ReviewOS

stacks/bun-query-builder

Dependency Dashboard

#1004
Open github-actions[bot] opened this 22 days ago · 0 comments
22 days ago

This issue lists Buddy Bot updates and detected dependencies. Read the Dependency Dashboard docs to learn more.

[!CAUTION] 7 known vulnerabilities affect 4 dependencies in this repository.

SeverityPackageCurrentAdvisoryFixed in
🟠 Highkysely^0.28.14GHSA-pv5w-4p9q-p3v20.28.17
🟠 Highkysely^0.28.11GHSA-8cpq-38p9-67gx0.28.14
🟠 Highkysely^0.28.11GHSA-pv5w-4p9q-p3v20.28.17
🟠 Highkysely^0.28.11GHSA-wmrf-hv6w-mr660.28.12
🟠 Highdrizzle-orm^0.45.1GHSA-gpj5-g38j-94v90.45.2
🟡 Moderatetypeorm^0.3.28GHSA-2rp8-mm9q-fp490.3.31
🟡 Moderatetypeorm^0.3.28GHSA-9ggv-8w38-r7pm0.3.29

Open

The following updates have all been created. To force a retry/rebase of any, click on a checkbox below.

Detected dependencies

npm
package.json
  • @stacksjs/ts-validation ^0.5.3
  • @stacksjs/bunpress ^0.2.11
  • @stacksjs/launchpad ^0.6.4
  • @stacksjs/ts-faker ^0.1.8
  • better-dx ^0.2.22
  • pickier ^0.1.56
  • ts-pantry ^0.11.29
package.json
  • @prisma/adapter-better-sqlite3 ^7.9.1
  • @prisma/client 6.19.3
  • better-sqlite3 ^12.11.1
  • bun-query-builder workspace:*
  • chalk ^6.0.0
  • cli-table3 ^0.6.5
  • drizzle-orm ^0.45.2
  • kysely ^0.28.14
  • kysely-bun-sqlite ^0.4.0
  • mitata ^1.0.34
  • prisma 6.19.3
  • typeorm ^1.1.0
  • @types/bun ^1.3.14
  • typescript ^7.0.2
package.json
  • @stacksjs/clapp ^0.2.12
  • @stacksjs/ts-faker ^0.1.8
  • @stacksjs/ts-validation ^0.5.2
  • dynamodb-tooling ^0.3.5
  • bunfig ^0.15.17
github-actions
.github/workflows/ci.yml
  • actions/checkout v7.0.1
  • oven-sh/setup-bun v2.2.0
  • actions/cache v6.1.0
  • actions/checkout v7
  • pantry-pm/pantry/packages/action main
.github/workflows/release.yml
  • actions/checkout v7.0.1
  • pantry-pm/pantry/packages/action main
  • stacksjs/action-releaser v1.2.11
.github/workflows/buddy-bot.yml
  • actions/checkout v7
  • oven-sh/setup-bun v2
  • shivammathur/setup-php v2
dependency-files
deps.yaml
  • bun ^1.3.14
  • mysql ^8.0.45
  • postgres ^18.0.0
  • sqlite ^3.52.0
  • libevent.org ^2
  • lz4.org ^1
  • openssl.org ^3
  • zlib.net ^1.2
  • facebook.com/zstd ^1
  • curl.se >=6.0
  • thrysoee.dk/editline ^3
  • developers.yubico.com/libfido2 ^1
  • sourceforge.net/libtirpc *
  • gnu.org/gcc/libstdcxx @14
  • curl.se/ca-certs *
  • tukaani.org/xz ^5
  • nghttp2.org *
  • invisible-island.net/ncurses ^6
  • github.com/PJK/libcbor @0
  • systemd.io *
  • libexpat.github.io *
  • google.com/fullycapable *
  • github.com/util-linux/util-linux *
  • github.com/besser82/libxcrypt *
  • gnu.org/libidn2 *
  • gnutls.org *
  • sourceware.org/bzip2 @1
  • pcre.org/v2 *
  • gnu.org/gettext ^0
  • sqlite.org ^3
  • gnome.org/libxml2 ~2.13 # 2.14 changes the API
  • gnu.org/readline @8
  • freedesktop.org/p11-kit *
  • gnu.org/libunistring ^1
  • gnu.org/libtasn1 ^4
  • gnu.org/nettle ^3
  • gnu.org/gmp >=4.2
  • unbound.net ^1
  • sourceware.org/libffi ^3
  • gnu.org/libiconv *
  • kerberos.org *
  • gnu.org/binutils *
  • gnu.org/mpfr >=2.4.0
  • gnu.org/mpc >=0.8.0
  • darwin/x86-64 ^# since 15.1.0
  • gnome.org/libxslt *
  • unicode.org ^73
pantry.lock
  • typescript ^5.9.3
  • chalk ^5.6.2
  • prisma ^7.4.2
  • ts-mocker ^0.1.7
  • @prisma/client ^7.4.2
  • kysely ^0.28.11
  • @types/bun ^1.3.10
  • @stacksjs/ts-validation ^0.4.10
  • @stacksjs/ts-validation ^0.4.9
  • @stacksjs/launchpad 0.6.4
  • cli-table3 ^0.6.5
  • drizzle-orm ^0.45.1
  • bunfig ^0.15.6
  • better-sqlite3 ^12.6.2
  • better-dx 0.2.7
  • typeorm ^0.3.28
  • dynamodb-tooling ^0.3.2
  • @stacksjs/clapp ^0.2.0
  • ts-mocker ^0.1.5
  • @stacksjs/docs 0.70.23
  • mitata ^1.0.34

  • Check this box to trigger a request for Buddy Bot to run again on this repository

Sign in to comment on this issue.