Skip to content

Update all non-major dependencies#1

Open
cnap-tech-renovate[bot] wants to merge 1 commit intomainfrom
renovate/all-minor-patch
Open

Update all non-major dependencies#1
cnap-tech-renovate[bot] wants to merge 1 commit intomainfrom
renovate/all-minor-patch

Conversation

@cnap-tech-renovate
Copy link
Contributor

@cnap-tech-renovate cnap-tech-renovate bot commented Feb 25, 2026

This PR contains the following updates:

Package Type Update Change
@modelcontextprotocol/sdk (source) devDependencies minor 1.26.01.27.1
hono (source) devDependencies patch 4.12.24.12.4
oxlint (source) devDependencies minor 1.50.01.51.0

Release Notes

modelcontextprotocol/typescript-sdk (@​modelcontextprotocol/sdk)

v1.27.1

Compare Source

What's Changed

New Contributors

Full Changelog: modelcontextprotocol/typescript-sdk@v1.27.0...v1.27.1

v1.27.0

Compare Source

What's Changed

New Contributors

Full Changelog: modelcontextprotocol/typescript-sdk@v1.26.0...v1.27.0

honojs/hono (hono)

v4.12.4

Compare Source

Security fixes

This release includes fixes for the following security issues:

SSE Control Field Injection

Affects: streamSSE() in Streaming Helper. Fixes injection of unintended SSE fields by rejecting CR/LF characters in event, id, and retry. GHSA-p6xx-57qc-3wxr

Cookie Attribute Injection in setCookie()

Affects: setCookie() from hono/cookie. Fixes cookie attribute manipulation by rejecting ;, \r, and \n in domain and path options. GHSA-5pq2-9x2x-5p6w

Middleware Bypass in Serve Static

Affects: Serve Static middleware. Fixes inconsistent URL decoding that could allow protected static resources to be accessed without triggering route-based middleware. GHSA-q5qw-h33p-qvwr

Users who uses Strreaming Helper, Cookie utility, and Serve Static are strongly encouraged to upgrade to this version.


Other changes

New Contributors

Full Changelog: honojs/hono@v4.12.3...v4.12.4

v4.12.3

Compare Source

What's Changed

New Contributors

Full Changelog: honojs/hono@v4.12.2...v4.12.3

oxc-project/oxc (oxlint)

v1.51.0

Compare Source

🚀 Features
🐛 Bug Fixes
  • 04e6223 npm: Add preferUnplugged for Yarn PnP compatibility (#​19829) (Boshen)
📚 Documentation

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@cnap-tech-renovate cnap-tech-renovate bot force-pushed the renovate/all-minor-patch branch from 8850ebc to 6787e3c Compare February 26, 2026 02:40
@cnap-tech-renovate
Copy link
Contributor Author

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

@cnap-tech-renovate cnap-tech-renovate bot changed the title Update dependency @modelcontextprotocol/sdk to v1.27.1 Update all non-major dependencies Feb 27, 2026
@cnap-tech-renovate cnap-tech-renovate bot force-pushed the renovate/all-minor-patch branch 2 times, most recently from c949d5e to e4fa944 Compare March 2, 2026 13:18
@cnap-tech-renovate cnap-tech-renovate bot force-pushed the renovate/all-minor-patch branch from e4fa944 to c19238d Compare March 3, 2026 13:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants