Three medium advisories land on hono before 4.13.5: a toSSG() path escape, a query parser that reads parameters past the URL fragment, and unbounded dot-notation nesting in parseBody(). Only the second one touches this server -- c.req.query() is read in imageproxy, icsproxy and app -- and even there safeFetch validates the value it actually fetches rather than a separate pre-check, so there was nothing to desync. toSSG and parseBody are never called. The bump is still worth taking on its own: it is a patch release with no API change. The declared range moves with it, from ^4.7.4 to ^4.13.7, so the security floor is recorded in server/package.json and not only in the lockfile. The dependabot.yml is the actual fix for how these were found. There was no config, so nothing opened a PR and the alerts sat on a dashboard until someone thought to look. Routine updates now group into one PR a week; majors stay separate, because they are migrations.
28 lines
797 B
JSON
28 lines
797 B
JSON
{
|
|
"name": "@ihasmail/server",
|
|
"version": "2.16.0",
|
|
"private": true,
|
|
"license": "AGPL-3.0-or-later",
|
|
"type": "module",
|
|
"main": "dist/index.js",
|
|
"scripts": {
|
|
"dev": "tsx watch --clear-screen=false src/index.ts",
|
|
"build": "tsc -p tsconfig.json",
|
|
"start": "node dist/index.js",
|
|
"typecheck": "tsc -p tsconfig.json --noEmit",
|
|
"test": "tsx --test src/*.test.ts src/**/*.test.ts",
|
|
"mock": "tsx src/mock/index.ts",
|
|
"mock:no-future-release": "MOCK_NO_FUTURE_RELEASE=1 tsx src/mock/index.ts",
|
|
"mock:no-keyword-sort": "MOCK_NO_KEYWORD_SORT=1 tsx src/mock/index.ts"
|
|
},
|
|
"dependencies": {
|
|
"@hono/node-server": "^1.13.8",
|
|
"hono": "^4.13.7"
|
|
},
|
|
"devDependencies": {
|
|
"@types/node": "^22.13.10",
|
|
"tsx": "^4.19.3",
|
|
"typescript": "^5.7.3"
|
|
}
|
|
}
|