GitShow/honojs/hono
honojs

hono

Web framework built on Web Standards

by honojs
aws-lambdabuncloudflarecloudflare-workersdenonpmroutertypescript
Star on GitHubForkWebsitenpm

TypeScript

32.4k stars1.4k forks369 contributorsActive · 21h agoSince 2021@hono/netlify@1.0.1MIT

Meet the team

See all 369 on GitHub →
yusukebe
yusukebe1.7k contributions
usualoma
usualoma244 contributions
EdamAme-x
EdamAme-x71 contributions
watany-dev
watany-dev53 contributions
ryuapp
ryuapp31 contributions
nakasyou
nakasyou27 contributions
metrue
metrue24 contributions
exoego
exoego21 contributions

Languages

View on GitHub →
TypeScript99.9%
JavaScript0.1%
Shell0%
HTML0%

Commit activity

Last 12 weeks · 168 commits

Full graph →

Community health

5 of 6 standards met

Community profile →
75
✓README✓License✓Contributing✓Code of Conduct○Issue Template✓PR Template

Recent PRs & issues

Active · Last activity 21h ago
See all on GitHub →
yusukebe
v5 features listOpenIssue

Features we aim to implement for the next major version v5. This list will be updated. [x] Migration bun to pnpm as a package manager https://github.com/honojs/hono/pull/5433 [ ] ESM only https://github.com/honojs/hono/issues/5105 https://github.com/honojs/hono/issues/3284 [ ] Splitting adapters to separate packages https://github.com/honojs/hono/issues/4949 [x] Adopting tsdown [ ] returns #3426 [ ] Consider https://github.com/honojs/hono/issues/667 ~~[ ] Response validation https://github.com/honojs/hono/issues/2439~~ (not now) [ ] #5155 [ ] #5221 [ ] to from https://github.com/orgs/honojs/discussions/4979 [ ] https://github.com/honojs/hono/pull/5229 [ ] Obsolete [ ] https://github.com/honojs/hono/issues/2343 [ ] Remove from (not used) [ ] Release the next version of Hono CLI [ ] Renew the website [ ] Add AGENTS.md to the starters [ ] Ant adapter https://github.com/honojs/hono/pull/5393 [x] Move to oxfmt https://github.com/honojs/hono/pull/5435 [x] ~~Move to oxlint~~ [x] Move to Vite+ https://github.com/honojs/hono/pull/5444 [x] Move to Vitest v5 https://github.com/honojs/hono/pull/5437

yusukebe · 1h ago
na-trium-144
fix(etag): correctly match mixed-case header name in retainedHeader optionOpenPR

Since the etag middleware compares header name converted to lower case, it did not match mixed-case header names specified in option, thus they were never retained. Fixed by converting all header names in the option to lowercase beforehand. The author should do the following, if applicable [x] Add tests [x] Run tests [x] to format and lint the code [ ] Add TSDoc/JSDoc to document the code

na-trium-144 · 2h ago
MustafaKemal0146
fix(timing): escape double quotes and backslashes in Server-Timing descriptionsOpenPR

The author should do the following, if applicable [x] Add tests [x] Run tests [ ] to format and lint the code [ ] Add TSDoc/JSDoc to document the code Description In , when constructing metric strings for the header, metric descriptions ( or ) were interpolated directly into the attribute without escaping inner double quotes or backslashes: If a caller provides a description containing double quotes (e.g., or ), unescaped quotes produce invalid HTTP header syntax: According to W3C Server Timing Section 2.1 and RFC 9110 Section 5.6.4 (Quoted Strings): The attribute is serialized as a (). Any internal double quote () or backslash () must be escaped using a backslash (, ). Unescaped inner quotes terminate the quoted-string early, causing HTTP header parsers (including browser DevTools in Chrome/Firefox and HTTP proxies) to fail parsing or drop the metric. This change escapes backslashes and double quotes with , bringing metric serialization into full compliance with RFC 9110 / W3C specifications and matching the quote-escaping behavior in Hono's and middlewares. Test Plan Added unit tests in verifying: Double quotes in numeric metric descriptions are escaped (). Double quotes in value-less metric descriptions are escaped (). Backslashes in descriptions are escaped (). Double quotes in custom are escaped (). All 20 tests pass cleanly (). TypeScript typecheck passes with 0 errors (). _Disclosure: Implemented with AI assistance under human review._

MustafaKemal0146 · 9h ago

Recent fixes

View closed PRs →
ndycode
fix(middleware/body-limit): reject malformed Content-Length, cancel oversized bodiesMergedPR

Summary trusted whenever the header was present, but / produce /negatives, and is always — so a request with skipped body measurement entirely and an arbitrarily large payload passed the limit. Malformed (non-finite or negative) now falls through to measuring the actual body, so the limit is enforced on real bytes. Once the limit is exceeded the body reader is cancelled instead of pulling the rest of an oversized body off the wire. Reproduction (before this change returns ): Test plan [x] and with oversized body → [x] Malformed with under-limit body → [x] Oversized stream asserts is called exactly once [x] — 15 tests pass Generated with Devin

ndycode · 7h ago
ndycode
fix(router/reg-exp): do not crash matching empty-capable param patternsMergedPR

Summary locates the end marker with — the first empty capture. A parameter whose pattern can match the empty string (e.g. ) also captures , so a request like against picked the param's capture instead of the marker. The resulting was not an array, returned , and a escaped entirely — outside the error handler, dropping the request/connection. RegExpRouter is part of the default SmartRouter, so default apps are affected. The marker is now found by scanning backwards for the last capture that maps to a handler-data entry. Reproduction (before this change, throws): Test plan [x] matches with stashed as [x] still matches with stashed as [x] — 217 tests pass Generated with Devin

ndycode · 7h ago
ndycode
fix(utils/createPool): release the slot and propagate rejections on failureMergedPR

Summary added a marker to but removed it only on the success path. When rejected, the marker leaked and — for a queued task — the caller's promise never settled at all: existed but was never wired up. After failures the pool permanently deadlocked: every later queued a retry that re-queued forever, and callers ed promises that could never resolve. is public () and is used by , so a single page-render failure during static generation hangs the whole build. The slot is now released in (still honoring ). A queued caller's promise rejects with the task's error instead of hanging; the internal retry's own copy of the rejection is consumed so it doesn't surface as an unhandled rejection. Reproduction (the second hangs forever before this change): Test plan [x] Slot released after rejection → subsequent resolves [x] Queued task's promise rejects (does not hang) once a slot frees [x] No unhandled rejection for a failing queued task [x] Slot release with set [x] — 10 tests pass Generated with Devin

ndycode · 7h ago
Structured data for AI agents

Repository: honojs/hono. Description: Web framework built on Web Standards Stars: 32379, Forks: 1353. Primary language: TypeScript. Languages: TypeScript (99.9%), JavaScript (0.1%), Shell (0%), HTML (0%). License: MIT. Homepage: https://hono.dev Topics: aws-lambda, bun, cloudflare, cloudflare-workers, deno, npm, router, typescript, web-framework. Latest release: @hono/netlify@1.0.1 (21h ago). Open PRs: 100, open issues: 316. Last activity: 21h ago. Community health: 75%. Top contributors: yusukebe, usualoma, EdamAme-x, watany-dev, ryuapp, nakasyou, metrue, exoego, sor4chi, yasuaki640 and others.

·@ofershap

Replace github.com with gitshow.dev