Skip to content

chore: updating esbuild version in drizzle-kit #4046

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 3 commits into from
Apr 15, 2025

Conversation

paulmarsicloud
Copy link
Contributor

Bump on esbuild to resolve #4045

@Jac0xb
Copy link

Jac0xb commented Mar 25, 2025

There is also GHSA-67mh-4wv8-2f99

┌─────────────────────┬────────────────────────────────────────────────────────┐
│ moderate            │ esbuild enables any website to send any requests to    │
│                     │ the development server and read the response           │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package             │ esbuild                                                │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ <=0.24.2                                               │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions    │ >=0.25.0                                               │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths               │ ..............  > drizzle-kit@0.30.5 >                 │
│                     │ @esbuild-kit/esm-loader@2.6.5 >                        │
│                     │ @esbuild-kit/core-utils@3.3.2 > esbuild@0.18.20        │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info           │ https://github.com/advisories/GHSA-67mh-4wv8-2f99      │
└─────────────────────┴────────────────────────────────────────────────────────┘

@renebrandel
Copy link

Just saw this PR also addresses the same vulnerability as discussed in #4250. Would love the maintainers' attention on this.

@AndriiSherman
Copy link
Member

I resolved all the conflicts and updated esbuild to 0.25.2 version

@AndriiSherman AndriiSherman merged commit f1c2dd6 into drizzle-team:0.41 Apr 15, 2025
32 checks passed
AndriiSherman added a commit that referenced this pull request Apr 15, 2025
* fix: incorrect types for inArray (#1774)

Co-authored-by: Andrii Sherman <andreysherman11@gmail.com>

* Pass row type parameter to @planetscale/database's execute  (#1852)

* Update session.ts

No need to cast, you can just pass a type parameter

* Update package.json

---------

Co-authored-by: AndriiSherman <andreysherman11@gmail.com>

* Don't enforce type restrictions on mysqlEnum and pgEnum to be non-empty arrays (#2429)

* Removed type restriction on non-empty arrays for mysqEnum

* Removed type restriction on non-empty arrays for pgEnum

* check values argument is not an empty array for pgEnum

* fix: typings

* Add type tests

---------

Co-authored-by: AndriiSherman <andreysherman11@gmail.com>

* Export mapColumnToSchema function (#2495)


Co-authored-by: Andrii Sherman <andreysherman11@gmail.com>

* [Pg-kit] Fix malformed array literal error on indexes (#2884)

* Fix malformed array literal error on indexes

The main issue is the expression text to array conversion happening in the edited line.
Commas in an expression become delimiters and split the expression up prematurely.
Some special characters like double quotes can cause the malformed array literal errors.

The postgres function pg_get_indexdef does what the snippet above is trying to do, but safely.

* Add index introspect test

* Update pg.test.ts

Remove .only in basic index test

---------

Co-authored-by: Andrii Sherman <andreysherman11@gmail.com>

* add infer enum type (#2552)

* Update how enums work in pg and mysql

* Remove duplicated exports, add related test (#4413)

* Remove duplicated exports, add related test

Fixes #4079

* Fix test

* chore: updating esbuild version in drizzle-kit (#4046)

* chore: updating esbuild version in drizzle-kit

* Fix build errors

---------

Co-authored-by: AndriiSherman <andreysherman11@gmail.com>

* Drizzle-kit: fix recreate enums + altering data type to enums, from enums in pg (#4330)

Co-authored-by: AndriiSherman <andreysherman11@gmail.com>

* Skip test and try latest gel

* Add release notes

---------

Co-authored-by: James <5511220+Zamiell@users.noreply.github.com>
Co-authored-by: Ayrton <git@ayrton.be>
Co-authored-by: April Mintac Pineda <21032419+aprilmintacpineda@users.noreply.github.com>
Co-authored-by: Matthew Ary <157217+MatthewAry@users.noreply.github.com>
Co-authored-by: Kratious <Kratious@users.noreply.github.com>
Co-authored-by: Toti Muñoz <64804554+totigm@users.noreply.github.com>
Co-authored-by: Dan Kochetov <danil.kochetov@gmail.com>
Co-authored-by: Paul Marsicovetere <71470776+paulmarsicloud@users.noreply.github.com>
Co-authored-by: Aleksandr Sherman <102579553+AleksandrSherman@users.noreply.github.com>
AndriiSherman added a commit that referenced this pull request Apr 23, 2025
* DPRINT!!!

* Updates to neon-http for `@neondatabase/serverless@1.0.0`, when released (#4237)

* Updates for @neondatabase/serverless@1.0.0 compatibility

* Clearer comments

* Linting

* Add release notes

* Shard integration tests, parallelise attw

* Thank you pnpm 10

* Split int tests by provider

* Update Neon config, fix bash

* Restore webSocketConstructor

* Use Docker for Neon

* Use docker-compose for Neon

* Fix env var

* Run Neon HTTP tests on real DB

* Downgrade attw

* Use Bun for attw

* Split unit tests

* Fix command

* Update latest pipeline

* Fix test

* Remove await

* Split relational tests

* Disable singlestore-relational

* Remove gel-relational

* Various fixes, features bundled for v0.41.0 (#4293)

* Various fixes, features bundled for v0.41.0

* Fixed broken test case

* D1 Buffer mapping fix, tests fix

* Disabled type parsers for `neon-http` driver

* [drizzle-kit] push to d1-http failed (#4268)

* drizzle-kit and push to d1-http failed
There are two reasons:
- d1-http don't support transactions with db.run("begin/commit/rollback")
- introspections run against some CF-D1 internal tables and fails later.
  that could mitigated with a right tablesFilter: ['!_cf_KV'].
  There was a incomplete mitigation in place which now includes _cf_KV
  tables.

