Bumps the npm_and_yarn group with 2 updates in the / directory: dompurify [QUARANTINED_URL: github.com] and hono [QUARANTINED_URL: github.com].
Updates dompurify from 3.4.12 to 3.4.13
Release notes
Sourced from dompurify's releases.
DOMPurify 3.4.13
- Fixed an issue with hook removal during
IN_PLACE sanitization, thanks @koyokr
- Fixed an issue with hooks potentially bypassing the clone guard, thanks
@AkshayjainG
- Fixed an issue with DOM clobbering via
ownerDocument during IN_PLACE, thanks @AkshayjainG
- Bumped several dependencies where possible
Commits
Updates hono from 4.12.31 to 4.13.1
Release notes
Sourced from hono's releases.
v4.13.1
What's Changed
New Contributors
Full Changelog: [QUARANTINED_URL: github.com]
v4.13.0
Hono v4.13.0 is now available!
The highlight of this release is performance: a batch of low-level optimizations makes the core request/response path significantly faster — up to 1.25x on common routes in our benchmark. This release also adds first-class support for the HTTP QUERY method, defined in RFC 10008, a new Method Not Allowed middleware, and more.
Performance improvements
This release includes a series of small optimizations: skipping unnecessary Headers allocations, replacing regex tests with indexOf, allocating internal state lazily, and more.
Here is benchmarks/fetch comparing v4.12 and v4.13 (ROUNDS=5 ./compare.sh, Bun 1.4.0, Apple Silicon — each measurement runs in a fresh process, and the variant order is reversed every round to avoid warm-up bias):
| Benchmark |
v4.12 |
v4.13 |
Speedup |
ping — GET / |
165.83 ns |
163.99 ns |
1.01x |
query — GET /id/1?name=bun |
674.40 ns |
616.99 ns |
1.09x |
json — GET /user |
528.99 ns |
422.44 ns |
1.25x |
body — POST /json |
1.16 µs |
1.00 µs |
1.15x |
The individual changes:
In addition, the RegExpRouter rewrite described below makes route registration plus the first match roughly 20% faster.
Thanks @kibertoad for the contributions!
First-class QUERY method support
The QUERY method — a safe, idempotent method that carries a request body — is now a first-class citizen in Hono. You can define QUERY handlers with app.query():
const app = new Hono()
</tr></table>
... (truncated)
Commits
cf78528 4.13.1
f6aa913 fix(etag): skip unsafe methods or error responses on non-* case (#5196)
cd31bc1 fix(utils/stream): re-acquire writer lock when pipe() throws (#4988)
569b419 fix(trie-router): count every slash a pattern consumes (#5189)
192768f 4.13.0
b0c2d90 Merge pull request #5154 from honojs/next
8f07028 fix(compress): set Vary: Accept-Encoding on negotiated responses (#5137)
8a0b18f feat(reg-exp-router): throw UnsupportedPathError during route registration (#...
3feb355 fix(jsx): allow a function component to return an array (#5179)
5d911d2 feat(utils/headers): add HTTP fields newly registered with IANA (#5153)
- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase will rebase this PR
@dependabot recreate will recreate this PR, overwriting any edits that have been made to it
@dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
@dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
@dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
@dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
@dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
@dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions
You can disable automated security fix PRs for this repo from the Security Alerts page [QUARANTINED_URL: github.com].
Bumps the npm_and_yarn group with 2 updates in the / directory: dompurify [QUARANTINED_URL: github.com] and hono [QUARANTINED_URL: github.com].
Updates
dompurifyfrom 3.4.12 to 3.4.13Release notes
Sourced from dompurify's releases.
Commits
3067f77release: 3.4.13 (#1562)Updates
honofrom 4.12.31 to 4.13.1Release notes
Sourced from hono's releases.
... (truncated)
Commits
cf785284.13.1f6aa913fix(etag): skip unsafe methods or error responses on non-* case (#5196)cd31bc1fix(utils/stream): re-acquire writer lock when pipe() throws (#4988)569b419fix(trie-router): count every slash a pattern consumes (#5189)192768f4.13.0b0c2d90Merge pull request #5154 from honojs/next8f07028fix(compress): set Vary: Accept-Encoding on negotiated responses (#5137)8a0b18ffeat(reg-exp-router): throw UnsupportedPathError during route registration (#...3feb355fix(jsx): allow a function component to return an array (#5179)5d911d2feat(utils/headers): add HTTP fields newly registered with IANA (#5153)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions You can disable automated security fix PRs for this repo from the Security Alerts page [QUARANTINED_URL: github.com].