Skip to content

chore(deps-dev): bump @hono/node-server from 1.19.9 to 2.1.0 in /samples/llm-council/frontend - #170

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/samples/llm-council/frontend/hono/node-server-2.1.0
Open

chore(deps-dev): bump @hono/node-server from 1.19.9 to 2.1.0 in /samples/llm-council/frontend#170
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/samples/llm-council/frontend/hono/node-server-2.1.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 12, 2026

Copy link
Copy Markdown
Contributor

Bumps @hono/node-server from 1.19.9 to 2.1.0.

Release notes

Sourced from @​hono/node-server's releases.

v2.1.0

What's Changed

New Contributors

Full Changelog: honojs/node-server@v2.0.12...v2.1.0

v2.0.12

What's Changed

Full Changelog: honojs/node-server@v2.0.11...v2.0.12

v2.0.11

What's Changed

Full Changelog: honojs/node-server@v2.0.10...v2.0.11

v2.0.10

Security fixes

This release includes a fix for the following security issue:

Unauthenticated memory-leak DoS via aborted WebSocket handshake

Affects: upgradeWebSocket. A WebSocket upgrade request with a missing or malformed Sec-WebSocket-Key header leaked the request's IncomingMessage and left a promise pending, even though no connection was established. Since the route is reachable pre-handshake without authentication, an attacker could flood it to gradually exhaust memory. GHSA-9mqv-5hh9-4cgg


Users of upgradeWebSocket are encouraged to upgrade to this version.

v2.0.9

What's Changed

New Contributors

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​hono/node-server since your current version.


@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 12, 2026
@github-actions

github-actions Bot commented Aug 12, 2026

Copy link
Copy Markdown

Latest scan for commit: aa10d5b | Updated: 2026-08-12 20:10:48 UTC

Security Scan Results

Scan Metadata

  • Project: ASH
  • Scan executed: 2026-08-12T20:10:29+00:00
  • ASH version: 3.2.2

Summary

Scanner Results

The table below shows findings by scanner, with status based on severity thresholds and dependencies:

Column Explanations:

Severity Levels (S/C/H/M/L/I):

  • Suppressed (S): Security findings that have been explicitly suppressed/ignored and don't affect the scanner's pass/fail status
  • Critical (C): The most severe security vulnerabilities requiring immediate remediation (e.g., SQL injection, remote code execution)
  • High (H): Serious security vulnerabilities that should be addressed promptly (e.g., authentication bypasses, privilege escalation)
  • Medium (M): Moderate security risks that should be addressed in normal development cycles (e.g., weak encryption, input validation issues)
  • Low (L): Minor security concerns with limited impact (e.g., information disclosure, weak recommendations)
  • Info (I): Informational findings for awareness with minimal security risk (e.g., code quality suggestions, best practice recommendations)

Other Columns:

  • Time: Duration taken by each scanner to complete its analysis
  • Action: Total number of actionable findings at or above the configured severity threshold that require attention

Scanner Results:

  • PASSED: Scanner found no security issues at or above the configured severity threshold - code is clean for this scanner
  • FAILED: Scanner found security vulnerabilities at or above the threshold that require attention and remediation
  • MISSING: Scanner could not run because required dependencies/tools are not installed or available
  • SKIPPED: Scanner was intentionally disabled or excluded from this scan
  • ERROR: Scanner encountered an execution error and could not complete successfully

Severity Thresholds (Thresh Column):

  • CRITICAL: Only Critical severity findings cause scanner to fail
  • HIGH: High and Critical severity findings cause scanner to fail
  • MEDIUM (MED): Medium, High, and Critical severity findings cause scanner to fail
  • LOW: Low, Medium, High, and Critical severity findings cause scanner to fail
  • ALL: Any finding of any severity level causes scanner to fail

Threshold Source: Values in parentheses indicate where the threshold is configured:

  • (g) = global: Set in the global_settings section of ASH configuration
  • (c) = config: Set in the individual scanner configuration section
  • (s) = scanner: Default threshold built into the scanner itself

Statistics calculation:

