chore(deps): override hono to ^4.12.25 (CVE fixes)#1708
Conversation
27e6341 to
933053e
Compare
|
Claude finished @cliffhall's task in 1m 30s —— View job Review: hono override →
|
933053e to
45fd6d9
Compare
Summary
honois a transitive runtime dependency pulled in via@modelcontextprotocol/sdk(and@hono/node-server), previously resolving tohono@4.12.23. Five Dependabot security advisories affecting hono are patched inhono >= 4.12.25.This PR adds an
overridesentry pinninghonoto^4.12.25, so the entire dependency tree resolves to a patched version. Afternpm install,npm ls hono --allshows all hono at4.12.30(>= 4.12.25).The only source change is the
overridesblock in the rootpackage.json(the existingget-intrinsicoverride is preserved);package-lock.jsonis refreshed accordingly. No inspector version numbers were changed.Verification
npx prettier --check .— passnpm run check-version— passclientlint — passclienttests — 535 passedclitests — 85 passednpm run build(server + client + cli) — passResolves Dependabot alerts 126, 128, 127, 125, 124
Part of #1706
🤖 Generated with Claude Code
https://claude.ai/code/session_01HiccCEh9mwCfVzE8qYcop1