This is a preview — how hono's changelog would look hosted on Wakelog (10 entries found). Nothing was saved. To make it real: sign up (30 seconds, no email), create a project, and paste the same URL in the Import box — you'll also get RSS, an embeddable widget, a README badge, and an API. Try another.

hono

v4.13.11

Sep 29, 2026
Security fixes
serveStatic decodes the request path a second time, leading to bypass of middleware on static paths

Affects: hono/serve-static and the adapters built on it (hono/bun, hono/deno, hono/cloudflare-workers, @hono/bun, @hono/deno, @hono/cloudflare-workers). Fixes serveStatic decoding an already-decoded path, where a crafted request could be routed as one path and served as another, skipping middleware mounted on a static prefix. GHSA-5r4p-p66f-jhc7

serveStatic now rejects request paths that still contain % after decoding. To serve files whose names contain a literal %, set allowPercentInPath: true.

The same fix ships in @hono/node-server v2.1.3.

v4.13.10

Sep 28, 2026
Adapters are now separate packages

The runtime adapters are now published as their own packages: @hono/bun, @hono/deno, @hono/cloudflare-workers, @hono/aws-lambda, @hono/lambda-edge, @hono/netlify, @hono/vercel, and @hono/service-worker. @hono/deno is also on JSR.

hono/ still works in v4 but is deprecated and will be removed in v5. Migrating is an import change:


- import { serveStatic } from 'hono/bun'
+ import { serveStatic } from '@hono/bun'

hono/cloudflare-pages is deprecated without a replacement package; Cloudflare recommends Workers with static assets.

What's Changed
  • chore: migrate the package manager from bun to pnpm in #5433
  • chore(package.json): invoke package scripts through pnpm instead of bun in #5434
  • chore: replace prettier with oxfmt in #5435
  • chore(deps): upgrade vitest to 5.0.1 in #5437
  • chore: let oxfmt sort imports instead of eslint in #5442
  • chore: replace eslint with oxlint in #5443
  • chore: introduce Vite+ in #5444
  • fix(types): allow returning a Blob as a response body in #5446
  • chore: convert build scripts into plugins in #5448
  • chore: stop editorconfig-checker from checking Markdown indent size in #5455
  • ci: remove empty step left in cr.yml by the pnpm migration in #5456
  • chore(deps): upgrade vite-plus to 1.0.0-rc.1 in #5459
  • feat(adapters): add @hono/bun as a workspace package in #5447
  • chore(adapters/bun): ship ESM only in #5462
  • feat(adapters): add the seven adapters as workspace packages in #5463
  • feat(adapters/deno): publish to JSR in #5465
  • test: move adapter runtime tests into adapters/* in #5466

Full Changelog: v4.13.9...v4.13.10

@hono/netlify@1.0.1

Sep 28, 2026

No content.

@hono/deno@1.0.2

Sep 28, 2026

No content.

@hono/deno@1.0.1

Sep 28, 2026

@hono/deno@1.0.1

v4.13.9

Sep 24, 2026
What's Changed
  • fix(jsx): replace Suspense and ErrorBoundary content across newlines in #5380
  • fix(accepts): match media types and language tags case-insensitively in #5376
  • fix(linear-router): don't match an empty path segment as a param in #5373
  • fix(pretty-json): don't break responses with unparseable JSON bodies in #5377
  • fix(jwt): throw JwtTokenInvalid when the signature is not valid base64url in #5379
  • fix(aws-lambda): treat binary +xml archive media types as binary in #5424
  • fix(aws-lambda): preserve empty query parameters in #5292
  • fix(lambda-edge): sync content type detection with aws-lambda in #5426
  • fix(lambda-edge): fail with a descriptive error on a malformed event in #5358

Full Changelog: v4.13.8...v4.13.9

v4.13.8

Sep 15, 2026
What's Changed
  • docs: fix typos in code comments and link third-party middleware section in #5343
  • perf(jsx/dom): reduce lookup work for large keyed updates in #5340
  • fix(aws-lambda): respect backpressure when streaming the response body in #5351
  • fix(accepts, language): skip accept entries with quality 0 when matching in #5311
  • fix(accept): treat the q parameter name as case-insensitive in #5349
  • fix(accept): clamp a negative q to 0, not 1 in #5357
  • fix(request): keep the request media type when reusing a cached body in #5366
  • docs(combine): fix except() JSDoc param and add missing @returns in #5346
  • perf(jsx/dom): optimize matching-head child lookup during reconciliation in #5329

Full Changelog: v4.13.7...v4.13.8

v4.13.7

Sep 4, 2026
Security fixes

This release includes a fix for the following security issue:

hono/jsx renders plain strings unescaped in boundary components, leading to XSS

Affects: Suspense, ErrorBoundary, and Context.Provider in hono/jsx, and renderToString() / renderToReadableStream() in hono/jsx/dom/server. Fixes missing HTML escaping for a plain string placed directly as a child or fallback of these components, or as the root value of the server rendering functions, so untrusted strings could be emitted as markup. GHSA-hxh3-vqpv-xpqv

Users who render untrusted strings inside Suspense, ErrorBoundary, or Context.Provider, or pass them directly to hono/jsx/dom/server, are strongly encouraged to upgrade to this version.

v4.13.6

Sep 4, 2026
What's Changed
  • fix(client): keep a param value of "index" in $url() and $path() in #5297
  • fix(client): normalize root WebSocket URLs in #5291
  • fix(types): allow symbol keys in Context get and set fallbacks in #5300
  • chore: bump editorconfig-checker in #5336
  • refactor(on-handler): use forEach for consistent handler iteration in #5326

Full Changelog: v4.13.5...v4.13.6

v4.13.5

Aug 26, 2026
Security fixes

This release includes fixes for the following security issues:

Query parser reads parameters after the URL fragment, causing cache-key and proxy interpretation differentials

Affects: Cache Middleware and applications behind a proxy, WAF, or logging layer that inspects query strings. Fixes query parsing that did not stop at the URL fragment, so a ? after a # was treated as the start of a query string and the application could read parameters that the other component never saw. GHSA-crvj-82cr-hjcx

Incomplete fix for CVE-2026-39408: toSSG() still writes files outside the output directory

Affects: toSSG() for Static Site Generation. Fixes a path normalization gap where consecutive parent-directory segments in ssgParams values were not fully collapsed, bypassing the containment check added in 4.12.12. GHSA-gqvv-2mrq-wpjv

Unbounded dot-notation nesting in parseBody() can cause memory exhaustion

Affects: parseBody() when dot-notation parsing is enabled. Fixes unbounded expansion of dot-separated field names, where a small request body could allocate a disproportionately large object graph and concurrent requests could exhaust the heap. GHSA-g6gw-c38x-mqfc

Users who use Cache Middleware, deploy behind a proxy or WAF that inspects query strings, use Static Site Generation, or use parseBody({ dot: true }) are strongly encouraged to upgrade to this version.

Claim your changelog — free