fix(deps): bump hono to ^4.12.7 (GHSA-v8w9-8mx6-g223)#308
Conversation
Resolves Dependabot alert #38 — prototype pollution via parseBody({ dot: true }). Not exploitable in Skillsmith (we don't use parseBody), but patching the transitive dependency through @modelcontextprotocol/sdk to eliminate the advisory. Co-Authored-By: claude-flow <ruv@ruv.net> Co-Authored-By: Claude <noreply@anthropic.com>
Performance Benchmark Results╔═══════════════════════════════════════════════════════════════╗ Running 50 iterations with 10 warmup... --- Memory Operations --- --- Embedding Search --- --- Recommendation Pipeline --- ═══════════════════════════════════════════════════════════════ V3 Migration Benchmark ReportDate: 2026-03-12T06:12:21.505Z Results
Summary
Notes
|
Summary
hononpm override from^4.11.10to^4.12.7to resolve Dependabot alert fix(website): enable SSR for signup page to read tier query param #38parseBody({ dot: true })(GHSA-v8w9-8mx6-g223)parseBody), but patching the transitive dep through@modelcontextprotocol/sdkResolves https://github.com/smith-horn/skillsmith/security/dependabot/38
Test plan
npm ls honoconfirms 4.12.7🤖 Generated with claude-flow