+ "5226cddb0d0b31d33bb78fc51230e4283cd6cc64": "chore(deps-dev): bump @hono/node-server from 2.0.4 to 2.0.10 in /libs/langchain in the npm_and_yarn group across 1 directory (#11243)\n\nBumps the npm_and_yarn group with 1 update in the /libs/langchain\ndirectory: [@hono/node-server](https://github.com/honojs/node-server).\n\nUpdates `@hono/node-server` from 2.0.4 to 2.0.10\n<details>\n<summary>Release notes</summary>\n<p><em>Sourced from <a\nhref=\"https://github.com/honojs/node-server/releases\">@\u200bhono/node-server's\nreleases</a>.</em></p>\n<blockquote>\n<h2>v2.0.10</h2>\n<h2>Security fixes</h2>\n<p>This release includes a fix for the following security issue:</p>\n<h3>Unauthenticated memory-leak DoS via aborted WebSocket handshake</h3>\n<p>Affects: <code>upgradeWebSocket</code>. A WebSocket upgrade request\nwith a missing or malformed <code>Sec-WebSocket-Key</code> header leaked\nthe request's <code>IncomingMessage</code> and left a promise pending,\neven though no connection was established. Since the route is reachable\npre-handshake without authentication, an attacker could flood it to\ngradually exhaust memory. <a\nhref=\"https://github.com/honojs/node-server/security/advisories/GHSA-9mqv-5hh9-4cgg\">GHSA-9mqv-5hh9-4cgg</a></p>\n<hr />\n<p>Users of <code>upgradeWebSocket</code> are encouraged to upgrade to\nthis version.</p>\n<h2>v2.0.9</h2>\n<h2>What's Changed</h2>\n<ul>\n<li>fix(websocket): polyfill missing ErrorEvent global by <a\nhref=\"https://github.com/otnc\"><code>@\u200botnc</code></a> in <a\nhref=\"https://redirect.github.com/honojs/node-server/pull/371\">honojs/node-server#371</a></li>\n<li>fix(serve-static): correct Range header parsing edge cases by <a\nhref=\"https://github.com/otnc\"><code>@\u200botnc</code></a> in <a\nhref=\"https://redirect.github.com/honojs/node-server/pull/372\">honojs/node-server#372</a></li>\n<li>fix: recover complete request bodies after client disconnect by <a\nhref=\"https://github.com/usualoma\"><code>@\u200busualoma</code></a> in <a\nhref=\"https://redirect.github.com/honojs/node-server/pull/375\">honojs/node-server#375</a></li>\n</ul>\n<h2>New Contributors</h2>\n<ul>\n<li><a href=\"https://github.com/otnc\"><code>@\u200botnc</code></a> made their\nfirst contribution in <a\nhref=\"https://redirect.github.com/honojs/node-server/pull/371\">honojs/node-server#371</a></li>\n</ul>\n<p><strong>Full Changelog</strong>: <a\nhref=\"https://github.com/honojs/node-server/compare/v2.0.8...v2.0.9\">https://github.com/honojs/node-server/compare/v2.0.8...v2.0.9</a></p>\n<h2>v2.0.8</h2>\n<h2>What's Changed</h2>\n<ul>\n<li>ci(release): add <code>--no-git-checks</code> option for <code>pnpm\nstage publish</code> by <a\nhref=\"https://github.com/yusukebe\"><code>@\u200byusukebe</code></a> in <a\nhref=\"https://redirect.github.com/honojs/node-server/pull/369\">honojs/node-server#369</a></li>\n</ul>\n<p><strong>Full Changelog</strong>: <a\nhref=\"https://github.com/honojs/node-server/compare/v2.0.7...v2.0.8\">https://github.com/honojs/node-server/compare/v2.0.7...v2.0.8</a></p>\n<h2>v2.0.7</h2>\n<h2>What's Changed</h2>\n<ul>\n<li>chore: migrate to pnpm by <a\nhref=\"https://github.com/BlankParticle\"><code>@\u200bBlankParticle</code></a>\nin <a\nhref=\"https://redirect.github.com/honojs/node-server/pull/367\">honojs/node-server#367</a></li>\n<li>fix(serve-static): serve precompressed files for\napplication/octet-stream by <a\nhref=\"https://github.com/yusukebe\"><code>@\u200byusukebe</code></a> in <a\nhref=\"https://redirect.github.com/honojs/node-server/pull/366\">honojs/node-server#366</a></li>\n<li>chore: bump <code>supertest</code> by <a\nhref=\"https://github.com/yusukebe\"><code>@\u200byusukebe</code></a> in <a\nhref=\"https://redirect.github.com/honojs/node-server/pull/368\">honojs/node-server#368</a></li>\n</ul>\n<p><strong>Full Changelog</strong>: <a\nhref=\"https://github.com/honojs/node-server/compare/v2.0.6...v2.0.7\">https://github.com/honojs/node-server/compare/v2.0.6...v2.0.7</a></p>\n<h2>v2.0.6</h2>\n<h2>What's Changed</h2>\n<ul>\n<li>ci: publish to npm from CI with OIDC trusted publishing and bump\n<code>np</code> by <a\nhref=\"https://github.com/yusukebe\"><code>@\u200byusukebe</code></a> in <a\nhref=\"https://redirect.github.com/honojs/node-server/pull/361\">honojs/node-server#361</a></li>\n<li>ci: use npm Staged publishing by <a\nhref=\"https://github.com/yusukebe\"><code>@\u200byusukebe</code></a> in <a\nhref=\"https://redirect.github.com/honojs/node-server/pull/364\">honojs/node-server#364</a></li>\n<li>fix: preserve status and statusText when cloning a Response with\nliveheaders by <a\nhref=\"https://github.com/usualoma\"><code>@\u200busualoma</code></a> in <a\nhref=\"https://redirect.github.com/honojs/node-server/pull/363\">honojs/node-server#363</a></li>\n</ul>\n<p><strong>Full Changelog</strong>: <a\nhref=\"https://github.com/honojs/node-server/compare/v2.0.5...v2.0.6\">https://github.com/honojs/node-server/compare/v2.0.5...v2.0.6</a></p>\n<h2>v2.0.5</h2>\n<!-- raw HTML omitted -->\n</blockquote>\n<p>... (truncated)</p>\n</details>\n<details>\n<summary>Commits</summary>\n<ul>\n<li><a\nhref=\"https://github.com/honojs/node-server/commit/7c1457ed5536c02fdd2f001129fae67bcbca54a1\"><code>7c1457e</code></a>\n2.0.10</li>\n<li><a\nhref=\"https://github.com/honojs/node-server/commit/3a21938c418340e980cb7ffa88e78369f78392d1\"><code>3a21938</code></a>\nMerge commit from fork</li>\n<li><a\nhref=\"https://github.com/honojs/node-server/commit/98420217e53a17a238ef1aa1a6bef0b2b70136c5\"><code>9842021</code></a>\n2.0.9</li>\n<li><a\nhref=\"https://github.com/honojs/node-server/commit/51f3bf56f56d9691ec0f7e1562a96f0b485a7dd9\"><code>51f3bf5</code></a>\nfix: recover complete request bodies after client disconnect (<a\nhref=\"https://redirect.github.com/honojs/node-server/issues/375\">#375</a>)</li>\n<li><a\nhref=\"https://github.com/honojs/node-server/commit/fdb87badbe313cfbfe6bb2355e9893dc0698d2bd\"><code>fdb87ba</code></a>\nfix(serve-static): correct Range header parsing edge cases (<a\nhref=\"https://redirect.github.com/honojs/node-server/issues/372\">#372</a>)</li>\n<li><a\nhref=\"https://github.com/honojs/node-server/commit/912e3fd80c4311756f724bd566de1433c8d772d9\"><code>912e3fd</code></a>\nfix(websocket): polyfill missing ErrorEvent global (<a\nhref=\"https://redirect.github.com/honojs/node-server/issues/371\">#371</a>)</li>\n<li><a\nhref=\"https://github.com/honojs/node-server/commit/114c15efb38dabaf81af774ddb764409e3d156d8\"><code>114c15e</code></a>\n2.0.8</li>\n<li><a\nhref=\"https://github.com/honojs/node-server/commit/5db2d5df662cd69ff5c4cc23b8ecb3a6f63e4e38\"><code>5db2d5d</code></a>\nci(release): add <code>--no-git-checks</code> option for <code>pnpm\nstage publish</code> (<a\nhref=\"https://redirect.github.com/honojs/node-server/issues/369\">#369</a>)</li>\n<li><a\nhref=\"https://github.com/honojs/node-server/commit/a528a77ed2c28dc12775c849abc6b6df6d4cb44c\"><code>a528a77</code></a>\n2.0.7</li>\n<li><a\nhref=\"https://github.com/honojs/node-server/commit/b2d610c1e37a96639fbb2eae662e858800aa8906\"><code>b2d610c</code></a>\nchore: bump <code>supertest</code> (<a\nhref=\"https://redirect.github.com/honojs/node-server/issues/368\">#368</a>)</li>\n<li>Additional commits viewable in <a\nhref=\"https://github.com/honojs/node-server/compare/v2.0.4...v2.0.10\">compare\nview</a></li>\n</ul>\n</details>\n<details>\n<summary>Maintainer changes</summary>\n<p>This version was pushed to npm by <a\nhref=\"https://www.npmjs.com/~GitHub%20Actions\">GitHub Actions</a>, a new\nreleaser for <code>@\u200bhono/node-server</code> since your current\nversion.</p>\n</details>\n<br />\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: John Kennedy <65985482+jkennedyvz@users.noreply.github.com>",
0 commit comments