🚨 [security] Update drizzle-orm 0.44.5 → 0.45.2 (major)#122
Open
depfu[bot] wants to merge 1 commit into
Open
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
🚨 Your current dependencies have known security vulnerabilities 🚨
This dependency update fixes known security vulnerabilities. Please see the details below and assess their impact carefully. We recommend to merge and deploy this as soon as possible!
Here is everything you need to know about this upgrade. Please take a good look at what changed and the test results before merging this pull request.
What changed?
✳️ drizzle-orm (0.44.5 → 0.45.2) · Repo
Security Advisories 🚨
🚨 Drizzle ORM has SQL injection via improperly escaped SQL identifiers
Release Notes
0.45.2
0.45.1
0.45.0
0.44.7
0.44.6
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 56 commits:
+ 0.45.2 (#5534)Kit updates (#5490)feat(drizzle-kit): support d1 via binding (#5302)Fixed pg-native Pool detection in node-postgres transactions breaking in environments with forbidden `require()` (fixes #5107) (#5118)Merge pull request #5095 from drizzle-team/main-workflowsMerge branch 'main' into main-workflowsrefactor: Update condition for run-feature job to improve clarity and functionalityMerge pull request #5087 from drizzle-team/main-workflowschore: Comment out NEON_HTTP_CONNECTION_STRING requirement in release workflowsrefactor: Simplify release router workflow by removing unnecessary switch job and consolidating secret inheritanceMerge remote-tracking branch 'origin/ext-deps-kit' into main-workflows+feat: Add release router workflow to manage feature and latest releasesMerge pull request #5002 from drizzle-team/main-next-packCredited author of copied tests in changelogMerge branch 'main' of https://github.com/drizzle-team/drizzle-orm into main-next-packFixed `bun-sql:postgresql` date, timestamp mappers not accounting for `Date` instances in driver response, updated changelogsFixed `SQL` in `` (fixes #2388, rework of #2911 with handling in proper place)fix: update permissions for GitHub releases in workflow fileschore: Update version to 0.31.8 and add changelog for bug fixesfix: Update external dependencies in build configurationRemoved unneeded lefrover changesMerge remote-tracking branch 'origin/main'+Merge pull request #5036 from drizzle-team/kit-checksMerge branch 'main' into kit-checksfix: Update permissions and streamline npm configuration in release workflowsMerge pull request #5035 from drizzle-team/kit-checksfix: Add environment variables for npm authentication in release workflowfix: Fix release-latestMerge pull request #5034 from drizzle-team/kit-checks++fix npm releasefix npm releasefix: Update Docker image tag from 'latest' to '6' in createDockerDB functionfix: Update version to 0.31.7 and add changelog for bug fixesfix: Refine CHECK constraint query in pgSerializerVersion fixVersion bump, added changelogsFix: Updated algorithm typo (#1676)Feat: Allow subqueries in select fields (#1674)Build fixFix pg-native Pool transactions (#1708)[Drizzle Kit]: Extend api (#4999)fix durable sqlite transaction return value (#3746)Merge pull request #4826 from divyenduz/patch-1Merge branch 'main' into patch-1dprintMerge branch 'feat/issue-4873'dprintfeat: add `$replicas` reference (#4874)Bump versionMerge branch 'main' into feat/issue-4873[Drizzle Kit]: Add casing support to studio configuration and related functions (#4940)Merge branch 'main' into feat/issue-4873🆕 @emnapi/core (added, 1.4.3)
🆕 @emnapi/runtime (added, 1.4.3)
🆕 @emnapi/wasi-threads (added, 1.0.2)
🆕 @napi-rs/wasm-runtime (added, 0.2.11)
🆕 @tybys/wasm-util (added, 0.9.0)
🆕 tslib (added, 2.8.0)
Depfu will automatically keep this PR conflict-free, as long as you don't add any commits to this branch yourself. You can also trigger a rebase manually by commenting with
@depfu rebase.All Depfu comment commands