chore(deps): bump @hono/node-server from 1.19.14 to 1.19.17 - #4474
chore(deps): bump @hono/node-server from 1.19.14 to 1.19.17#4474dependabot[bot] wants to merge 1 commit into
Conversation
PR SummaryLow Risk Overview The lockfile also refreshes several packages in that same MCP / Express 5 subtree— Reviewed by Cursor Bugbot for commit 047a184. Bugbot is set up for automated code reviews on this repo. Configure here. |
|
Your PR title doesn't contain a Jira issue key. Consider adding it for better traceability. Example:
Projects:
Please add a Jira issue key to your PR title. |
|
|
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit bcb2f94. Configure here.
| needle@https://codeload.github.com/clearbit/needle/tar.gz/84d28b5f2c3916db1e7eb84aeaa9d976cc40054b: | ||
| resolution: {tarball: https://codeload.github.com/clearbit/needle/tar.gz/84d28b5f2c3916db1e7eb84aeaa9d976cc40054b} | ||
| needle@git+https://git@github.com:clearbit/needle.git#84d28b5f2c3916db1e7eb84aeaa9d976cc40054b: | ||
| resolution: {commit: 84d28b5f2c3916db1e7eb84aeaa9d976cc40054b, repo: git@github.com:clearbit/needle.git, type: git} |
There was a problem hiding this comment.
Lockfile forces SSH for needle
High Severity
The clearbit dependency’s needle resolution changed from a public HTTPS codeload tarball to a git clone of git@github.com:clearbit/needle.git. CI runs pnpm i --frozen-lockfile without GitHub SSH keys, so installs can fail with public-key errors even though the intended change is only the @hono/node-server bump.
Additional Locations (2)
Reviewed by Cursor Bugbot for commit bcb2f94. Configure here.
Bumps [@hono/node-server](https://github.com/honojs/node-server) from 1.19.14 to 1.19.17. - [Release notes](https://github.com/honojs/node-server/releases) - [Commits](honojs/node-server@v1.19.14...v1.19.17) --- updated-dependencies: - dependency-name: "@hono/node-server" dependency-version: 1.19.17 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
bcb2f94 to
047a184
Compare


Bumps @hono/node-server from 1.19.14 to 1.19.17.
Commits
71941da1.19.170208500ci: addstageoption for publishing (#386)cbdf7131.19.1686e96c2ci: add an action for trusted publisher (#385)99c1a1aci: run on v1.x branch pushes84cb2eeMerge commit from forkMaintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for
@hono/node-serversince your current version.