Zum Inhalt springen

Hono Release Notes

28 Einträge aus 1 Quelle. Zuletzt aktualisiert:

Folge Hono, um die Release Notes in deinen Feed zu holen.

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Hono

Hono 4.12.28: Fixes bei serve-static, Content-Type, Bun und aws-lambda

Hono v4.12.28 behebt Fehler: serve-static behandelt leeren Inhalt als gefunden, Content-Type wird ohne Beachtung der Groß-/Kleinschreibung abgeglichen, Bun meldet das angeforderte Subprotokoll in WSContext.protocol, aws-lambda erkennt V2-Events über den Request-Kontext, und eine zirkuläre Abhängigkeit zwischen body.ts und request.ts entfällt.

What's Changed

New Contributors

Full Changelog: https://github.com/honojs/hono/compare/v4.12.27...v4.12.28

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Hono

Hono 4.12.27 mit Sicherheitsfixes

Version 4.12.27 behebt Sicherheitslücken: fehlende Kontext-Isolierung pro Request in hono/jsx, einen XSS-Bypass in cx() von hono/css und das fälschliche Verwerfen wiederholter Header-Werte im API-Gateway-v1-Adapter von hono/aws-lambda.

Security fixes

This release includes fixes for the following security issues:

hono/jsx does not isolate context per request

Affects: hono/jsx, hono/jsx-renderer. During SSR, context was stored process-wide instead of per request, so useContext()/useRequestContext() read after an await in an async component could return another concurrent request's value — leading to cross-request data disclosure or authorization checks against the wrong request. GHSA-hvrm-45r6-mjfj

Server-Side XSS via JSX escaping bypass in cx()

Affects: hono/css. cx() marked its composed class name as already-escaped without escaping the input, so untrusted input passed as a class name could break out of the JSX class attribute during SSR and inject markup (XSS). GHSA-w62v-xxxg-mg59

API Gateway v1 adapter can drop a repeated request header value

Affects: hono/aws-lambda. The API Gateway v1 (and VPC Lattice) adapter de-duplicated repeated header values by substring instead of exact match, dropping a value that is a substring of another (e.g. 203.0.113.1 dropped when 203.0.113.10 is present) — affecting logic such as X-Forwarded-For-based IP restriction. GHSA-xgm2-5f3f-mvvc


Users of hono/jsx/hono/jsx-renderer, hono/css (cx()), or the hono/aws-lambda API Gateway v1 / VPC Lattice adapters are encouraged to upgrade.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Hono

Hono 4.12.26

Version 4.12.26 passt lambda-edge an die Deno-Lib-Typen für die Content-Length-Kodierung an und stellt die npm-Veröffentlichung auf OIDC Trusted Publishing um.

What's Changed

Full Changelog: https://github.com/honojs/hono/compare/v4.12.25...v4.12.26

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Hono

Hono 4.12.25 mit Sicherheitsfixes

Version 4.12.25 behebt Sicherheitslücken in der CORS-Middleware (Origin-Spiegelung mit Credentials), im Body Limit auf AWS Lambda bei zu niedrigem Content-Length sowie Path Traversal in serveStatic unter Windows über %5C und weitere Probleme.

Security fixes

This release includes fixes for the following security issues:

CORS Middleware reflects any Origin with credentials when origin defaults to the wildcard

Affects: hono/cors. Fixes the wildcard origin reflecting the request Origin and sending Access-Control-Allow-Credentials: true when credentials: true is set without an explicit origin, where any site a logged-in user visited could make credentialed cross-origin requests and read responses from cookie-authenticated endpoints. GHSA-88fw-hqm2-52qc

Body Limit Middleware can be bypassed on AWS Lambda by understating Content-Length

Affects: hono/body-limit on AWS Lambda (hono/aws-lambda, hono/lambda-edge). Fixes the request being built with the client-declared Content-Length while the body is delivered fully buffered, where a client could declare a small Content-Length with a much larger body and slip past the configured size limit. GHSA-rv63-4mwf-qqc2

Path traversal in serve-static on Windows via encoded backslash (%5C)

Affects: serveStatic on Windows (Node, Bun, Deno adapters). Fixes the path guard allowing a lone backslash, where an encoded backslash (%5C) decoded to \ was treated as a separator by the Windows path resolver, letting a single URL segment escape into a middleware-guarded subtree. GHSA-wwfh-h76j-fc44

AWS Lambda adapter merges multiple Set-Cookie headers into one value, dropping cookies on ALB single-header and Lattice …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Hono

Hono 4.12.24

Version 4.12.24 korrigiert die IPv6-Behandlung in utils/ipaddr (Erweiterung von "::" und Darstellung der unspezifizierten Adresse) und verbessert die Fehlermeldung von bearer-auth.

What's Changed

Full Changelog: https://github.com/honojs/hono/compare/v4.12.23...v4.12.24

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Hono

Hono 4.12.23

Version 4.12.23 exportiert die Context-Klasse öffentlich, ergänzt eine contentTypeFilter-Option für compress und normalisiert in serve-static alle Backslashes sowie korrigiert die IPv6-Komprimierung einzelner 0-Gruppen.

What's Changed

Full Changelog: https://github.com/honojs/hono/compare/v4.12.22...v4.12.23

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Hono

Hono 4.12.22

Version 4.12.22 legt den MIME-Charset je Typ fest, berücksichtigt Accept-Encoding bei compress, gibt unter Deno das ausgehandelte WebSocket-Subprotokoll zurück und behandelt msgpack als komprimierbaren Inhaltstyp.

What's Changed

New Contributors

Full Changelog: https://github.com/honojs/hono/compare/v4.12.21...v4.12.22

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Hono

Hono 4.12.21 mit Sicherheitsfixes

Version 4.12.21 behebt Sicherheitslücken bei app.mount() mit prozentkodierten Pfaden, bei der IP-Restriction mit nicht-kanonischem IPv6, bei fehlender Bereinigung von sameSite und priority im Cookie-Helper sowie bei der JWT-Middleware.

Security fixes

This release includes fixes for the following security issues:

app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded paths

Affects: app.mount(). Fixes prefix stripping using the raw URL pathname instead of the decoded path, where percent-encoded characters in the mount prefix or path could cause the prefix to be removed at the wrong position, resulting in the sub-application receiving an incorrect path. GHSA-2gcr-mfcq-wcc3

IP Restriction bypasses static deny rules for non-canonical IPv6

Affects: hono/ip-restriction. Fixes IP address comparison using string equality, where non-canonical IPv6 representations of a denied address — such as compressed forms or hex-notation IPv4-mapped addresses — could bypass static deny rules. GHSA-xrhx-7g5j-rcj5

Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injection

Affects: hono/cookie. Fixes missing validation of sameSite and priority options against injection characters (;, \r, \n), where user-controlled input passed to either option could inject additional attributes into the Set-Cookie response header. GHSA-3hrh-pfw6-9m5x

JWT middleware accepts any Authorization scheme, not only Bearer …

Originalquelle(öffnet in neuem Tab)Problem melden