chore(deps): bump @hono/node-server from 1.19.13 to 1.19.17 in /mcp-server - #170
Conversation
Bumps [@hono/node-server](https://github.com/honojs/node-server) from 1.19.13 to 1.19.17. - [Release notes](https://github.com/honojs/node-server/releases) - [Commits](honojs/node-server@v1.19.13...v1.19.17) --- updated-dependencies: - dependency-name: "@hono/node-server" dependency-version: 1.19.17 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
🤖 Dependabot PR Review — Automated AnalysisDependencies Changed
Changelog highlights (1.19.13 → 1.19.17):
No dependencies added or removed. Build Result✅ Passed ( Test Result✅ All tests passed (17 files, 435 tests) Execution Check✅ Starts successfully — Risk AssessmentLOW — Patch-level transitive dependency bump with bug/security fixes only. Code Changes ProposedNone Decision✅ Auto-approved and merged |
|
Update: Automated approval and merge could not be completed — the integration token lacks |
Security triage: Tier A — ready to merge, nothing outstandingWhat and why. No Vanta finding covers this — Vanta has no Exposure. Advisory impact, quoted: "Path traversal in The fix. Lockfile refresh, no manifest edit — correct mechanism here, since Breaking-change check. Same major, patch-level move across 1.19.14–1.19.17. Verification. Not run locally — this repo has no installed tree in the triage sandbox this run, and CI covers the same ground directly ( CI coverage.
Not triggered by this diff: What a human should still check. Nothing. Needs release. Unrelated to this PR, recorded so it is not lost: Generated by Claude Code |
Bumps @hono/node-server from 1.19.13 to 1.19.17.
Release notes
Sourced from @hono/node-server's releases.
Commits
71941da1.19.170208500ci: addstageoption for publishing (#386)cbdf7131.19.1686e96c2ci: add an action for trusted publisher (#385)99c1a1aci: run on v1.x branch pushes84cb2eeMerge commit from forkb5e63a31.19.14c02d777fix: add custom inspect to lightweight Request/Response to prevent TypeError ...Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for
@hono/node-serversince your current version.Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.