Skip to content

chore(deps): bump the bun-dependencies group with 5 updates - #36

Merged
tdtgit merged 1 commit into
mainfrom
dependabot/bun/bun-dependencies-f6effc332d
Oct 9, 2026
Merged

tdtgit merged 1 commit into
mainfrom
dependabot/bun/bun-dependencies-f6effc332d

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 6, 2026

Copy link
Copy Markdown
Contributor

Bumps the bun-dependencies group with 5 updates:

Package From To
hono 4.13.9 4.13.12
openai 7.23.0 7.27.0
postal-mime 3.0.1 4.0.2
@types/node 26.6.3 26.6.4
wrangler 4.141.0 4.147.0

Updates hono from 4.13.9 to 4.13.12

Release notes

Sourced from hono's releases.

v4.13.12

What's Changed

  • fix(build): keep internal types private in bundled d.ts and avoid a self-referencing JSX.IntrinsicElements in honojs/hono#5485
  • test(build): type-check the bundled declarations from a consumer project in honojs/hono#5486
  • fix(etag): correctly match mixed-case header name in retainedHeader option in honojs/hono#5475
  • fix(jsx): add px to numeric gridGap, gridRowGap and gridColumnGap in honojs/hono#5487
  • fix(combine): return a Response from a short-circuiting middleware in some() in honojs/hono#5391
  • chore(deps): upgrade vite-plus to 1.0.0 in honojs/hono#5464

Full Changelog: honojs/hono@v4.13.11...v4.13.12

v4.13.11

Security fixes

serveStatic decodes the request path a second time, leading to bypass of middleware on static paths

Affects: hono/serve-static and the adapters built on it (hono/bun, hono/deno, hono/cloudflare-workers, @hono/bun, @hono/deno, @hono/cloudflare-workers). Fixes serveStatic decoding an already-decoded path, where a crafted request could be routed as one path and served as another, skipping middleware mounted on a static prefix. GHSA-5r4p-p66f-jhc7

serveStatic now rejects request paths that still contain % after decoding. To serve files whose names contain a literal %, set allowPercentInPath: true.

The same fix ships in @hono/node-server v2.1.3.

v4.13.10

Adapters are now separate packages

The runtime adapters are now published as their own packages: @hono/bun, @hono/deno, @hono/cloudflare-workers, @hono/aws-lambda, @hono/lambda-edge, @hono/netlify, @hono/vercel, and @hono/service-worker. @hono/deno is also on JSR.

hono/<adapter> still works in v4 but is deprecated and will be removed in v5. Migrating is an import change:

- import { serveStatic } from 'hono/bun'
+ import { serveStatic } from '@hono/bun'

hono/cloudflare-pages is deprecated without a replacement package; Cloudflare recommends Workers with static assets.

What's Changed

... (truncated)

Commits
  • 6abd35b 4.13.12
  • 95eb860 chore(deps): upgrade vite-plus to 1.0.0 (#5464)
  • afb2068 fix(combine): return a Response from a short-circuiting middleware in some() ...
  • e5bb206 fix(jsx): add px to numeric gridGap, gridRowGap and gridColumnGap (#5487)
  • c3053cc fix(etag): correctly match mixed-case header name in retainedHeader option (#...
  • c437d75 test(build): type-check the bundled declarations from a consumer project (#5486)
  • be1f749 fix(build): keep internal types private in bundled d.ts and avoid a self-refe...
  • 37ce069 4.13.11
  • 1e1207c test(serve-static): fix the test (#5479)
  • 8b05c77 Merge commit from fork
  • Additional commits viewable in compare view

Updates openai from 7.23.0 to 7.27.0

Release notes

Sourced from openai's releases.

v7.27.0

7.27.0 (2026-10-01)

Features

  • agents: prepare hosted files and download result artifacts (#2855) (7b5a9e0)

v7.26.0

7.26.0 (2026-10-01)

Features

  • collect final output from beta Agents streams (#2850) (71d2412)
  • agents: [1/n] parse typed output from agent streams (#2853) (95b197b)
  • api: Add agent session trace listing (#2845) (c6dd4c7)
  • beta: bind typed application functions to Agents tools (#2852) (6198ba0)

Bug Fixes

  • api: allow original image detail in Chat Completions (#2851) (a3c1af5)
  • api: correct the eval run cancellation endpoint (#2847) (2f77415)
  • deps-dev: bump @​swc/core from 1.16.1 to 1.16.2 (#2827) (ff26e64)
  • deps-dev: bump puppeteer from 25.10.0 to 25.11.0 in /ecosystem-tests/browser-direct-import (#2823) (53f8877)
  • deps-dev: bump puppeteer from 25.10.0 to 25.11.0 in /ecosystem-tests/ts-browser-webpack (#2830) (2ac0cf2)
  • deps-dev: bump webpack from 5.110.3 to 5.111.1 in /ecosystem-tests/ts-browser-webpack (#2828) (89de47a)
  • deps-dev: bump wrangler from 4.131.1 to 4.135.0 in /ecosystem-tests/cloudflare-worker (#2824) (8c2e159)
  • deps-dev: update Vercel CLI to remove legacy proxy dependencies (#2835) (94395e8)
  • deps-dev: upgrade Vitest and migrate performance benchmarks (#2831) (a1421b1)
  • deps: bump @​azure/identity from 4.13.2 to 4.13.3 (#2825) (bfa2dec)
  • deps: bump dotenv from 17.4.2 to 18.0.1 (#2822) (6d0a62c)
  • deps: bump zod from 4.5.4 to 4.6.5 (#2829) (d2e9a06)
  • responses: refresh credentials on WebSocket reconnects (#2856) (0afb3da)
  • responses: reserve lane IDs across WebSocket session replacements (#2842) (8b5e176)

Chores

  • api: retain WebRTC Live session transport types (#2846) (9798c93)

v7.25.0

7.25.0 (2026-09-29)

Features

... (truncated)

Changelog

Sourced from openai's changelog.

7.27.0 (2026-10-01)

Features

  • agents: prepare hosted files and download result artifacts (#2855) (7b5a9e0)

7.26.0 (2026-10-01)

Features

  • collect final output from beta Agents streams (#2850) (71d2412)
  • agents: [1/n] parse typed output from agent streams (#2853) (95b197b)
  • api: Add agent session trace listing (#2845) (c6dd4c7)
  • beta: bind typed application functions to Agents tools (#2852) (6198ba0)

Bug Fixes

  • api: allow original image detail in Chat Completions (#2851) (a3c1af5)
  • api: correct the eval run cancellation endpoint (#2847) (2f77415)
  • deps-dev: bump @​swc/core from 1.16.1 to 1.16.2 (#2827) (ff26e64)
  • deps-dev: bump puppeteer from 25.10.0 to 25.11.0 in /ecosystem-tests/browser-direct-import (#2823) (53f8877)
  • deps-dev: bump puppeteer from 25.10.0 to 25.11.0 in /ecosystem-tests/ts-browser-webpack (#2830) (2ac0cf2)
  • deps-dev: bump webpack from 5.110.3 to 5.111.1 in /ecosystem-tests/ts-browser-webpack (#2828) (89de47a)
  • deps-dev: bump wrangler from 4.131.1 to 4.135.0 in /ecosystem-tests/cloudflare-worker (#2824) (8c2e159)
  • deps-dev: update Vercel CLI to remove legacy proxy dependencies (#2835) (94395e8)
  • deps-dev: upgrade Vitest and migrate performance benchmarks (#2831) (a1421b1)
  • deps: bump @​azure/identity from 4.13.2 to 4.13.3 (#2825) (bfa2dec)
  • deps: bump dotenv from 17.4.2 to 18.0.1 (#2822) (6d0a62c)
  • deps: bump zod from 4.5.4 to 4.6.5 (#2829) (d2e9a06)
  • responses: refresh credentials on WebSocket reconnects (#2856) (0afb3da)
  • responses: reserve lane IDs across WebSocket session replacements (#2842) (8b5e176)

Chores

  • api: retain WebRTC Live session transport types (#2846) (9798c93)

7.25.0 (2026-09-29)

Features

7.24.0 (2026-09-29)

... (truncated)

Commits
  • e39bd99 release: 7.27.0 (#2857)
  • 7b5a9e0 feat(agents): prepare hosted files and download result artifacts (#2855)
  • a06c456 release: 7.26.0 (#2844)
  • 0afb3da fix(responses): refresh credentials on WebSocket reconnects (#2856)
  • 95b197b feat(agents): [1/n] parse typed output from agent streams (#2853)
  • 6198ba0 feat(beta): bind typed application functions to Agents tools (#2852)
  • 71d2412 feat: collect final output from beta Agents streams (#2850)
  • a1421b1 fix(deps-dev): upgrade Vitest and migrate performance benchmarks (#2831)
  • a3c1af5 fix(api): allow original image detail in Chat Completions (#2851)
  • 94395e8 fix(deps-dev): update Vercel CLI to remove legacy proxy dependencies (#2835)
  • Additional commits viewable in compare view

Updates postal-mime from 3.0.1 to 4.0.2

Release notes

Sourced from postal-mime's releases.

v4.0.2

4.0.2 (2026-09-30)

Bug Fixes

  • stop a "[" from hiding the operators after it (2797ee5)

v4.0.1

4.0.1 (2026-09-30)

Bug Fixes

  • do not read an address out of a quoted encoded word (c88eaf5)
  • keep a display name holding an encoded word out of the address (ce5ba24)
  • open a domain-literal only after the '@' of an address (776b951)
  • port the address parser fixes from Nodemailer (902bd3f)

v4.0.0

4.0.0 (2026-09-26)

⚠ BREAKING CHANGES

  • Node.js 20 or newer is required.
  • Attachment.disposition is typed as AttachmentDisposition | null, which accepts any Content-Disposition token, instead of 'attachment' | 'inline' | null. The parsed output is unchanged, but code that assigns the value to the narrower type has to widen it.
  • the ES module entry point moved from src/postal-mime.js to dist/esm/postal-mime.js, so browser code that imported the file from node_modules directly has to use the new path. Consumers that import postal-mime by name are unaffected.

Features

  • convert to TypeScript and ship ES module and CommonJS builds (2559c82)
  • declare the CommonJS entry point with export = and ship source maps (84d1159)
  • type the attachment disposition as the token the message carries (4bb2796)

Bug Fixes

  • keep the public object types assignable to an index signature (3363039)

Miscellaneous Chores

  • require Node.js 20 or newer (21eaae6)
Changelog

Sourced from postal-mime's changelog.

4.0.2 (2026-09-30)

Bug Fixes

  • stop a "[" from hiding the operators after it (2797ee5)

4.0.1 (2026-09-30)

Bug Fixes

  • do not read an address out of a quoted encoded word (c88eaf5)
  • keep a display name holding an encoded word out of the address (ce5ba24)
  • open a domain-literal only after the '@' of an address (776b951)
  • port the address parser fixes from Nodemailer (902bd3f)

4.0.0 (2026-09-26)

⚠ BREAKING CHANGES

  • Node.js 20 or newer is required.
  • Attachment.disposition is typed as AttachmentDisposition | null, which accepts any Content-Disposition token, instead of 'attachment' | 'inline' | null. The parsed output is unchanged, but code that assigns the value to the narrower type has to widen it.
  • the ES module entry point moved from src/postal-mime.js to dist/esm/postal-mime.js, so browser code that imported the file from node_modules directly has to use the new path. Consumers that import postal-mime by name are unaffected.

Features

  • convert to TypeScript and ship ES module and CommonJS builds (2559c82)
  • declare the CommonJS entry point with export = and ship source maps (84d1159)
  • type the attachment disposition as the token the message carries (4bb2796)

Bug Fixes

  • keep the public object types assignable to an index signature (3363039)

Miscellaneous Chores

  • require Node.js 20 or newer (21eaae6)
Commits
  • a64b943 chore(master): release 4.0.2 (#101)
  • 2797ee5 fix: stop a "[" from hiding the operators after it
  • b9406e6 chore(master): release 4.0.1 (#100)
  • 053d18d chore: update dependencies
  • 776b951 fix: open a domain-literal only after the '@' of an address
  • c88eaf5 fix: do not read an address out of a quoted encoded word
  • ce5ba24 fix: keep a display name holding an encoded word out of the address
  • 902bd3f fix: port the address parser fixes from Nodemailer
  • 7800715 chore(master): release 4.0.0 (#99)
  • ec42302 chore: update dependencies
  • Additional commits viewable in compare view

Updates @types/node from 26.6.3 to 26.6.4

Commits

Updates wrangler from 4.141.0 to 4.147.0

Release notes

Sourced from wrangler's releases.

wrangler@4.147.0

Minor Changes

  • #15928 7f57b1c Thanks @​ichernetsky-cf! - Allow "us" as a jurisdiction for Container applications

    Container placement constraints now accept constraints.jurisdiction: "us" in Wrangler and typed Cloudflare configuration. This makes the US jurisdiction available alongside "eu" and "fedramp".

Patch Changes

  • #15974 7f700ef Thanks @​martinezjandrew! - Fix wrangler containers list to report live instances

    The LIVE INSTANCES column now reports each application's active runtime instances instead of its configured instance count, matching the Cloudflare dashboard. JSON output continues to expose the configured count through the existing instances field.

  • #15980 90e6a1b Thanks @​martinezjandrew! - Accept Durable Object application IDs in Containers commands

    wrangler containers instances and wrangler containers delete now accept the 32-character hexadecimal application IDs returned for Durable Object-backed applications, in addition to legacy dashed UUIDs.

  • #15871 6a4b0fe Thanks @​tw4! - Retry transient API failures in wrangler workflows instances list and wrangler workflows instances describe

    Previously, a single temporary 5xx response or dropped connection made these read-only commands exit with an error, even though the next request would have succeeded. They now use Wrangler's existing bounded API retry handling. The read that resolves --id latest is retried too, which also benefits the other wrangler workflows instances commands that accept latest; the mutating requests they make afterwards are not retried. Persistent failures are still reported after the retries are exhausted, and under --json any retry notices are written to stderr so stdout stays valid JSON.

