Skip to content

chore(deps-dev): bump hono from 4.12.30 to 4.13.1 in /tests/e2e/mcp/vulnerable-server - #239

Merged
jithin23-kv merged 1 commit into
masterfrom
dependabot/npm_and_yarn/tests/e2e/mcp/vulnerable-server/hono-4.13.1
Aug 12, 2026
Merged

jithin23-kv merged 1 commit into
masterfrom
dependabot/npm_and_yarn/tests/e2e/mcp/vulnerable-server/hono-4.13.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 9, 2026 •

Copy link
Copy Markdown
Contributor

Bumps hono from 4.12.30 to 4.13.1.

Release notes

Sourced from hono's releases.

v4.13.1

What's Changed

New Contributors

Full Changelog: honojs/hono@v4.13.0...v4.13.1

v4.13.0

Hono v4.13.0 is now available!

The highlight of this release is performance: a batch of low-level optimizations makes the core request/response path significantly faster — up to 1.25x on common routes in our benchmark. This release also adds first-class support for the HTTP QUERY method, defined in RFC 10008, a new Method Not Allowed middleware, and more.

Performance improvements

This release includes a series of small optimizations: skipping unnecessary Headers allocations, replacing regex tests with indexOf, allocating internal state lazily, and more.

Here is benchmarks/fetch comparing v4.12 and v4.13 (ROUNDS=5 ./compare.sh, Bun 1.4.0, Apple Silicon — each measurement runs in a fresh process, and the variant order is reversed every round to avoid warm-up bias):

Benchmark v4.12 v4.13 Speedup
ping — GET / 165.83 ns 163.99 ns 1.01x
query — GET /id/1?name=bun 674.40 ns 616.99 ns 1.09x
json — GET /user 528.99 ns 422.44 ns 1.25x
body — POST /json 1.16 µs 1.00 µs 1.15x

The individual changes:

In addition, the RegExpRouter rewrite described below makes route registration plus the first match roughly 20% faster.

Thanks @​kibertoad for the contributions!

First-class QUERY method support

The QUERY method — a safe, idempotent method that carries a request body — is now a first-class citizen in Hono. You can define QUERY handlers with app.query():

const app = new Hono()
</tr></table>

... (truncated)

Commits
  • cf78528 4.13.1
  • f6aa913 fix(etag): skip unsafe methods or error responses on non-* case (#5196)
  • cd31bc1 fix(utils/stream): re-acquire writer lock when pipe() throws (#4988)
  • 569b419 fix(trie-router): count every slash a pattern consumes (#5189)
  • 192768f 4.13.0
  • b0c2d90 Merge pull request #5154 from honojs/next
  • 8f07028 fix(compress): set Vary: Accept-Encoding on negotiated responses (#5137)
  • 8a0b18f feat(reg-exp-router): throw UnsupportedPathError during route registration (#...
  • 3feb355 fix(jsx): allow a function component to return an array (#5179)
  • 5d911d2 feat(utils/headers): add HTTP fields newly registered with IANA (#5153)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 9, 2026
Bumps [hono](https://github.com/honojs/hono) from 4.12.30 to 4.13.1.
- [Release notes](https://github.com/honojs/hono/releases)
- [Commits](honojs/hono@v4.12.30...v4.13.1)

---
updated-dependencies:
- dependency-name: hono
  dependency-version: 4.13.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/tests/e2e/mcp/vulnerable-server/hono-4.13.1 branch from b6c6363 to 0317183 Compare August 10, 2026 05:50
@jithin23-kv
jithin23-kv merged commit 39354ca into master Aug 12, 2026
6 of 7 checks passed
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/tests/e2e/mcp/vulnerable-server/hono-4.13.1 branch August 12, 2026 12:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant