chore(deps): bump the npm_and_yarn group across 2 directories with 3 updates - #703
chore(deps): bump the npm_and_yarn group across 2 directories with 3 updates#703dependabot[bot] wants to merge 1 commit into
Conversation
…updates Bumps the npm_and_yarn group with 3 updates in the / directory: [@hono/node-server](https://github.com/honojs/node-server), [adm-zip](https://github.com/cthackers/adm-zip) and [sigstore](https://github.com/sigstore/sigstore-js). Bumps the npm_and_yarn group with 1 update in the /e2e/hono directory: [@hono/node-server](https://github.com/honojs/node-server). Updates `@hono/node-server` from 1.19.14 to 2.0.10 - [Release notes](https://github.com/honojs/node-server/releases) - [Commits](honojs/node-server@v1.19.14...v2.0.10) Updates `adm-zip` from 0.5.10 to 0.5.18 - [Release notes](https://github.com/cthackers/adm-zip/releases) - [Changelog](https://github.com/cthackers/adm-zip/blob/master/history.md) - [Commits](cthackers/adm-zip@v0.5.10...v0.5.18) Updates `sigstore` from 3.0.0 to 3.1.0 - [Release notes](https://github.com/sigstore/sigstore-js/releases) - [Commits](https://github.com/sigstore/sigstore-js/compare/sigstore@3.0.0...sigstore@3.1.0) Updates `@hono/node-server` from 1.19.14 to 2.0.10 - [Release notes](https://github.com/honojs/node-server/releases) - [Commits](honojs/node-server@v1.19.14...v2.0.10) Updates `@hono/node-server` from 1.19.17 to 2.0.12 - [Release notes](https://github.com/honojs/node-server/releases) - [Commits](honojs/node-server@v1.19.14...v2.0.10) --- updated-dependencies: - dependency-name: "@hono/node-server" dependency-version: 2.0.10 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: adm-zip dependency-version: 0.5.18 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: sigstore dependency-version: 3.1.0 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: "@hono/node-server" dependency-version: 2.0.10 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: "@hono/node-server" dependency-version: 2.0.12 dependency-type: direct:production dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 0835f8f. Configure here.
| "author": "", | ||
| "peerDependencies": { | ||
| "next": ">=14.2.25", | ||
| "next": ">=16.2.12", |
There was a problem hiding this comment.
Next peer deps drop prior majors
High Severity
This Dependabot bump raises published next peer ranges to require Next.js 16 only (>=16.2.12 / ^16.2.12), dropping Next 15 support that the packages previously declared. No SDK source changes justify that floor, and Next 15.5.21 remains a patched Maintenance LTS line, so consumers on 15.x would hit peer-dependency failures on install.
Additional Locations (2)
Reviewed by Cursor Bugbot for commit 0835f8f. Configure here.


Bumps the npm_and_yarn group with 3 updates in the / directory: @hono/node-server, adm-zip and sigstore.
Bumps the npm_and_yarn group with 1 update in the /e2e/hono directory: @hono/node-server.
Updates
@hono/node-serverfrom 1.19.14 to 2.0.10Release notes
Sourced from @hono/node-server's releases.
... (truncated)
Commits
7c1457e2.0.103a21938Merge commit from fork98420212.0.951f3bf5fix: recover complete request bodies after client disconnect (#375)fdb87bafix(serve-static): correct Range header parsing edge cases (#372)912e3fdfix(websocket): polyfill missing ErrorEvent global (#371)114c15e2.0.85db2d5dci(release): add--no-git-checksoption forpnpm stage publish(#369)a528a772.0.7b2d610cchore: bumpsupertest(#368)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for
@hono/node-serversince your current version.Updates
adm-zipfrom 0.5.10 to 0.5.18Release notes
Sourced from adm-zip's releases.
... (truncated)
Commits
8592b15Incremented version4c61451Merge pull request #563 from JohnJunior/fix/empty-dir-versionafd618eFixed jsdocs7d41d71Fixed sanitize bugedd43edUpdate author and bug report email in package.json83ac9f3Add security section to README692ae21Enhance security policy with vulnerability reporting details46279d7Merge pull request #562 from mielverkerken/masterb091814Merge pull request #551 from matt-fidd/webpack-crashe5b2dd8Merge pull request #564 from JohnJunior/fix/issue-555-data-descriptorUpdates
sigstorefrom 3.0.0 to 3.1.0Release notes
Sourced from sigstore's releases.
Commits
06cd267Version Packages (#1361)a045bb6bump express from 4.21.1. to 4.21.2 (#1367)74cc6c5Bump@sigstore/protobuf-specsfrom 0.3.2 to 0.4.0 (#1365)58777afBump the dev-deps group with 3 updates (#1364)1ddcf9bBump github/codeql-action from 3.28.5 to 3.28.8 in the minor-patch group (#1366)c9abfaaUpdate TUF seed files (#1356)26d40e2Bump the dev-deps group with 5 updates (#1359)71d3b4fBump the minor-patch group with 3 updates (#1357)c36ace7Bump the dev-deps group with 2 updates (#1354)3d15de3Bump the dev-deps group across 1 directory with 6 updates (#1352)Updates
@hono/node-serverfrom 1.19.14 to 2.0.10Release notes
Sourced from @hono/node-server's releases.
... (truncated)
Commits
7c1457e2.0.103a21938Merge commit from fork98420212.0.951f3bf5fix: recover complete request bodies after client disconnect (#375)fdb87bafix(serve-static): correct Range header parsing edge cases (#372)912e3fdfix(websocket): polyfill missing ErrorEvent global (#371)114c15e2.0.85db2d5dci(release): add--no-git-checksoption forpnpm stage publish(#369)a528a772.0.7b2d610cchore: bumpsupertest(#368)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for
@hono/node-serversince your current version.Updates
@hono/node-serverfrom 1.19.17 to 2.0.12Release notes
Sourced from @hono/node-server's releases.
... (truncated)
Commits
7c1457e2.0.103a21938Merge commit from fork98420212.0.951f3bf5fix: recover complete request bodies after client disconnect (#375)fdb87bafix(serve-static): correct Range header parsing edge cases (#372)912e3fdfix(websocket): polyfill missing ErrorEvent global (#371)114c15e2.0.85db2d5dci(release): add--no-git-checksoption forpnpm stage publish(#369)a528a772.0.7b2d610cchore: bumpsupertest(#368)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for
@hono/node-serversince your current version.Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.
Note
Medium Risk
Next 16 and @hono/node-server 2 are major upgrades that can break builds or runtime for SDK consumers and e2e apps; lockfile-only transitive bumps are lower risk but still warrant CI/e2e validation.
Overview
This PR refreshes dependency versions across e2e apps, published Next/Hono SDKs, and the root lockfile—no runtime or SDK source changes.
Next.js 16.2.12 replaces 15.5.x in
e2e/nextjs,e2e/nextjs-ld,@highlight-run/next, and@launchdarkly/observability-next, including raising peer requirements to^16.2.12/>=16.2.12. That is a major framework bump for consumers of those packages.The Hono e2e example moves
@hono/node-serverfrom 1.x to ^2.0.12 (major), with relatedhonopatch bumps in the lockfile/SDK dev deps. The example only usesservefrom that adapter.Root
fast-uriresolution is bumped to ^3.1.5;yarn.lockalso picks up updates such as adm-zip, sigstore (and@sigstore/*), and js-yaml 3.x.Reviewed by Cursor Bugbot for commit 0835f8f. Bugbot is set up for automated code reviews on this repo. Configure here.