  • Updated dependencies []:

wrangler@4.146.0

Minor Changes

  • #15777 464a582 Thanks @​Naapperas! - Support the new Workflows createBatch() API in local development

    Local Workflows bindings now accept object-form batches that create instances from a count or a list of instance options. The result includes handles for created instances and indexed per-instance errors, matching the runtime API while preserving the deprecated array form.

  • #15639 aee2842 Thanks @​hugo-vicente11! - Add --allowed-mail to the experimental wrangler tunnel quick-start command

    The option forwards exact email addresses, comma-separated lists, and wildcard domains to cloudflared. It can be specified more than once to combine multiple recipient rules.

    Email-protected tunnels require cloudflared 2026.9.2 or later. Wrangler checks the selected binary before starting the tunnel and reports an upgrade error when it is incompatible.

Patch Changes

  • #15992 b8e7cc3 Thanks @​zebp! - Mark wrangler artifacts commands as open beta

    Artifacts has entered open beta, so the wrangler artifacts commands no longer display a "private beta" label in help output and warnings.

  • #15984 9d7b08e Thanks @​dependabot! - Update dependencies of "miniflare", "wrangler"

    The following dependency versions have been updated:

    Dependency From To
    @​cloudflare/workers-types ^5.20260930.2 ^5.20261001.1

... (truncated)

Commits
  • 64c1337 Version Packages (#15996)
  • 6a4b0fe [wrangler] Retry transient failures in workflows instances list and describe ...
  • 7f700ef CC-8799: report active instead of configured instances in containers list (#1...
  • 90e6a1b CC-8800: accept durable object app ids in container commands (#15980)
  • b4954c1 Version Packages (#15983)
  • b8e7cc3 [wrangler] Mark Artifacts commands as open beta (#15992)
  • aee2842 [wrangler] Support email-protected Quick Tunnels (#15639)
  • efd67e6 [wrangler] Keep colons in wrangler tail --header filter values (#15959)
  • 89061a4 Version Packages (#15957)
  • 4a5ab6c Preserve existing secret bindings during Worker deployments (#15964)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the bun-dependencies group with 5 updates:

| Package | From | To |
| --- | --- | --- |
| [hono](https://github.com/honojs/hono) | `4.13.9` | `4.13.12` |
| [openai](https://github.com/openai/openai-node) | `7.23.0` | `7.27.0` |
| [postal-mime](https://github.com/postalsys/postal-mime) | `3.0.1` | `4.0.2` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.6.3` | `26.6.4` |
| [wrangler](https://github.com/cloudflare/workers-sdk/tree/HEAD/packages/wrangler) | `4.141.0` | `4.147.0` |


Updates `hono` from 4.13.9 to 4.13.12
- [Release notes](https://github.com/honojs/hono/releases)
- [Commits](honojs/hono@v4.13.9...v4.13.12)

Updates `openai` from 7.23.0 to 7.27.0
- [Release notes](https://github.com/openai/openai-node/releases)
- [Changelog](https://github.com/openai/openai-node/blob/main/CHANGELOG.md)
- [Commits](openai/openai-node@v7.23.0...v7.27.0)

Updates `postal-mime` from 3.0.1 to 4.0.2
- [Release notes](https://github.com/postalsys/postal-mime/releases)
- [Changelog](https://github.com/postalsys/postal-mime/blob/master/CHANGELOG.md)
- [Commits](postalsys/postal-mime@v3.0.1...v4.0.2)

Updates `@types/node` from 26.6.3 to 26.6.4
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `wrangler` from 4.141.0 to 4.147.0
- [Release notes](https://github.com/cloudflare/workers-sdk/releases)
- [Commits](https://github.com/cloudflare/workers-sdk/commits/wrangler@4.147.0/packages/wrangler)

---
updated-dependencies:
- dependency-name: hono
  dependency-version: 4.13.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: bun-dependencies
- dependency-name: openai
  dependency-version: 7.27.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: bun-dependencies
- dependency-name: postal-mime
  dependency-version: 4.0.2
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: bun-dependencies
- dependency-name: "@types/node"
  dependency-version: 26.6.4
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: bun-dependencies
- dependency-name: wrangler
  dependency-version: 4.147.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: bun-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 6, 2026
@cloudflare-workers-and-pages

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Preview URL Updated (UTC)
✅ Deployment successful!
View logs
mine-personal-accounting fd55b86 Commit Preview URL

Branch Preview URL
Oct 06 2026, 07:04 PM

@tdtgit
tdtgit merged commit 0aa2e98 into main Oct 9, 2026
4 checks passed
@dependabot
dependabot Bot deleted the dependabot/bun/bun-dependencies-f6effc332d branch October 9, 2026 03:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant