[Snyk] Upgrade: , , axios, chart.js, cheerio, lucide-react, prisma, qrcode.react, react-resizable-panels #200
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Snyk has created this PR to upgrade multiple dependencies.
👯 The following dependencies are linked and will therefore be updated together.ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
@prisma/client
from 5.18.0 to 5.19.0 | 76 versions ahead of your current version | a month ago
on 2024-08-27
@sentry/nextjs
from 7.118.0 to 7.119.0 | 1 version ahead of your current version | a month ago
on 2024-08-14
axios
from 1.7.4 to 1.7.7 | 3 versions ahead of your current version | 22 days ago
on 2024-08-31
chart.js
from 4.4.3 to 4.4.4 | 1 version ahead of your current version | a month ago
on 2024-08-20
cheerio
from 1.0.0-rc.12 to 1.0.0 | 1 version ahead of your current version | a month ago
on 2024-08-09
lucide-react
from 0.416.0 to 0.437.0 | 19 versions ahead of your current version | 22 days ago
on 2024-08-31
prisma
from 5.18.0 to 5.19.0 | 75 versions ahead of your current version | a month ago
on 2024-08-27
qrcode.react
from 3.1.0 to 3.2.0 | 1 version ahead of your current version | 21 days ago
on 2024-09-01
react-resizable-panels
from 2.1.0 to 2.1.2 | 2 versions ahead of your current version | 24 days ago
on 2024-08-29
Release notes
Package name: @prisma/client
-
5.19.0 - 2024-08-27
-
-
-
-
-
import { PrismaClient } from '@ prisma/client'
- Mathematic operations such as
- Resolved issues when comparing
- #23742 fixes Prisma Client not supporting deeply nested
- Senior Engineer (TypeScript): This person will be primarily working on the TypeScript side and evolving our Prisma client. Rust knowledge (or desire to learn Rust) is a plus.
- Senior Engineer (Rust): This person will be focused on the
-
5.19.0-integration-feat-typed-sql.26 - 2024-08-23
-
5.19.0-integration-feat-typed-sql.25 - 2024-08-23
-
5.19.0-integration-feat-typed-sql.24 - 2024-08-23
-
5.19.0-integration-feat-typed-sql.23 - 2024-08-23
-
5.19.0-integration-feat-typed-sql.22 - 2024-08-23
-
5.19.0-integration-feat-typed-sql.21 - 2024-08-22
-
5.19.0-integration-feat-typed-sql.20 - 2024-08-22
-
5.19.0-integration-feat-typed-sql.19 - 2024-08-22
-
5.19.0-integration-feat-typed-sql.18 - 2024-08-22
-
5.19.0-integration-feat-typed-sql.17 - 2024-08-22
-
5.19.0-integration-feat-typed-sql.16 - 2024-08-22
-
5.19.0-integration-feat-typed-sql.15 - 2024-08-22
-
5.19.0-integration-feat-typed-sql.14 - 2024-08-22
-
5.19.0-integration-feat-typed-sql.13 - 2024-08-21
-
5.19.0-integration-feat-typed-sql.12 - 2024-08-21
-
5.19.0-integration-feat-typed-sql.11 - 2024-08-21
-
5.19.0-integration-feat-typed-sql.10 - 2024-08-21
-
5.19.0-integration-feat-typed-sql.9 - 2024-08-21
-
5.19.0-integration-feat-typed-sql.8 - 2024-08-20
-
5.19.0-integration-feat-typed-sql.7 - 2024-08-20
-
5.19.0-integration-feat-typed-sql.6 - 2024-08-08
-
5.19.0-integration-feat-typed-sql.5 - 2024-08-07
-
5.19.0-integration-feat-typed-sql.4 - 2024-08-07
-
5.19.0-integration-feat-typed-sql.3 - 2024-08-07
-
5.19.0-integration-feat-typed-sql.2 - 2024-08-07
-
5.19.0-integration-feat-typed-sql.1 - 2024-08-07
-
5.19.0-integration-engines-5-19-0-9-integration-fix-planetscale-transactions-6b0a78a8af3fae4debef82ff443972dff0807722.2 - 2024-08-12
-
5.19.0-integration-engines-5-19-0-9-integration-fix-planetscale-transactions-6b0a78a8af3fae4debef82ff443972dff0807722.1 - 2024-08-12
-
5.19.0-integration-engines-5-19-0-32-integration-fix-planetscale-transactions-c83aea2de749622725d37b2125922e2b83ac349c.2 - 2024-08-26
-
5.19.0-integration-engines-5-19-0-32-integration-fix-planetscale-transactions-c83aea2de749622725d37b2125922e2b83ac349c.1 - 2024-08-26
-
5.19.0-integration-engines-5-19-0-3-integration-fix-d1-int64-3fe108cb35159b6838b9365ea06876b999e37136.2 - 2024-08-08
-
5.19.0-integration-engines-5-19-0-3-integration-fix-d1-int64-3fe108cb35159b6838b9365ea06876b999e37136.1 - 2024-08-08
-
5.19.0-integration-engines-5-19-0-29-integration-build-rs-version-34ac31986ed851ada6e3c142e76db8fdb839a8f0.2 - 2024-08-24
-
5.19.0-integration-engines-5-19-0-29-integration-build-rs-version-34ac31986ed851ada6e3c142e76db8fdb839a8f0.1 - 2024-08-24
-
5.19.0-integration-engines-5-19-0-28-integration-enum-mapped-values-ba87944c8b88a1e7b2255a110274d540df6bb831.2 - 2024-08-24
-
5.19.0-integration-engines-5-19-0-28-integration-enum-mapped-values-ba87944c8b88a1e7b2255a110274d540df6bb831.1 - 2024-08-24
-
5.19.0-integration-engines-5-19-0-25-feat-typed-sql-nullability-860858bb818708261f36cd05bc915e603aae5004.1 - 2024-08-20
-
5.19.0-integration-engines-5-19-0-22-integration-mongodb-ipv6-fix-a6fed372778795b60d9899578c11319bc19597ac.2 - 2024-08-20
-
5.19.0-integration-engines-5-19-0-22-integration-mongodb-ipv6-fix-a6fed372778795b60d9899578c11319bc19597ac.1 - 2024-08-20
-
5.19.0-integration-engines-5-19-0-21-feat-typed-sql-nullability-e696c9149500a73fbefedf5b0edb3f085ff90515.1 - 2024-08-19
-
5.19.0-integration-engines-5-19-0-20-integration-mongodb-ipv6-fix-52a7684de6884ddf5b7e91ac5f37254a02a69774.2 - 2024-08-15
-
5.19.0-integration-engines-5-19-0-20-integration-mongodb-ipv6-fix-52a7684de6884ddf5b7e91ac5f37254a02a69774.1 - 2024-08-15
-
5.19.0-integration-engines-5-19-0-2-integration-fix-d1-int64-e5ebd17c4a7f6a855bd0d3594e1c593542db3061.2 - 2024-08-07
-
5.19.0-integration-engines-5-19-0-2-integration-fix-d1-int64-e5ebd17c4a7f6a855bd0d3594e1c593542db3061.1 - 2024-08-07
-
5.19.0-integration-engines-5-19-0-18-feat-typed-sql-nullability-c4dc3c5083115b65abe4436e4ec6e1c8c2afbecd.1 - 2024-08-14
-
5.19.0-integration-engines-5-19-0-17-feat-typed-sql-nullability-4b818550ffc9da4e66541525cca08569a58a78e2.1 - 2024-08-14
-
5.19.0-integration-engines-5-19-0-16-feat-typed-sql-nullability-c79c3569f88658b971ff948a55aff64ff3a4e4bf.1 - 2024-08-14
-
5.19.0-integration-engines-5-19-0-15-integration-fix-planetscale-transactions-cc0baab23c1961e4f06f2114b9cf252e99ac90f5.2 - 2024-08-14
-
5.19.0-integration-engines-5-19-0-15-integration-fix-planetscale-transactions-cc0baab23c1961e4f06f2114b9cf252e99ac90f5.1 - 2024-08-14
-
5.19.0-integration-engines-5-19-0-14-feat-typed-sql-nullability-29abebce25f4e6c26673d18598de307337325b86.1 - 2024-08-13
-
5.19.0-integration-engines-5-19-0-13-feat-typed-sql-nullability-7d01fb5b13f6e0f51384fe689b7e9ace5a504565.1 - 2024-08-13
-
5.19.0-integration-engines-5-19-0-11-integration-fix-planetscale-transactions-5154993b5b25464fff0c724fe47c547aa076c73a.2 - 2024-08-12
-
5.19.0-integration-engines-5-19-0-11-integration-fix-planetscale-transactions-5154993b5b25464fff0c724fe47c547aa076c73a.1 - 2024-08-12
-
5.19.0-integration-engines-5-19-0-10-integration-fix-planetscale-transactions-630e1df957c8431ec5989ee7188545730681ae49.2 - 2024-08-12
-
5.19.0-integration-engines-5-19-0-10-integration-fix-planetscale-transactions-630e1df957c8431ec5989ee7188545730681ae49.1 - 2024-08-12
-
5.19.0-integration-engines-5-19-0-1-integration-fix-d1-int64-61431bbd9716f47de3f303a09ece9b370da04142.2 - 2024-08-06
-
5.19.0-integration-engines-5-19-0-1-integration-fix-d1-int64-61431bbd9716f47de3f303a09ece9b370da04142.1 - 2024-08-06
-
5.19.0-dev.18 - 2024-08-26
-
5.19.0-dev.17 - 2024-08-24
-
5.19.0-dev.16 - 2024-08-23
-
5.19.0-dev.15 - 2024-08-23
-
5.19.0-dev.14 - 2024-08-23
-
5.19.0-dev.13 - 2024-08-21
-
5.19.0-dev.12 - 2024-08-20
-
5.19.0-dev.11 - 2024-08-19
-
5.19.0-dev.10 - 2024-08-16
-
5.19.0-dev.9 - 2024-08-16
-
5.19.0-dev.8 - 2024-08-13
-
5.19.0-dev.7 - 2024-08-12
-
5.19.0-dev.6 - 2024-08-12
-
5.19.0-dev.5 - 2024-08-12
-
5.19.0-dev.4 - 2024-08-12
-
5.19.0-dev.3 - 2024-08-09
-
5.19.0-dev.2 - 2024-08-09
-
5.19.0-dev.1 - 2024-08-07
-
5.18.0 - 2024-08-06
model User {
- SQLite db will now be created and read from the correct location when using
- Empty
- Support UUID v7
- Support fetching references for a model
from @prisma/client GitHub release notesToday, we are excited to share the
5.19.0stable release 🎉🌟 Help us spread the word about Prisma by starring the repo or posting on X about the release. 🌟
Highlights
Introducing TypedSQL
TypedSQL is a brand new way to interact with your database from Prisma Client. After enabling the
typedSqlPreview feature, you’re able to write SQL queries in a newsqlsubdirectory of yourprismadirectory. These queries are then checked by Prisma during using the new--sqlflag ofprisma generateand added to your client for use in your code.To get started with TypedSQL:
Make sure that you have the latest version of
prismaand@ prisma/clientinstalled:Enable the
typedSqlPreview feature in your Prisma Schema.Create a
sqlsubdirectory of yourprismadirectory.You can now add
.sqlfiles to thesqldirectory! Each file can contain one sql query and the name must be a valid JS identifier. For this example, say you had the filegetUsersWithPosts.sqlwith the following contents:Import your SQL query into your code with the
@ prisma/client/sqlimport:import { getUsersWithPosts } from '@prisma/client/sql'
const prisma = new PrismaClient()
const usersWithPostCounts = await prisma.$queryRawTyped(getUsersWithPosts)
console.log(usersWithPostCounts)
There’s a lot more to talk about with TypedSQL. We think that the combination of the high-level Prisma Client API and the low-level TypedSQL will make for a great developer experience for all of our users.
To learn more about behind the “why” of TypedSQL be sure to check out our announcement blog post.
For docs, check out our new TypedSQL section.
Bug fixes
Driver adapters and D1
A few issues with our
driverAdaptersPreview feature and Cloudflare D1 support were resolved via prisma/prisma-engines#4970 and #24922max,min,eq, etc in queries when using Cloudflare D1.BigIntIDs whenrelationMode="prisma"was enabled and Cloudflare D1 was being used.Joins
someclauses when therelationJoinsPreview feature was enabled.MongoDB
The MongoDB driver for Rust (that our query engine users under the hood) had behavior that prioritized IPv4 connections over IPv6 connections. In IPv6-only environments, this could lead to significant "cold starts" where the query engine had to wait for IPv4 to fail before the driver would try IPv6.
With help from the MongoDB team, this has been resolved. The driver will now try IPv4 and IPv6 connections in parallel and then move forward with the first response. This should prevent cold start issues that have been seen with MongoDB in Prisma Accelerate.
Thank you to the MongoDB team!
Join us
Looking to make an impact on Prisma in a big way? We're now hiring engineers for the ORM team!
prisma-enginesRust codebase. TypeScript knowledge (or, again, a desire to learn) is a plus.Credits
Huge thanks to @ mcuelenaere, @ pagewang0, @ Druue, @ key-moon, @ Jolg42, @ pranayat, @ ospfranco, @ yubrot, @ skyzh for helping!
🌟 Help us spread the word about Prisma by starring the repo or tweeting about the release. 🌟
Highlights
Native support for UUIDv7
Previous to this release, the Prisma Schema function
uuid()did not accept any arguments and created a UUIDv4 ID. While sufficient in many cases, UUIDv4 has a few drawbacks, namely that it is not temporally sortable.UUIDv7 attempts to resolve this issue, making it easy to temporally sort your database rows by ID!
To support this, we’ve updated the
uuid()function in Prisma Schema to accept an optional, integer argument. Right now, the only valid values are4and7, with4being the default.id String @id @default(uuid()) // defaults to 4
name String
}
model User {
id String @id @default(uuid(4)) // same as above, but explicit
name String
}
model User {
id String @id @default(uuid(7)) // will use UUIDv7 instead of UUIDv4
name String
}
Bug squashing
We’ve squashed a number of bugs this release, special thanks to everyone who helped us! A few select highlights are:
prismaSchemaFolder.Json[]fields will now return[]instead ofnullwhen accessed through a join using therelationJoinsPreview feature.Fixes and improvements
Prisma
Language tools (e.g. VS Code)
Share your feedback about Prisma ORM
We want to know how you like working with Prisma ORM in your projects! Please take our 2min survey and let us know what you like or where we can improve 🙏
Credits
Huge thanks to @ mcuelenaere, @ pagewang0, @ Druue, @ key-moon, @ Jolg42, @ pranayat, @ ospfranco, @ yubrot, @ skyzh, @ haaawk for helping!
Package name: @sentry/nextjs
-
7.119.0 - 2024-08-14
- backport(tracing): Report dropped spans for transactions (#13343)
Path
Size
@ sentry/browser (incl. Tracing, Replay, Feedback) - Webpack (gzipped)
80.96 KB
@ sentry/browser (incl. Tracing, Replay) - Webpack (gzipped)
71.89 KB
@ sentry/browser (incl. Tracing, Replay with Canvas) - Webpack (gzipped)
76.14 KB
@ sentry/browser (incl. Tracing, Replay) - Webpack with treeshaking flags (gzipped)
65.52 KB
@ sentry/browser (incl. Tracing) - Webpack (gzipped)
35.77 KB
@ sentry/browser (incl. browserTracingIntegration) - Webpack (gzipped)
35.66 KB
@ sentry/browser (incl. Feedback) - Webpack (gzipped)
31.71 KB
@ sentry/browser (incl. sendFeedback) - Webpack (gzipped)
31.72 KB
@ sentry/browser - Webpack (gzipped)
22.91 KB
@ sentry/browser (incl. Tracing, Replay, Feedback) - ES6 CDN Bundle (gzipped)
79.17 KB
@ sentry/browser (incl. Tracing, Replay) - ES6 CDN Bundle (gzipped)
70.49 KB
@ sentry/browser (incl. Tracing) - ES6 CDN Bundle (gzipped)
36.17 KB
@ sentry/browser - ES6 CDN Bundle (gzipped)
25.41 KB
@ sentry/browser (incl. Tracing, Replay) - ES6 CDN Bundle (minified & uncompressed)
221.92 KB
@ sentry/browser (incl. Tracing) - ES6 CDN Bundle (minified & uncompressed)
109.52 KB
@ sentry/browser - ES6 CDN Bundle (minified & uncompressed)
76.24 KB
@ sentry/browser (incl. Tracing) - ES5 CDN Bundle (gzipped)
39.45 KB
@ sentry/react (incl. Tracing, Replay) - Webpack (gzipped)
72.4 KB
@ sentry/react - Webpack (gzipped)
22.94 KB
@ sentry/nextjs Client (incl. Tracing, Replay) - Webpack (gzipped)
90.16 KB
@ sentry/nextjs Client - Webpack (gzipped)
54.27 KB
@ sentry-internal/feedback - Webpack (gzipped)
17.34 KB
-
7.118.0 - 2024-06-21
from @sentry/nextjs GitHub release notesBundle size 📦
Package name: axios
-
1.7.7 - 2024-08-31
- fetch: fix stream handling in Safari by fallback to using a stream reader instead of an async iterator; (#6584) (d198085)
- http: fixed support for IPv6 literal strings in url (#5731) (364993f)
Rishi556
Dmitriy Mozgovoy
-
1.7.6 - 2024-08-30
- fetch: fix content length calculation for FormData payload; (#6524) (085f568)
- fetch: optimize signals composing logic; (#6582) (df9889b)
Dmitriy Mozgovoy
Jacques Germishuys
kuroino721
-
1.7.5 - 2024-08-23
- adapter: fix undefined reference to hasBrowserEnv (#6572) (7004707)
- core: add the missed implementation of AxiosError#status property; (#6573) (6700a8a)
- core: fix
- fetch: fix credentials handling in Cloudflare workers (#6533) (550d885)
Dmitriy Mozgovoy
Antonin Bas
Hans Otto Wirtz
-
1.7.4 - 2024-08-13
- sec: CVE-2024-39338 (#6539) (#6543) (6b6b605)
- sec: disregard protocol-relative URL to remediate SSRF (#6539) (07a661a)
Lev Pachmanov
Đỗ Trọng Hải
from axios GitHub release notesRelease notes:
Bug Fixes
Contributors to this release
Release notes:
Bug Fixes
Contributors to this release
Release notes:
Bug Fixes
ReferenceError: navigator is not definedfor custom environments; (#6567) (fed1a4b)Contributors to this release
Release notes:
Bug Fixes
Contributors to this release
Package name: chart.js
-
4.4.4 - 2024-08-20
- npm
- Migration guide
- Docs
- API
- Samples
- #11873 Check if range method exists on element before executing it
- #11863 Return false from the average tooltip positioner on no valid data
- #11858 Bugfix/issue 11804 tooltip show for all invisible
- #11851 fix: Unset _resizeBeforeDraw before _resize() call to avoid possible recursion
- #11844 fix issue #11717
- #11788 Fix drawing angle lines on reversed radial scale
- #11867 fix(types): exclude DeepPartial<unknown[]> from ChartOptions interface
- #11862 fix(types): add xCenter and yCenter properties to RadialLinearScale interface
- #11817 Remove box padding from legend types
- #11796 Add fit method to LegendElement interface
- #11780 types: Allow passing undefined for chart options
- #11871 Add radial linear scale to docs section of samples
- #11823 Update OffscreenCanvas documentation, as it is widely available now
- #11781 Fix some typos
- #11874 Bump package version to 4.4.4
-
4.4.3 - 2024-05-17
- npm
- Migration guide
- Docs
- API
- Samples
- #11754 Fix error when object prototype is frozen
- #11764 do not attempt to clear canvas if one does not exist
- #11755 #11450 hide bar by dataindex
- #11690 Create parsed object with correct keys
- #11707 platform.isAttached should return false if canvas is false-y
- #11762 Update license year
- #11776 Bump to 4.4.3
- #11773 Bump pnpm/action-setup from 3.0.0 to 4.0.0
- #11720 Bump follow-redirects from 1.15.4 to 1.15.6
from chart.js GitHub release notesEssential Links
Bugs Fixed
Types
Documentation
Development
Thanks to @ CatchABus, @ LeeLenaleee, @ MichelHMachado, @ artus9033, @ huqingkun, @ jdufresne and @ joliss
Essential Links
Bugs Fixed
Documentation
Development
Thanks to @ DAcodedBEAT, @ EricWittrock, @ LeeLenaleee, @ LiamSwayne, @ dependabot and @ dependabot[bot]
Package name: cheerio
Cheerio 1.0 is here! 🎉
Announcement Blog Post
Breaking Changes
The minimum NodeJS version is now 18.17 or higher #3959
Import paths were simplified. For example, use
cheerio/sliminstead ofcheerio/lib/slim. #3970The deprecated default Cheerio instance and static methods were removed. #3974
Before, it was possible to write code like this:
html(cheerio('<test></test>')); // ~ '<test></test>' -- NO LONGER WORKS
Make sure to always load documents first:
cheerio.load('<test></test>').html();
Node types previously re-exported by Cheerio must now be imported directly
from (
domhandler)(https://github.com/fb55/domhandler). #3969htmlparser2 options now reside exclusively under the
xmlkey (#2916):New Features
Fixes
cheerio/utilsby @ blixt in #2601data, and simplify by @ fb55 in #2818closestbe able to start from text nodes by @ Qualtagh in #2811Other
Full Changelog: v1.0.0-rc.12...v1.0.0
Bugfix release. Fixed issues:
propundefined handling with jQuery by