what stackpulse tracks
Hono releases from GitHub
StackPulse watches Hono release notes and keeps the original source link close to every summary.
Ultrafast web framework for the Edges StackPulse turns upstream changelogs into scannable summaries with risky changes, deprecations, migration notes, and source links.
what stackpulse tracks
StackPulse watches Hono release notes and keeps the original source link close to every summary.
upgrade risk
Risky changes are separated from normal feature notes so you can scan upgrade impact before changing production dependencies.
migration notes
Migration steps and recommended actions are only shown when the upstream release notes support them.
This release fixes a critical XSS vulnerability in `hono/jsx` where plain strings were rendered unescaped in boundary components and server rendering functions, potentially allowing untrusted strings to be emitted as markup.
Users who render untrusted strings inside `Suspense`, `ErrorBoundary`, or `Context.Provider`, or pass them directly to `hono/jsx/dom/server` are affected by this XSS vulnerability.
Upgrade to v4.13.7 immediately if you render untrusted strings in the affected components or server rendering functions.
This release addresses critical security vulnerabilities affecting Cache Middleware, Static Site Generation, and `parseBody()` functionality. It fixes query parsing issues, path normalization gaps, and memory exhaustion risks.
Users who use Cache Middleware, deploy behind a proxy or WAF that inspects query strings, use Static Site Generation, or use `parseBody({ dot: true })` are affected.
Upgrade to this version immediately to mitigate security risks.
This release addresses several critical security vulnerabilities affecting SSR, CORS, language middleware, and proxy functionality. The fixes prevent cross-user data disclosure, ReDoS attacks, and algorithmic complexity DoS vulnerabilities.
Users of `hono/jsx` for SSR, `hono/cors`, `hono/language`, or `hono/proxy` are affected by security vulnerabilities.
Upgrade to v4.12.34 immediately if using `hono/jsx` for SSR, `hono/cors`, `hono/language`, or `hono/proxy`.
This release addresses several critical security issues affecting `hono/jsx`, `hono/css`, and `hono/aws-lambda` adapters, fixing context isolation, XSS vulnerabilities, and header handling problems.
Users of `hono/jsx`, `hono/jsx-renderer`, `hono/css` (`cx()`), or the `hono/aws-lambda` API Gateway v1 / VPC Lattice adapters are affected.
Upgrade to version v4.12.27 to mitigate the security vulnerabilities.
This release focuses on addressing several critical security vulnerabilities across various middleware and adapters, including CORS, body limit, static file serving, and AWS Lambda integrations.
Users of Hono's CORS, body limit, static file serving, and AWS Lambda integrations are affected by these security vulnerabilities.
Upgrade to v4.12.25 immediately to mitigate the security risks.