObject<T>is now{ current: T }, so type a nullable ref asRefObject<T | null>, and passuseRef(undefined)instead ofuseRef(). Thanks @ashunar0!Vary: Accept-Encodingon negotiated responses. Thanks @arhxam!All changes
fetchby @yusukebe in #5113indexOfby @yusukebe in #5121tryDecodeURIComponentby @yusukebe in #5158envfield initializer by @kibertoad in #5174#validatedDatalazily by @kibertoad in #5175fetchby @yusukebe in #5184envfield initializer by @yusukebe in #5186Full Changelog: honojs/hono@v4.12.34...v4.13.0
Thank you to all contributors!
v4.12.34Compare Source
v4.12.33Compare Source
What's Changed
@hono/node-serverin #5167Full Changelog: honojs/hono@v4.12.32...v4.12.33
v4.12.32Compare Source
What's Changed
Object.create(null)when parsing query, headers, and params in #5161Full Changelog: honojs/hono@v4.12.31...v4.12.32
v4.12.31Compare Source
v4.12.30Compare Source
What's Changed
Full Changelog: honojs/hono@v4.12.29...v4.12.30
v4.12.29Compare Source
What's Changed
compatibilityDateby @yusukebe in #5100*as a match by @yusukebe in #5084New Contributors
Full Changelog: honojs/hono@v4.12.28...v4.12.29
v4.12.28Compare Source
What's Changed
*.tsbuildinfoby @yusukebe in #5066devDependenciesby @yusukebe in #5085New Contributors
Full Changelog: honojs/hono@v4.12.27...v4.12.28
v4.12.27Compare Source
Security fixes
This release includes fixes for the following security issues:
hono/jsx does not isolate context per request
Affects:
hono/jsx,hono/jsx-renderer. During SSR, context was stored process-wide instead of per request, souseContext()/useRequestContext()read after anawaitin an async component could return another concurrent request's value — leading to cross-request data disclosure or authorization checks against the wrong request. GHSA-hvrm-45r6-mjfjServer-Side XSS via JSX escaping bypass in cx()
Affects:
hono/css.cx()marked its composed class name as already-escaped without escaping the input, so untrusted input passed as a class name could break out of the JSXclassattribute during SSR and inject markup (XSS). GHSA-w62v-xxxg-mg59API Gateway v1 adapter can drop a repeated request header value
Affects:
hono/aws-lambda. The API Gateway v1 (and VPC Lattice) adapter de-duplicated repeated header values by substring instead of exact match, dropping a value that is a substring of another (e.g.203.0.113.1dropped when203.0.113.10is present) — affecting logic such asX-Forwarded-For-based IP restriction. GHSA-xgm2-5f3f-mvvcUsers of
hono/jsx/hono/jsx-renderer,hono/css(cx()), or thehono/aws-lambdaAPI Gateway v1 / VPC Lattice adapters are encouraged to upgrade.v4.12.26Compare Source
What's Changed
Full Changelog: honojs/hono@v4.12.25...v4.12.26
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.