Skip to content

deps(indexer): bump the minor-and-patch group across 1 directory with 2 updates#57

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/packages/indexer/minor-and-patch-08234e3637
Open

deps(indexer): bump the minor-and-patch group across 1 directory with 2 updates#57
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/packages/indexer/minor-and-patch-08234e3637

Conversation

@dependabot
Copy link
Copy Markdown

@dependabot dependabot Bot commented on behalf of github Mar 30, 2026

Bumps the minor-and-patch group with 2 updates in the /packages/indexer directory: drizzle-orm and @electric-sql/pglite.

Updates drizzle-orm from 0.45.1 to 0.45.2

Release notes

Sourced from drizzle-orm's releases.

0.45.2

  • Fixed sql.identifier(), sql.as() escaping issues. Previously all the values passed to this functions were not properly escaped causing a possible SQL Injection (CWE-89) vulnerability

Thanks to @​EthanKim88, @​0x90sh and @​wgoodall01 for reaching out to us with a reproduction and suggested fix

Commits

Updates @electric-sql/pglite from 0.3.16 to 0.4.2

Release notes

Sourced from @​electric-sql/pglite's releases.

@​electric-sql/pglite-sync@​0.4.2

Patch Changes

  • Updated dependencies [3dfa40f]
    • @​electric-sql/pglite@​0.3.16

@​electric-sql/pglite@​0.4.2

Patch Changes

  • 41632c4: Allow passing initdb.wasm asset for bundlers that need it.

@​electric-sql/pglite@​0.4.1

Patch Changes

  • 37fb39e: clear timers on exit; remove pglite-socket dependency on pglite-postgis

@​electric-sql/pglite-sync@​0.4.0

Minor Changes

  • 408500c: Allow passing in onError to 'syncShapesToTables'

Patch Changes

  • Updated dependencies [8785034]
  • Updated dependencies [90cfee8]
    • @​electric-sql/pglite@​0.3.14

@​electric-sql/pglite-sync@​0.3.17

Patch Changes

  • Updated dependencies [ad3d0d8]
    • @​electric-sql/pglite@​0.3.13
Changelog

Sourced from @​electric-sql/pglite's changelog.

0.4.2

Patch Changes

  • 41632c4: Allow passing initdb.wasm asset for bundlers that need it.

0.4.1

Patch Changes

  • 37fb39e: clear timers on exit; remove pglite-socket dependency on pglite-postgis

0.4.0

Minor Changes

  • d848955: New simplified PGlite with separate initdb. New included extension: pg_textsearch (experimental). New package for postgis (experimental) as extension. Breaking changes: 'postgres' is the default database instead of 'template1'.
Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

… 2 updates

Bumps the minor-and-patch group with 2 updates in the /packages/indexer directory: [drizzle-orm](https://github.com/drizzle-team/drizzle-orm) and [@electric-sql/pglite](https://github.com/electric-sql/pglite/tree/HEAD/packages/pglite).


Updates `drizzle-orm` from 0.45.1 to 0.45.2
- [Release notes](https://github.com/drizzle-team/drizzle-orm/releases)
- [Commits](drizzle-team/drizzle-orm@0.45.1...0.45.2)

Updates `@electric-sql/pglite` from 0.3.16 to 0.4.2
- [Release notes](https://github.com/electric-sql/pglite/releases)
- [Changelog](https://github.com/electric-sql/pglite/blob/main/packages/pglite/CHANGELOG.md)
- [Commits](https://github.com/electric-sql/pglite/commits/@electric-sql/pglite@0.4.2/packages/pglite)

---
updated-dependencies:
- dependency-name: drizzle-orm
  dependency-version: 0.45.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: "@electric-sql/pglite"
  dependency-version: 0.4.2
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github
Copy link
Copy Markdown
Author

dependabot Bot commented on behalf of github Mar 30, 2026

Labels

The following labels could not be found: dependencies, indexer. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@vercel
Copy link
Copy Markdown

vercel Bot commented Mar 30, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

2 Skipped Deployments
Project Deployment Actions Updated (UTC)
horizon-starknet.production Ignored Ignored Mar 30, 2026 1:30am
horizon-starknet.sepolia Ignored Ignored Mar 30, 2026 1:30am

Request Review

@coderabbitai
Copy link
Copy Markdown

coderabbitai Bot commented Mar 30, 2026

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Free

Run ID: 0b28e295-12a1-4a8e-a389-291f879f090b

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands and usage tips.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants