Skip to content

chore(deps): bump @hono/node-server and @angular/cli - #1685

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/multi-cbb1d4f0ae
Open

chore(deps): bump @hono/node-server and @angular/cli#1685
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/multi-cbb1d4f0ae

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 12, 2026

Copy link
Copy Markdown
Contributor

Bumps @hono/node-server to 2.1.1 and updates ancestor dependency @angular/cli. These dependencies need to be updated together.

Updates @hono/node-server from 1.19.11 to 2.1.1

Release notes

Sourced from @​hono/node-server's releases.

v2.1.1

What's Changed

Full Changelog: honojs/node-server@v2.1.0...v2.1.1

v2.1.0

What's Changed

New Contributors

Full Changelog: honojs/node-server@v2.0.12...v2.1.0

v2.0.12

What's Changed

Full Changelog: honojs/node-server@v2.0.11...v2.0.12

v2.0.11

What's Changed

Full Changelog: honojs/node-server@v2.0.10...v2.0.11

v2.0.10

Security fixes

This release includes a fix for the following security issue:

Unauthenticated memory-leak DoS via aborted WebSocket handshake

Affects: upgradeWebSocket. A WebSocket upgrade request with a missing or malformed Sec-WebSocket-Key header leaked the request's IncomingMessage and left a promise pending, even though no connection was established. Since the route is reachable pre-handshake without authentication, an attacker could flood it to gradually exhaust memory. GHSA-9mqv-5hh9-4cgg


Users of upgradeWebSocket are encouraged to upgrade to this version.

v2.0.9

What's Changed

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​hono/node-server since your current version.


Updates @angular/cli from 20.3.19 to 20.3.35

Release notes

Sourced from @​angular/cli's releases.

20.3.35

@​angular-devkit/build-angular

Commit Description
fix - 94b620acd7 update webpack-dev-server to 5.2.6

20.3.34

@​angular/cli

Commit Description
fix - 3962517b9 update dependency @​modelcontextprotocol/sdk to v1.30.0

@​angular-devkit/build-angular

Commit Description
fix - f348efe8b bump undici to 7.29.0

20.3.33

@​angular-devkit/build-angular

Commit Description
fix - 0b4008f17d upgrade postcss to 8.5.23

@​angular/build

Commit Description
fix - fc861affcd upgrade postcss to 8.5.23

20.3.32

@​angular-devkit/build-angular

Commit Description
fix - d4e07cb3e update http-proxy-middleware to 3.0.7

20.3.31

@​angular-devkit/build-angular

Commit Description
fix - 4ea787cd0 bump undici to 7.28.0

@​angular/build

Commit Description
fix - df5a2cc2b bump vite to 7.3.6

20.3.30

@​angular/build

Commit Description
fix - 36adca99c bump @​babel/core to 7.29.7
fix - 7f236cfea bump esbuild to 0.28.1
fix - 94fb3c122 bump piscina to 5.2.0
fix - 1f283a41c bump vite to 7.3.5

... (truncated)

Changelog

Sourced from @​angular/cli's changelog.

20.3.35 (2026-08-26)

@​angular-devkit/build-angular

Commit Type Description
94b620acd7 fix update webpack-dev-server to 5.2.6

22.2.0-next.4 (2026-08-19)

@​angular/cli

Commit Type Description
34e1e0bb5 fix enforce MCP roots in get_best_practices tool
2b060630c fix handle errors from isAllowedWorkspacePath in best-practices tool
24fd8fce2 fix throw on out-of-roots workspace in best-practices tool

@​schematics/angular

Commit Type Description
ce1b60f89 fix transform fail() to expect.fail() in refactor-jasmine-vitest

@​angular/build

Commit Type Description
175273931 feat Support splitting browser and server stats jsonfiles for easier consumption
1ee0beca7 fix correct misleading error message for top-level await
0ffe2d27f fix disable code splitting for unit test builds
50994d76e fix preserve integrity and crossorigin in autoCsp loader
d6fd24320 perf traverse AST with iterative post-order walker in i18n inliner

22.1.5 (2026-08-19)

@​angular/cli

Commit Type Description
e672271f8 fix enforce MCP roots in get_best_practices tool
a14916cc4 fix handle errors from isAllowedWorkspacePath in best-practices tool

... (truncated)

Commits
  • c17729f release: cut the v20.3.35 release
  • 94b620a fix(@​angular-devkit/build-angular): update webpack-dev-server to 5.2.6
  • 40c30ba release: cut the v20.3.34 release
  • f348efe fix(@​angular-devkit/build-angular): bump undici to 7.29.0
  • 3962517 fix(@​angular/cli): update dependency @​modelcontextprotocol/sdk to v1.30.0
  • 1bd120b release: cut the v20.3.33 release
  • 0b4008f fix(@​angular-devkit/build-angular): upgrade postcss to 8.5.23
  • fc861af fix(@​angular/build): upgrade postcss to 8.5.23
  • ed8f6ff release: cut the v20.3.32 release
  • d4e07cb fix(@​angular-devkit/build-angular): update http-proxy-middleware to 3.0.7
  • Additional commits viewable in compare view

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 12, 2026
@coveralls

coveralls commented Aug 12, 2026

Copy link
Copy Markdown

Coverage Status

coverage: 86.02%. remained the same — dependabot/npm_and_yarn/multi-cbb1d4f0ae into main

Bumps [@hono/node-server](https://github.com/honojs/node-server) to 2.1.1 and updates ancestor dependency [@angular/cli](https://github.com/angular/angular-cli). These dependencies need to be updated together.


Updates `@hono/node-server` from 1.19.11 to 2.1.1
- [Release notes](https://github.com/honojs/node-server/releases)
- [Commits](honojs/node-server@v1.19.11...v2.1.1)

Updates `@angular/cli` from 20.3.19 to 20.3.35
- [Release notes](https://github.com/angular/angular-cli/releases)
- [Changelog](https://github.com/angular/angular-cli/blob/main/CHANGELOG.md)
- [Commits](angular/angular-cli@v20.3.19...v20.3.35)

---
updated-dependencies:
- dependency-name: "@angular/cli"
  dependency-version: 20.3.34
  dependency-type: direct:development
- dependency-name: "@hono/node-server"
  dependency-version: 2.1.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/multi-cbb1d4f0ae branch from 853e8bf to 25c6a4d Compare August 26, 2026 10:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant