chore(deps): bump @hono/node-server from 1.19.13 to 2.0.10 (#2628)
Bumps [@hono/node-server](https://github.com/honojs/node-server) from 1.19.13 to 2.0.10. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/honojs/node-server/releases">@hono/node-server's releases</a>.</em></p> <blockquote> <h2>v2.0.10</h2> <h2>Security fixes</h2> <p>This release includes a fix for the following security issue:</p> <h3>Unauthenticated memory-leak DoS via aborted WebSocket handshake</h3> <p>Affects: <code>upgradeWebSocket</code>. A WebSocket upgrade request with a missing or malformed <code>Sec-WebSocket-Key</code> header leaked the request's <code>IncomingMessage</code> and left a promise pending, even though no connection was established. Since the route is reachable pre-handshake without authentication, an attacker could flood it to gradually exhaust memory. <a href="https://github.com/honojs/node-server/security/advisories/GHSA-9mqv-5hh9-4cgg">GHSA-9mqv-5hh9-4cgg</a></p> <hr /> <p>Users of <code>upgradeWebSocket</code> are encouraged to upgrade to this version.</p> <h2>v2.0.9</h2> <h2>What's Changed</h2> <ul> <li>fix(websocket): polyfill missing ErrorEvent global by <a href="https://github.com/otnc"><code>@otnc</code></a> in <a href="https://redirect.github.com/honojs/node-server/pull/371">honojs/node-server#371</a></li> <li>fix(serve-static): correct Range header parsing edge cases by <a href="https://github.com/otnc"><code>@otnc</code></a> in <a href="https://redirect.github.com/honojs/node-server/pull/372">honojs/node-server#372</a></li> <li>fix: recover complete request bodies after client disconnect by <a href="https://github.com/usualoma"><code>@usualoma</code></a> in <a href="https://redirect.github.com/honojs/node-server/pull/375">honojs/node-server#375</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/otnc"><code>@otnc</code></a> made their first contribution in <a href="https://redirect.github.com/honojs/node-server/pull/371">honojs/node-server#371</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/honojs/node-server/compare/v2.0.8...v2.0.9">https://github.com/honojs/node-server/compare/v2.0.8...v2.0.9</a></p> <h2>v2.0.8</h2> <h2>What's Changed</h2> <ul> <li>ci(release): add <code>--no-git-checks</code> option for <code>pnpm stage publish</code> by <a href="https://github.com/yusukebe"><code>@yusukebe</code></a> in <a href="https://redirect.github.com/honojs/node-server/pull/369">honojs/node-server#369</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/honojs/node-server/compare/v2.0.7...v2.0.8">https://github.com/honojs/node-server/compare/v2.0.7...v2.0.8</a></p> <h2>v2.0.7</h2> <h2>What's Changed</h2> <ul> <li>chore: migrate to pnpm by <a href="https://github.com/BlankParticle"><code>@BlankParticle</code></a> in <a href="https://redirect.github.com/honojs/node-server/pull/367">honojs/node-server#367</a></li> <li>fix(serve-static): serve precompressed files for application/octet-stream by <a href="https://github.com/yusukebe"><code>@yusukebe</code></a> in <a href="https://redirect.github.com/honojs/node-server/pull/366">honojs/node-server#366</a></li> <li>chore: bump <code>supertest</code> by <a href="https://github.com/yusukebe"><code>@yusukebe</code></a> in <a href="https://redirect.github.com/honojs/node-server/pull/368">honojs/node-server#368</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/honojs/node-server/compare/v2.0.6...v2.0.7">https://github.com/honojs/node-server/compare/v2.0.6...v2.0.7</a></p> <h2>v2.0.6</h2> <h2>What's Changed</h2> <ul> <li>ci: publish to npm from CI with OIDC trusted publishing and bump <code>np</code> by <a href="https://github.com/yusukebe"><code>@yusukebe</code></a> in <a href="https://redirect.github.com/honojs/node-server/pull/361">honojs/node-server#361</a></li> <li>ci: use npm Staged publishing by <a href="https://github.com/yusukebe"><code>@yusukebe</code></a> in <a href="https://redirect.github.com/honojs/node-server/pull/364">honojs/node-server#364</a></li> <li>fix: preserve status and statusText when cloning a Response with liveheaders by <a href="https://github.com/usualoma"><code>@usualoma</code></a> in <a href="https://redirect.github.com/honojs/node-server/pull/363">honojs/node-server#363</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/honojs/node-server/compare/v2.0.5...v2.0.6">https://github.com/honojs/node-server/compare/v2.0.5...v2.0.6</a></p> <h2>v2.0.5</h2> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/honojs/node-server/commit/7c1457ed5536c02fdd2f001129fae67bcbca54a1"><code>7c1457e</code></a> 2.0.10</li> <li><a href="https://github.com/honojs/node-server/commit/3a21938c418340e980cb7ffa88e78369f78392d1"><code>3a21938</code></a> Merge commit from fork</li> <li><a href="https://github.com/honojs/node-server/commit/98420217e53a17a238ef1aa1a6bef0b2b70136c5"><code>9842021</code></a> 2.0.9</li> <li><a href="https://github.com/honojs/node-server/commit/51f3bf56f56d9691ec0f7e1562a96f0b485a7dd9"><code>51f3bf5</code></a> fix: recover complete request bodies after client disconnect (<a href="https://redirect.github.com/honojs/node-server/issues/375">#375</a>)</li> <li><a href="https://github.com/honojs/node-server/commit/fdb87badbe313cfbfe6bb2355e9893dc0698d2bd"><code>fdb87ba</code></a> fix(serve-static): correct Range header parsing edge cases (<a href="https://redirect.github.com/honojs/node-server/issues/372">#372</a>)</li> <li><a href="https://github.com/honojs/node-server/commit/912e3fd80c4311756f724bd566de1433c8d772d9"><code>912e3fd</code></a> fix(websocket): polyfill missing ErrorEvent global (<a href="https://redirect.github.com/honojs/node-server/issues/371">#371</a>)</li> <li><a href="https://github.com/honojs/node-server/commit/114c15efb38dabaf81af774ddb764409e3d156d8"><code>114c15e</code></a> 2.0.8</li> <li><a href="https://github.com/honojs/node-server/commit/5db2d5df662cd69ff5c4cc23b8ecb3a6f63e4e38"><code>5db2d5d</code></a> ci(release): add <code>--no-git-checks</code> option for <code>pnpm stage publish</code> (<a href="https://redirect.github.com/honojs/node-server/issues/369">#369</a>)</li> <li><a href="https://github.com/honojs/node-server/commit/a528a77ed2c28dc12775c849abc6b6df6d4cb44c"><code>a528a77</code></a> 2.0.7</li> <li><a href="https://github.com/honojs/node-server/commit/b2d610c1e37a96639fbb2eae662e858800aa8906"><code>b2d610c</code></a> chore: bump <code>supertest</code> (<a href="https://redirect.github.com/honojs/node-server/issues/368">#368</a>)</li> <li>Additional commits viewable in <a href="https://github.com/honojs/node-server/compare/v1.19.13...v2.0.10">compare view</a></li> </ul> </details> <details> <summary>Maintainer changes</summary> <p>This version was pushed to npm by <a href="https://www.npmjs.com/~GitHub%20Actions">GitHub Actions</a>, a new releaser for <code>@hono/node-server</code> since your current version.</p> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
D
dependabot[bot] committed
708770350bfd7c623f14c18ededa6455b5ebbe36
Parent: fa98921
Committed by GitHub <noreply@github.com>
on 7/23/2026, 8:14:43 PM