Skip to content

Bump h3 from 2.0.1-rc.14 to 2.0.1-rc.16 in the npm_and_yarn group across 1 directory#115

Merged
github-actions[bot] merged 1 commit intomainfrom
dependabot/npm_and_yarn/npm_and_yarn-a49ea5abe7
Mar 18, 2026
Merged

Bump h3 from 2.0.1-rc.14 to 2.0.1-rc.16 in the npm_and_yarn group across 1 directory#115
github-actions[bot] merged 1 commit intomainfrom
dependabot/npm_and_yarn/npm_and_yarn-a49ea5abe7

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot bot commented on behalf of github Mar 18, 2026

Bumps the npm_and_yarn group with 1 update in the / directory: h3.

Updates h3 from 2.0.1-rc.14 to 2.0.1-rc.16

Release notes

Sourced from h3's releases.

v2.0.1-rc.16

compare changes

📦 Dependencies

v2.0.1-rc.15

compare changes

🚀 Enhancements

  • handler: New defineJsonRpcHandler and defineJsonRpcWebSocketHandler (#1180)

🔥 Performance

  • resolveLazyHandler: Replace with inline expression (#1296)

🩹 Fixes

  • sse: Sanitize newlines in event stream fields to prevent SSE injection (7791538)
  • static: Prevent path traversal via percent-encoded dot segments (0e751b4)

📖 Documentation

  • community: Add clear router (#1303)
  • Add unjwt community library entry (#1309)

📦 Build

  • Bundle docs as skill + h3 docs (#1311)

❤️ Contributors

Changelog

Sourced from h3's changelog.

v2.0.1-rc.16

compare changes

🏡 Chore

❤️ Contributors

v2.0.1-rc.15

compare changes

🚀 Enhancements

  • handler: New defineJsonRpcHandler and defineJsonRpcWebSocketHandler (#1180)

🔥 Performance

  • resolveLazyHandler: Replace with inline expression (#1296)

🩹 Fixes

  • sse: Sanitize newlines in event stream fields to prevent SSE injection (7791538)
  • static: Prevent path traversal via percent-encoded dot segments (0e751b4)

📖 Documentation

  • community: Add clear router (#1303)
  • Add unjwt community library entry (#1309)

📦 Build

  • Bundle docs as skill + h3 docs (#1311)

🏡 Chore

❤️ Contributors

... (truncated)

Commits
  • 95111ad chore(release): v2.0.1-rc.16
  • 05959e3 chore: update srvx
  • 4701dc4 chore: update rou3 to 0.8
  • e69f0c4 chore: update deps
  • 9136183 chore(release): v2.0.1-rc.15
  • 6da10a9 chore: update deps
  • 0e751b4 fix(static): prevent path traversal via percent-encoded dot segments
  • 7791538 fix(sse): sanitize newlines in event stream fields to prevent SSE injection
  • 1689ee3 docs: add unjwt community library entry (#1309)
  • 45de3dc build: bundle docs as skill + h3 docs (#1311)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps the npm_and_yarn group with 1 update in the / directory: [h3](https://github.com/h3js/h3).


Updates `h3` from 2.0.1-rc.14 to 2.0.1-rc.16
- [Release notes](https://github.com/h3js/h3/releases)
- [Changelog](https://github.com/h3js/h3/blob/main/CHANGELOG.md)
- [Commits](h3js/h3@v2.0.1-rc.14...v2.0.1-rc.16)

---
updated-dependencies:
- dependency-name: h3
  dependency-version: 2.0.1-rc.16
  dependency-type: indirect
  dependency-group: npm_and_yarn
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Mar 18, 2026
@github-actions github-actions bot merged commit d776e16 into main Mar 18, 2026
4 checks passed
@github-actions github-actions bot deleted the dependabot/npm_and_yarn/npm_and_yarn-a49ea5abe7 branch March 18, 2026 20:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants