From 4836d43e84bfd6163d3b7bdd050e8dc6ad0dc386 Mon Sep 17 00:00:00 2001 From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com> Date: Sat, 8 Aug 2026 19:11:08 +0000 Subject: [PATCH] chore(ui): update dependency @hono/node-server to v2 [security] --- ui/pnpm-workspace.yaml | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/ui/pnpm-workspace.yaml b/ui/pnpm-workspace.yaml index cd3f7d25f2..551b8dd218 100644 --- a/ui/pnpm-workspace.yaml +++ b/ui/pnpm-workspace.yaml @@ -1,6 +1,3 @@ -# pnpm 11+ workspace config. .npmrc is auth/registry only; everything else lives here. -# Reference: https://pnpm.io/supply-chain-security - packages: [] # Refuse to install on Node/pnpm outside the `engines` block in package.json. @@ -28,7 +25,7 @@ overrides: # but not yet in the npm audit feed), fixed in 4.12.27. Not 4.12.29: it is # still inside StepSecurity's 7-day npm cooldown gate. "hono": "4.12.28" - "@hono/node-server": "1.19.14" + "@hono/node-server": "2.0.5" "@isaacs/brace-expansion": "5.0.1" "fast-xml-parser": "5.8.0" "serialize-javascript": "7.0.5" @@ -121,3 +118,6 @@ trustPolicyExclude: # Block transitive dependencies from using exotic specifiers (git URLs, tarballs). blockExoticSubdeps: true +minimumReleaseAgeExclude: + # Renovate security update: @hono/node-server@2.0.5 + - "@hono/node-server@2.0.5"