Bumps the npm_and_yarn group with 2 updates in the / directory: @hono/node-server [QUARANTINED_URL: github.com] and ip-address [QUARANTINED_URL: github.com].
Updates @hono/node-server from 1.19.13 to 2.0.12
Release notes
Sourced from @hono/node-server's releases.
v2.0.12
What's Changed
Full Changelog: [QUARANTINED_URL: github.com]
v2.0.11
What's Changed
Full Changelog: [QUARANTINED_URL: github.com]
v2.0.10
Security fixes
This release includes a fix for the following security issue:
Unauthenticated memory-leak DoS via aborted WebSocket handshake
Affects: upgradeWebSocket. A WebSocket upgrade request with a missing or malformed Sec-WebSocket-Key header leaked the request's IncomingMessage and left a promise pending, even though no connection was established. Since the route is reachable pre-handshake without authentication, an attacker could flood it to gradually exhaust memory. GHSA-9mqv-5hh9-4cgg
Users of upgradeWebSocket are encouraged to upgrade to this version.
v2.0.9
What's Changed
New Contributors
Full Changelog: [QUARANTINED_URL: github.com]
v2.0.8
What's Changed
Full Changelog: [QUARANTINED_URL: github.com]
v2.0.7
What's Changed
... (truncated)
Commits
Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for @hono/node-server since your current version.
Updates ip-address from 10.2.0 to 10.4.0
Release notes
Sourced from ip-address's releases.
v10.4.0
What's Changed
Full Changelog: [QUARANTINED_URL: github.com]
v10.3.1
Full Changelog: [QUARANTINED_URL: github.com]
v10.3.0
Full Changelog: [QUARANTINED_URL: github.com]
v10.2.2
Full Changelog: [QUARANTINED_URL: github.com]
v10.2.1
Full Changelog: [QUARANTINED_URL: github.com]
Commits
fbb8db2 10.4.0
45a2b11 Validate the byte arrays Address6 is given (#217)
bac8810 Keep the package loadable on node 12, and enforce it (#216)
9b3d848 Add a security policy and a README section on security posture
e84a7b3 Order the README API reference Address4, Address6, AddressError
015160b Collapse each class in the README API reference
34061a8 Pin checkout and setup-node to commits in the release job
c5fae5d Pin action-gh-release to a commit and move it to 3.0.2
e0ef048 Replace CircleCI with GitHub Actions
5e3ceb7 Add GitHub Actions CI across Node 20, 22, 24 and 25 (#213)
- Additional commits viewable in compare view
Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for ip-address since your current version.
Install script changes
This version adds prepare script that runs during installation. Review the package contents before updating.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase will rebase this PR
@dependabot recreate will recreate this PR, overwriting any edits that have been made to it
@dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
@dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
@dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
@dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
@dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
@dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions
You can disable automated security fix PRs for this repo from the Security Alerts page [QUARANTINED_URL: github.com].
Bumps the npm_and_yarn group with 2 updates in the / directory: @hono/node-server [QUARANTINED_URL: github.com] and ip-address [QUARANTINED_URL: github.com].
Updates
@hono/node-serverfrom 1.19.13 to 2.0.12Release notes
Sourced from @hono/node-server's releases.
... (truncated)
Commits
a813b6c2.0.12caf48bafix(response): copy headers when init is a foreign Response (#382)3b1dd68test: replace supertest (#379)834e54f2.0.11ba72bcdperf(request): fast-path PATCH method (#380)962baa4perf(request): fast-path QUERY methods (#376)62284d6test: use a custom helper for path traversal tests (#377)7c1457e2.0.103a21938Merge commit from fork98420212.0.9Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for
@hono/node-serversince your current version.Updates
ip-addressfrom 10.2.0 to 10.4.0Release notes
Sourced from ip-address's releases.
Commits
fbb8db210.4.045a2b11Validate the byte arrays Address6 is given (#217)bac8810Keep the package loadable on node 12, and enforce it (#216)9b3d848Add a security policy and a README section on security posturee84a7b3Order the README API reference Address4, Address6, AddressError015160bCollapse each class in the README API reference34061a8Pin checkout and setup-node to commits in the release jobc5fae5dPin action-gh-release to a commit and move it to 3.0.2e0ef048Replace CircleCI with GitHub Actions5e3ceb7Add GitHub Actions CI across Node 20, 22, 24 and 25 (#213)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for ip-address since your current version.
Install script changes
This version adds
preparescript that runs during installation. Review the package contents before updating.Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions You can disable automated security fix PRs for this repo from the Security Alerts page [QUARANTINED_URL: github.com].