Sourced from hono's releases.
v4.12.23
What's Changed
- fix(serve-static): normalize all backslashes in file paths, not just the first in honojs/hono#4962
- feat(context): export the Context class publicly by
@BlankParticlein honojs/hono#4543- docs(contribution): add AI Usage Policy by
@yusukebein honojs/hono#4970- feat(compress): add contentTypeFilter option and
COMPRESSIBLE_CONTENT_TYPE_REGEXre-export by@na-trium-144in honojs/hono#4961- fix(utils/ipaddr): do not compress a single 0 group to
::by@yusukebein honojs/hono#4971Full Changelog: https://github.com/honojs/hono/compare/v4.12.22...v4.12.23
v4.12.22
What's Changed
- chore: update vitest to v4 and cleanups by
@BlankParticlein honojs/hono#4952- fix(mime): specify charset parameter per MIME type instead of mechanical detection by
@renatograsso10in honojs/hono#4912- fix(compress): respect Accept-Encoding when encoding option is set by
@LeSingh1in honojs/hono#4951- fix(deno): echo negotiated WebSocket subprotocol in upgrade response by
@ATOM00bluein honojs/hono#4955- feat: add msgpack as a compressible content type by
@na-trium-144in honojs/hono#4957New Contributors
@renatograsso10made their first contribution in honojs/hono#4912@LeSingh1made their first contribution in honojs/hono#4951@ATOM00bluemade their first contribution in honojs/hono#4955@na-trium-144made their first contribution in honojs/hono#4957Full Changelog: https://github.com/honojs/hono/compare/v4.12.21...v4.12.22
v4.12.21
Security fixes
This release includes fixes for the following security issues:
app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded paths
Affects:
app.mount(). Fixes prefix stripping using the raw URL pathname instead of the decoded path, where percent-encoded characters in the mount prefix or path could cause the prefix to be removed at the wrong position, resulting in the sub-application receiving an incorrect path. GHSA-2gcr-mfcq-wcc3IP Restriction bypasses static deny rules for non-canonical IPv6
Affects:
hono/ip-restriction. Fixes IP address comparison using string equality, where non-canonical IPv6 representations of a denied address — such as compressed forms or hex-notation IPv4-mapped addresses — could bypass static deny rules. GHSA-xrhx-7g5j-rcj5Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injection
Affects:
hono/cookie. Fixes missing validation ofsameSiteandpriorityoptions against injection characters (;,\r,\n), where user-controlled input passed to either option could inject additional attributes into the Set-Cookie response header. GHSA-3hrh-pfw6-9m5xJWT middleware accepts any Authorization scheme, not only Bearer
Affects:
hono/jwt,hono/jwk. Fixes missing scheme validation in the Authorization header, where any two-part header value was accepted regardless of the scheme name, allowing non-Bearer schemes to pass JWT authentication. GHSA-f577-qrjj-4474
Users who use
app.mount(),hono/ip-restriction,hono/cookie, orhono/jwt/hono/jwkare encouraged to upgrade to this version.
... (truncated)
83bfb3b
4.12.23bcd290a
fix(utils/ipaddr): do not compress a single 0 group to ::
(#4971)c968177
feat(compress): add contentTypeFilter option and
`COMPRESSIBLE_CONTENT_TYPE_R...0265a54
docs(contribution): add AI Usage Policy (#4970)c84c5d2
feat(context): export the Context class publicly (#4543)82dad62
fix(serve-static): normalize all backslashes in file paths, not just the
firs...2f01b77
4.12.226bc0dff
feat: add msgpack as a compressible content type (#4957)7e0555d
fix(deno): echo negotiated WebSocket subprotocol in upgrade response (#4955)f0ed246
fix(compress): respect Accept-Encoding when encoding option is set (#4951)