[Snyk] Security upgrade hono from 4.7.6 to 4.11.7#61
Conversation
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-HONO-15123484 - https://snyk.io/vuln/SNYK-JS-HONO-15123483 - https://snyk.io/vuln/SNYK-JS-HONO-15123868 - https://snyk.io/vuln/SNYK-JS-HONO-15123927
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Deploying with
|
| Status | Name | Latest Commit | Updated (UTC) |
|---|---|---|---|
| 🔵 In progress View logs |
weather-mcp-server | ba27978 | Feb 02 2026, 11:07 AM |
Deploying with
|
| Status | Name | Latest Commit | Updated (UTC) |
|---|---|---|---|
| 🔵 In progress View logs |
brave-search-mcp-server | ba27978 | Feb 02 2026, 11:07 AM |
✅ Deploy Preview for express-mcp-server canceled.
|
Deploying with
|
| Status | Name | Latest Commit | Updated (UTC) |
|---|---|---|---|
| ✅ Deployment successful! View logs |
remote-mcp-server-bearer-auth | ba27978 | Feb 02 2026, 11:07 AM |
✅ Deploy Preview for mcp-example-oauth canceled.
|
There was a problem hiding this comment.
Pull request overview
Updates the examples/weather-mcp-server dependency on hono to remediate Snyk-reported vulnerabilities.
Changes:
- Bumped
honodependency inexamples/weather-mcp-server/package.jsonto^4.11.7.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
| "@modelcontextprotocol/sdk": "^1.7.0", | ||
| "agents": "^0.0.43", | ||
| "hono": "^4.7.4", | ||
| "hono": "^4.11.7", |
There was a problem hiding this comment.
pnpm-lock.yaml in this package still pins hono to 4.7.6 (and specifier ^4.7.4), so this change won’t actually take effect for installs that use the lockfile (and may fail with frozen lockfile settings). Please regenerate and commit examples/weather-mcp-server/pnpm-lock.yaml so it resolves hono to 4.11.7 (or later within the new range).
Snyk has created this PR to fix 4 vulnerabilities in the pnpm dependencies of this project.
Snyk changed the following file(s):
examples/weather-mcp-server/package.jsonVulnerabilities that will be fixed with an upgrade:
SNYK-JS-HONO-15123484
SNYK-JS-HONO-15123483
SNYK-JS-HONO-15123868
SNYK-JS-HONO-15123927
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Incorrect Regular Expression
🦉 Incorrect Authorization
🦉 Cross-site Scripting (XSS)