Last 12 weeks · 168 commits
5 of 6 standards met
Features we aim to implement for the next major version v5. This list will be updated. [x] Migration bun to pnpm as a package manager https://github.com/honojs/hono/pull/5433 [ ] ESM only https://github.com/honojs/hono/issues/5105 https://github.com/honojs/hono/issues/3284 [ ] Splitting adapters to separate packages https://github.com/honojs/hono/issues/4949 [x] Adopting tsdown [ ] returns #3426 [ ] Consider https://github.com/honojs/hono/issues/667 ~~[ ] Response validation https://github.com/honojs/hono/issues/2439~~ (not now) [ ] #5155 [ ] #5221 [ ] to from https://github.com/orgs/honojs/discussions/4979 [ ] https://github.com/honojs/hono/pull/5229 [ ] Obsolete [ ] https://github.com/honojs/hono/issues/2343 [ ] Remove from (not used) [ ] Release the next version of Hono CLI [ ] Renew the website [ ] Add AGENTS.md to the starters [ ] Ant adapter https://github.com/honojs/hono/pull/5393 [x] Move to oxfmt https://github.com/honojs/hono/pull/5435 [x] ~~Move to oxlint~~ [x] Move to Vite+ https://github.com/honojs/hono/pull/5444 [x] Move to Vitest v5 https://github.com/honojs/hono/pull/5437
Since the etag middleware compares header name converted to lower case, it did not match mixed-case header names specified in option, thus they were never retained. Fixed by converting all header names in the option to lowercase beforehand. The author should do the following, if applicable [x] Add tests [x] Run tests [x] to format and lint the code [ ] Add TSDoc/JSDoc to document the code
The author should do the following, if applicable [x] Add tests [x] Run tests [ ] to format and lint the code [ ] Add TSDoc/JSDoc to document the code Description In , when constructing metric strings for the header, metric descriptions ( or ) were interpolated directly into the attribute without escaping inner double quotes or backslashes: If a caller provides a description containing double quotes (e.g., or ), unescaped quotes produce invalid HTTP header syntax: According to W3C Server Timing Section 2.1 and RFC 9110 Section 5.6.4 (Quoted Strings): The attribute is serialized as a (). Any internal double quote () or backslash () must be escaped using a backslash (, ). Unescaped inner quotes terminate the quoted-string early, causing HTTP header parsers (including browser DevTools in Chrome/Firefox and HTTP proxies) to fail parsing or drop the metric. This change escapes backslashes and double quotes with , bringing metric serialization into full compliance with RFC 9110 / W3C specifications and matching the quote-escaping behavior in Hono's and middlewares. Test Plan Added unit tests in verifying: Double quotes in numeric metric descriptions are escaped (). Double quotes in value-less metric descriptions are escaped (). Backslashes in descriptions are escaped (). Double quotes in custom are escaped (). All 20 tests pass cleanly (). TypeScript typecheck passes with 0 errors (). _Disclosure: Implemented with AI assistance under human review._
Summary trusted whenever the header was present, but / produce /negatives, and is always — so a request with skipped body measurement entirely and an arbitrarily large payload passed the limit. Malformed (non-finite or negative) now falls through to measuring the actual body, so the limit is enforced on real bytes. Once the limit is exceeded the body reader is cancelled instead of pulling the rest of an oversized body off the wire. Reproduction (before this change returns ): Test plan [x] and with oversized body → [x] Malformed with under-limit body → [x] Oversized stream asserts is called exactly once [x] — 15 tests pass Generated with Devin
Summary locates the end marker with — the first empty capture. A parameter whose pattern can match the empty string (e.g. ) also captures , so a request like against picked the param's capture instead of the marker. The resulting was not an array, returned , and a escaped entirely — outside the error handler, dropping the request/connection. RegExpRouter is part of the default SmartRouter, so default apps are affected. The marker is now found by scanning backwards for the last capture that maps to a handler-data entry. Reproduction (before this change, throws): Test plan [x] matches with stashed as [x] still matches with stashed as [x] — 217 tests pass Generated with Devin
Summary added a marker to but removed it only on the success path. When rejected, the marker leaked and — for a queued task — the caller's promise never settled at all: existed but was never wired up. After failures the pool permanently deadlocked: every later queued a retry that re-queued forever, and callers ed promises that could never resolve. is public () and is used by , so a single page-render failure during static generation hangs the whole build. The slot is now released in (still honoring ). A queued caller's promise rejects with the task's error instead of hanging; the internal retry's own copy of the rejection is consumed so it doesn't surface as an unhandled rejection. Reproduction (the second hangs forever before this change): Test plan [x] Slot released after rejection → subsequent resolves [x] Queued task's promise rejects (does not hang) once a slot frees [x] No unhandled rejection for a failing queued task [x] Slot release with set [x] — 10 tests pass Generated with Devin
Repository: honojs/hono. Description: Web framework built on Web Standards Stars: 32379, Forks: 1353. Primary language: TypeScript. Languages: TypeScript (99.9%), JavaScript (0.1%), Shell (0%), HTML (0%). License: MIT. Homepage: https://hono.dev Topics: aws-lambda, bun, cloudflare, cloudflare-workers, deno, npm, router, typescript, web-framework. Latest release: @hono/netlify@1.0.1 (21h ago). Open PRs: 100, open issues: 316. Last activity: 21h ago. Community health: 75%. Top contributors: yusukebe, usualoma, EdamAme-x, watany-dev, ryuapp, nakasyou, metrue, exoego, sor4chi, yasuaki640 and others.