  • All statistics are calculated from the final aggregated SARIF report
  • Suppressed findings are counted separately and do not contribute to actionable findings
  • Scanner status is determined by comparing actionable findings to the threshold
Scanner S C H M L I Time Action Result Thresh
bandit 0 0 0 0 0 0 523ms 0 PASSED MED (g)
cdk-nag 0 0 0 0 0 0 9.5s 0 PASSED MED (g)
cfn-nag 0 0 0 0 0 0 1.1s 0 PASSED MED (g)
checkov 0 0 0 0 0 0 5.0s 0 PASSED MED (g)
detect-secrets 0 0 0 0 0 0 437ms 0 PASSED MED (g)
grype 0 5 0 10 2 0 60.0s 15 FAILED MED (g)
npm-audit 0 0 0 0 0 0 209ms 0 PASSED MED (g)
opengrep 0 0 0 0 0 0 19.6s 0 PASSED MED (g)
semgrep 0 0 0 0 0 0 <1ms 0 MISSING MED (g)
syft 0 0 0 0 0 0 2.3s 0 PASSED MED (g)

Detailed Findings

Show 15 actionable findings

Finding 1: GHSA-jmr7-xgp7-cmfj-fast-xml-parser

  • Severity: HIGH
  • Scanner: grype
  • Rule ID: GHSA-jmr7-xgp7-cmfj-fast-xml-parser
  • Location: samples/llm-council/frontend/package-lock.json:1

Description:
A high vulnerability in npm package: fast-xml-parser, version 5.3.4 was found at: /samples/llm-council/frontend/package-lock.json


Finding 2: GHSA-jmr7-xgp7-cmfj-fast-xml-parser

  • Severity: HIGH
  • Scanner: grype
  • Rule ID: GHSA-jmr7-xgp7-cmfj-fast-xml-parser
  • Location: samples/llm-council/frontend/package-lock.json:1

Description:
A high vulnerability in npm package: fast-xml-parser, version 5.3.5 was found at: /samples/llm-council/frontend/package-lock.json


Finding 3: GHSA-8gc5-j5rx-235r-fast-xml-parser

  • Severity: HIGH
  • Scanner: grype
  • Rule ID: GHSA-8gc5-j5rx-235r-fast-xml-parser
  • Location: samples/llm-council/frontend/package-lock.json:1

Description:
A high vulnerability in npm package: fast-xml-parser, version 5.3.4 was found at: /samples/llm-council/frontend/package-lock.json


Finding 4: GHSA-8gc5-j5rx-235r-fast-xml-parser

  • Severity: HIGH
  • Scanner: grype
  • Rule ID: GHSA-8gc5-j5rx-235r-fast-xml-parser
  • Location: samples/llm-council/frontend/package-lock.json:1

Description:
A high vulnerability in npm package: fast-xml-parser, version 5.3.5 was found at: /samples/llm-council/frontend/package-lock.json


Finding 5: GHSA-m7jm-9gc2-mpf2-fast-xml-parser

  • Severity: HIGH
  • Scanner: grype
  • Rule ID: GHSA-m7jm-9gc2-mpf2-fast-xml-parser
  • Location: samples/llm-council/frontend/package-lock.json:1

Description:
A critical vulnerability in npm package: fast-xml-parser, version 5.3.4 was found at: /samples/llm-council/frontend/package-lock.json


Finding 6: GHSA-jp2q-39xq-3w4g-fast-xml-parser

  • Severity: MEDIUM
  • Scanner: grype
  • Rule ID: GHSA-jp2q-39xq-3w4g-fast-xml-parser
  • Location: samples/llm-council/frontend/package-lock.json:1

Description:
A medium vulnerability in npm package: fast-xml-parser, version 5.3.4 was found at: /samples/llm-council/frontend/package-lock.json


Finding 7: GHSA-jp2q-39xq-3w4g-fast-xml-parser

  • Severity: MEDIUM
  • Scanner: grype
  • Rule ID: GHSA-jp2q-39xq-3w4g-fast-xml-parser
  • Location: samples/llm-council/frontend/package-lock.json:1

Description:
A medium vulnerability in npm package: fast-xml-parser, version 5.3.5 was found at: /samples/llm-council/frontend/package-lock.json


Finding 8: GHSA-337j-9hxr-rhxg-react-router

  • Severity: MEDIUM
  • Scanner: grype
  • Rule ID: GHSA-337j-9hxr-rhxg-react-router
  • Location: samples/llm-council/frontend/package-lock.json:1

Description:
A medium vulnerability in npm package: react-router, version 6.30.3 was found at: /samples/llm-council/frontend/package-lock.json


Finding 9: GHSA-w5hq-g745-h8pq-uuid

  • Severity: MEDIUM
  • Scanner: grype
  • Rule ID: GHSA-w5hq-g745-h8pq-uuid
  • Location: samples/llm-council/frontend/package-lock.json:1

Description:
A medium vulnerability in npm package: uuid, version 11.1.0 was found at: /samples/llm-council/frontend/package-lock.json


Finding 10: GHSA-jjmj-jmhj-qwj2-react-router-dom

  • Severity: MEDIUM
  • Scanner: grype
  • Rule ID: GHSA-jjmj-jmhj-qwj2-react-router-dom
  • Location: samples/llm-council/frontend/package-lock.json:1

Description:
A medium vulnerability in npm package: react-router-dom, version 6.30.3 was found at: /samples/llm-council/frontend/package-lock.json


Finding 11: GHSA-wrjc-x8rr-h8h6-react-router

  • Severity: MEDIUM
  • Scanner: grype
  • Rule ID: GHSA-wrjc-x8rr-h8h6-react-router
  • Location: samples/llm-council/frontend/package-lock.json:1

Description:
A medium vulnerability in npm package: react-router, version 6.30.3 was found at: /samples/llm-council/frontend/package-lock.json


Finding 12: GHSA-gh4j-gqv2-49f6-fast-xml-parser

  • Severity: MEDIUM
  • Scanner: grype
  • Rule ID: GHSA-gh4j-gqv2-49f6-fast-xml-parser
  • Location: samples/llm-council/frontend/package-lock.json:1

Description:
A medium vulnerability in npm package: fast-xml-parser, version 5.3.4 was found at: /samples/llm-council/frontend/package-lock.json


Finding 13: GHSA-gh4j-gqv2-49f6-fast-xml-parser

  • Severity: MEDIUM
  • Scanner: grype
  • Rule ID: GHSA-gh4j-gqv2-49f6-fast-xml-parser
  • Location: samples/llm-council/frontend/package-lock.json:1

Description:
A medium vulnerability in npm package: fast-xml-parser, version 5.3.5 was found at: /samples/llm-council/frontend/package-lock.json


Finding 14: GHSA-2j2x-hqr9-3h42-@remix-run/router

  • Severity: MEDIUM
  • Scanner: grype
  • Rule ID: GHSA-2j2x-hqr9-3h42-@remix-run/router
  • Location: samples/llm-council/frontend/package-lock.json:1

Description:
A medium vulnerability in npm package: @remix-run/router, version 1.23.2 was found at: /samples/llm-council/frontend/package-lock.json


Finding 15: GHSA-2j2x-hqr9-3h42-react-router

  • Severity: MEDIUM
  • Scanner: grype
  • Rule ID: GHSA-2j2x-hqr9-3h42-react-router
  • Location: samples/llm-council/frontend/package-lock.json:1

Description:
A medium vulnerability in npm package: react-router, version 6.30.3 was found at: /samples/llm-council/frontend/package-lock.json


Report generated by Automated Security Helper (ASH) at 2026-08-12T20:10:24+00:00

Bumps [@hono/node-server](https://github.com/honojs/node-server) from 1.19.9 to 2.1.0.
- [Release notes](https://github.com/honojs/node-server/releases)
- [Commits](honojs/node-server@v1.19.9...v2.1.0)

---
updated-dependencies:
- dependency-name: "@hono/node-server"
  dependency-version: 2.1.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/samples/llm-council/frontend/hono/node-server-2.1.0 branch from 6a6f136 to aa10d5b Compare August 12, 2026 20:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file frontend javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants