Skip to content

Bump h3 from 1.15.4 to 1.15.11#2000

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/h3-1.15.11
Open

Bump h3 from 1.15.4 to 1.15.11#2000
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/h3-1.15.11

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Apr 2, 2026

Copy link
Copy Markdown
Contributor

Bumps h3 from 1.15.4 to 1.15.11.

Release notes

Sourced from h3's releases.

v1.15.11

compare changes

🏡 Chore

v1.15.10

compare changes

🩹 Fixes

  • Preserve percent-encoded req.url in app event handler (#1355)

❤️ Contributors

v1.15.9

compare changes

🩹 Fixes

  • Preserve %25 in pathname (1103df6)
  • static: Prevent path traversal via double-encoded dot segments (%252e%252e) (c56683d)
  • sse: Sanitize carriage returns in event stream data and comments (ba3c3fe)

v1.15.8

compare changes

🩹 Fixes

  • Preserve %25 in pathname (1103df6)

v1.15.7

compare changes

🩹 Fixes

  • static: Narrow path traversal check to match .. as a path segment only (c049dc0)
  • app: Decode percent-encoded path segments to prevent auth bypass (313ea52)

💅 Refactors

  • Remove implicit event handler conversion warning (#1340)

❤️ Contributors

... (truncated)

Changelog

Sourced from h3's changelog.

v1.15.11

compare changes

🏡 Chore

❤️ Contributors

v1.15.10

compare changes

🩹 Fixes

  • Preserve percent-encoded req.url in app event handler (#1355)

🏡 Chore

❤️ Contributors

v1.15.9

compare changes

🩹 Fixes

  • Preserve %25 in pathname (1103df6)
  • static: Prevent path traversal via double-encoded dot segments (%252e%252e) (c56683d)
  • sse: Sanitize carriage returns in event stream data and comments (ba3c3fe)

🏡 Chore

❤️ Contributors

... (truncated)

Commits

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Apr 2, 2026
Copilot AI review requested due to automatic review settings April 2, 2026 05:12
@dependabot dependabot Bot review requested due to automatic review settings April 2, 2026 05:12
@github-project-automation github-project-automation Bot moved this to Backlog (Not Ready) in DevX Apr 2, 2026
Copilot AI review requested due to automatic review settings April 23, 2026 20:18
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/h3-1.15.11 branch from 623e616 to 7b77cad Compare April 23, 2026 20:18
@dependabot dependabot Bot review requested due to automatic review settings April 23, 2026 20:18
Bumps [h3](https://github.com/h3js/h3) from 1.15.4 to 1.15.11.
- [Release notes](https://github.com/h3js/h3/releases)
- [Changelog](https://github.com/h3js/h3/blob/v1.15.11/CHANGELOG.md)
- [Commits](h3js/h3@v1.15.4...v1.15.11)

---
updated-dependencies:
- dependency-name: h3
  dependency-version: 1.15.11
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/h3-1.15.11 branch from 7b77cad to c67a350 Compare April 30, 2026 20:03
@dependabot dependabot Bot requested review from Copilot and removed request for Copilot April 30, 2026 20:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

Status: Backlog (Not Ready)

Development

Successfully merging this pull request may close these issues.

0 participants