* chore: there are more _cf_ prefixed tables

* fix: Add escaping to sqlite pull queries

* should we pass-with-no-tests ??

* D P R I N T

* Add ci vitest config

* Bump kit, added release notes

---------

Co-authored-by: Roman <nabukhotnyiroman@gmail.com>
Co-authored-by: AndriiSherman <andreysherman11@gmail.com>

* Add Arktype validation (via `drizzle-arktype` package) (#4314)

* Export (almost) everything from validator packages

* Support infinitely recursive types in JSON columns

* Fix import

* Format

* Init drizzle-arktype

* Finish drizzle-arktype

* Sync fixes from other branch

* Update READMEs

* Update README

* Type optimizations and better debugging for tests

* Add CI/CD updates for arktype package

* Bump arktype

* bump to 0.1.2

* Update turbo config

* Bump all validator packages versions

---------

Co-authored-by: Andrii Sherman <andreysherman11@gmail.com>
Co-authored-by: David Blass <david@arktype.io>

* feat: add lua scripts for get tag and onMutate

* Added hexp + peerDeps

* fix: use hexpire option in hexpire

* fix: add hset back

* dprint

* Update pnpm lock

* fix: getByTag script

* fix: exit getByTag script if compositeTable doesn't exist

* Add all test cases for pg

* Add mysql cache functions

* 0.41 (#4416)

* fix: incorrect types for inArray (#1774)

Co-authored-by: Andrii Sherman <andreysherman11@gmail.com>

* Pass row type parameter to @planetscale/database's execute  (#1852)

* Update session.ts

No need to cast, you can just pass a type parameter

* Update package.json

---------

Co-authored-by: AndriiSherman <andreysherman11@gmail.com>

* Don't enforce type restrictions on mysqlEnum and pgEnum to be non-empty arrays (#2429)

* Removed type restriction on non-empty arrays for mysqEnum

* Removed type restriction on non-empty arrays for pgEnum

* check values argument is not an empty array for pgEnum

* fix: typings

* Add type tests

---------

Co-authored-by: AndriiSherman <andreysherman11@gmail.com>

* Export mapColumnToSchema function (#2495)


Co-authored-by: Andrii Sherman <andreysherman11@gmail.com>

* [Pg-kit] Fix malformed array literal error on indexes (#2884)

* Fix malformed array literal error on indexes

The main issue is the expression text to array conversion happening in the edited line.
Commas in an expression become delimiters and split the expression up prematurely.
Some special characters like double quotes can cause the malformed array literal errors.

The postgres function pg_get_indexdef does what the snippet above is trying to do, but safely.

* Add index introspect test

* Update pg.test.ts

Remove .only in basic index test

---------

Co-authored-by: Andrii Sherman <andreysherman11@gmail.com>

* add infer enum type (#2552)

* Update how enums work in pg and mysql

* Remove duplicated exports, add related test (#4413)

* Remove duplicated exports, add related test

Fixes #4079

* Fix test

* chore: updating esbuild version in drizzle-kit (#4046)

* chore: updating esbuild version in drizzle-kit

* Fix build errors

---------

Co-authored-by: AndriiSherman <andreysherman11@gmail.com>

* Drizzle-kit: fix recreate enums + altering data type to enums, from enums in pg (#4330)

Co-authored-by: AndriiSherman <andreysherman11@gmail.com>

* Skip test and try latest gel

* Add release notes

---------

Co-authored-by: James <5511220+Zamiell@users.noreply.github.com>
Co-authored-by: Ayrton <git@ayrton.be>
Co-authored-by: April Mintac Pineda <21032419+aprilmintacpineda@users.noreply.github.com>
Co-authored-by: Matthew Ary <157217+MatthewAry@users.noreply.github.com>
Co-authored-by: Kratious <Kratious@users.noreply.github.com>
Co-authored-by: Toti Muñoz <64804554+totigm@users.noreply.github.com>
Co-authored-by: Dan Kochetov <danil.kochetov@gmail.com>
Co-authored-by: Paul Marsicovetere <71470776+paulmarsicloud@users.noreply.github.com>
Co-authored-by: Aleksandr Sherman <102579553+AleksandrSherman@users.noreply.github.com>

* Update CI/CD to 22.04

* add planetscale cache tests

* Add sqlite cache

* Add singlestore db

* Add gel cache

* Fix build errors

* Fix imports

* fix pg default schema

---------

Co-authored-by: Andrii Sherman <andreysherman11@gmail.com>
Co-authored-by: George MacKerron <george@mackerron.co.uk>
Co-authored-by: Dan Kochetov <danil.kochetov@gmail.com>
Co-authored-by: Sergey Reka <71607800+Sukairo-02@users.noreply.github.com>
Co-authored-by: Meno Abels <meno.abels@adviser.com>
Co-authored-by: Roman <nabukhotnyiroman@gmail.com>
Co-authored-by: L-Mario564 <ka.mario564@gmail.com>
Co-authored-by: David Blass <david@arktype.io>
Co-authored-by: James <5511220+Zamiell@users.noreply.github.com>
Co-authored-by: Ayrton <git@ayrton.be>
Co-authored-by: April Mintac Pineda <21032419+aprilmintacpineda@users.noreply.github.com>
Co-authored-by: Matthew Ary <157217+MatthewAry@users.noreply.github.com>
Co-authored-by: Kratious <Kratious@users.noreply.github.com>
Co-authored-by: Toti Muñoz <64804554+totigm@users.noreply.github.com>
Co-authored-by: Paul Marsicovetere <71470776+paulmarsicloud@users.noreply.github.com>
Co-authored-by: Aleksandr Sherman <102579553+AleksandrSherman@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

goog-vulnz flags CVE-2024-24790 in esbuild 0.19.7
4 participants