Repository navigation
fix(deps): update all non-major npm dependencies - #166
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/all-non-major-npm-dependencies
branch
from
June 1, 2026 18:35
87514e2 to
3007811
Compare
renovate
Bot
force-pushed
the
renovate/all-non-major-npm-dependencies
branch
4 times, most recently
from
June 8, 2026 23:12
5af791f to
133f719
Compare
renovate
Bot
force-pushed
the
renovate/all-non-major-npm-dependencies
branch
4 times, most recently
from
June 16, 2026 02:39
51998a2 to
b35aa85
Compare
renovate
Bot
force-pushed
the
renovate/all-non-major-npm-dependencies
branch
3 times, most recently
from
June 22, 2026 22:01
391ea4c to
8082856
Compare
renovate
Bot
force-pushed
the
renovate/all-non-major-npm-dependencies
branch
7 times, most recently
from
July 1, 2026 23:46
02a8080 to
8c1dc16
Compare
renovate
Bot
force-pushed
the
renovate/all-non-major-npm-dependencies
branch
5 times, most recently
from
July 13, 2026 18:40
8894cd7 to
81c2789
Compare
renovate
Bot
force-pushed
the
renovate/all-non-major-npm-dependencies
branch
from
July 20, 2026 22:06
81c2789 to
64d9fff
Compare
Contributor
Author
|
renovate
Bot
force-pushed
the
renovate/all-non-major-npm-dependencies
branch
2 times, most recently
from
July 21, 2026 11:43
d3abf4a to
e86b7fb
Compare
renovate
Bot
force-pushed
the
renovate/all-non-major-npm-dependencies
branch
4 times, most recently
from
August 10, 2026 19:13
8241d1a to
f932f65
Compare
renovate
Bot
force-pushed
the
renovate/all-non-major-npm-dependencies
branch
3 times, most recently
from
August 17, 2026 22:58
ab41e30 to
7b297a8
Compare
renovate
Bot
force-pushed
the
renovate/all-non-major-npm-dependencies
branch
3 times, most recently
from
August 25, 2026 17:11
f3f1657 to
ecc7244
Compare
renovate
Bot
force-pushed
the
renovate/all-non-major-npm-dependencies
branch
3 times, most recently
from
September 3, 2026 11:33
0702dcc to
10791bf
Compare
renovate
Bot
force-pushed
the
renovate/all-non-major-npm-dependencies
branch
3 times, most recently
from
September 11, 2026 21:39
29644e0 to
9ca724b
Compare
renovate
Bot
force-pushed
the
renovate/all-non-major-npm-dependencies
branch
5 times, most recently
from
September 21, 2026 22:04
0e05e07 to
2f42176
Compare
renovate
Bot
force-pushed
the
renovate/all-non-major-npm-dependencies
branch
4 times, most recently
from
September 29, 2026 12:08
063bac2 to
ab53ba9
Compare
renovate
Bot
force-pushed
the
renovate/all-non-major-npm-dependencies
branch
3 times, most recently
from
October 5, 2026 21:17
b65f508 to
4a1cb67
Compare
renovate
Bot
force-pushed
the
renovate/all-non-major-npm-dependencies
branch
from
October 7, 2026 01:03
4a1cb67 to
949bf22
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
0.34.3→0.41.37.8.0→7.10.07.8.0→7.10.022.19.19→22.20.58.20.0→8.23.119.2.15→19.3.019.2.3→19.3.08.60.0→8.71.18.60.0→8.71.19.39.4→9.39.516.2.6→16.4.05.5.5→5.5.616.2.6→16.4.04.24.14→4.24.158.21.0→8.23.13.8.3→3.9.97.8.0→7.10.019.2.6→19.3.019.2.6→19.3.02.4.1→2.5.1Release Notes
nextauthjs/next-auth (@auth/core)
v0.41.3Compare Source
Bugfixes
getToken()now returnsnullinstead of throwing when theAuthorizationheader contains a malformed Bearer valuestate,nonce, and PKCE check cookies are now bound to the provider that created them and are rejected when a different provider handles the callback@bypassOther
v0.41.2Compare Source
Bugfixes
Other
v0.41.1Compare Source
Bugfixes
nodemailer(#13305)Other
v0.41.0Compare Source
Features
745751e)Other
v0.40.0Compare Source
Features
e0168ed)Bugfixes
dd211c5)e16b07b)0adbd10)Other
22c1b8b)v0.39.1Compare Source
Bugfixes
4155eee)Other
v0.39.0Compare Source
Features
c1f89ea)a05451d)Other
v0.38.0Compare Source
Features
af2ccea)14dfaf3)dcaaf1a)6a72f3d)517c877)3ec0684)Bugfixes
parseProviders()whenproviderIdnot found in config (#12438) (80a2c14)b0f1538)7772375)Other
5a2f595)6aefefd)e231168)9411046)2f86dfd)format(#12302) (7c20f02)507aadd)2465101)9dbc9ba)v0.37.4Compare Source
Bugfixes
cookieuntil it has an ESM build (#12248) (a150f1e)c650d0c)Other
v0.37.3Compare Source
Bugfixes
d6d8d4f)cookiepackage (#12177) (39250e3)2e78fa2)39b7d9a)8034cfe)Other
b3e4369)a88c7a3)accountas optional in callbacks (#12017)v0.37.2Compare Source
Bugfixes
be6d169)2810f6b)v0.37.1Compare Source
Bugfixes
issuer(#11980) (e981e4d)v0.37.0Compare Source
Features
2d67f11)v0.36.0Compare Source
Features
fetch(#11975) (fedff04)Bugfixes
isNewUserduring account linking & user creationOther
917cb2c)isDate(#11953)v0.35.3Compare Source
Bugfixes
f6b7228)cce637c)v0.35.2Compare Source
Bugfixes
3e8a648)identifier(54ba689)v0.35.1Compare Source
Bugfixes
3744f56)181c6b8)4b784c5)96f49e0)v0.35.0Compare Source
Features
1073030)edfa5e5)120f550)cfcb221)e65759b)ed6b48c)208410d)d1dfb52)51c0bbd)Bugfixes
b080a49)4a8ab0f)abb4dcd)69c0b58)9b8614f)a681cba)0410ae5)a5dacb3)bbc6710)270fc6c)5c721d7)0d73205)bbd3af6)GetTokenParamstype definition to makesaltoptional (#11572) (1279593)extendsproperty in packages configuration (#11666) (e6eaa95)Other
8c52012)prisma/prisma (@prisma/adapter-pg)
v7.10.0Compare Source
Prisma ORM 7.10.0
Prisma ORM 7.10.0 introduces a compatibility package for running Prisma 7 alongside newer Prisma versions, secures Prisma Studio's local server, and includes fixes across Prisma Client and the PostgreSQL, MariaDB, Neon, SQLite, and Prisma Postgres Serverless adapters.
Highlights
Run Prisma 7 alongside Prisma 8
This release introduces
@prisma/prisma7, a compatibility package that lets you retain a matching Prisma 7 CLI and configuration while installing Prisma 8 in the same project.Once 7.10.0 is released, a side-by-side installation can use:
Use
prismafor the directly installed Prisma 8 CLI andprisma7for Prisma 7:Prisma 7 now prefers version-specific configuration files, allowing its configuration to coexist with Prisma 8's
prisma.config.*files:Without an explicit
--configoption, Prisma 7 searches for:prisma7.config.*files..config/prisma7.*files.prisma.config.*files as a backwards-compatible fallback.The supported extensions are
.js,.ts,.mjs,.cjs,.mts, and.cts. An explicit config path always takes precedence:New projects initialized by the Prisma 7 CLI use
prisma7.config.ts. Existing projects containing onlyprisma.config.*continue to work without migration or additional warnings. If aprisma7.config.*file exists but cannot be loaded, Prisma reports the error rather than silently falling back to another configuration.The
prisma7identity is carried through CLI help, version output, shell completion, initialization, migration, database, and generation guidance. Stable Prisma concepts such asschema.prisma, Prisma Migrate,@prisma/client, andPRISMA_*environment variables remain unchanged.Together, the separate executable and configuration namespace make it possible to operate Prisma 7 and Prisma 8 side by side without command or config-file collisions.
#29949, #29969, #29994, #30000, #30002, #30020
Prisma Studio security hardening
Prisma Studio's local HTTP server now:
127.0.0.1instead of all network interfaces.localhostor127.0.0.1Studio URL.This prevents network clients or malicious websites from accessing Studio's database endpoints while Studio is running.
#29890
Prisma Client
P2002errors from nested writes someta.modelNameidentifies the model where the unique constraint violation occurred, including models using@@mapand@@schema. #29628findUniqueOrThrow()calls so every missing record rejects withP2025; later misses no longer resolve toundefined. #29654$disconnect(), including transactions whose driver-level startup is still in progress. #28768selectorinclude. #29683DateandUint8Arrayvalues created in other JavaScript realms, such as iframes, jsdom, and Node.jsvmcontexts. #29177Datevalues passed to$queryRawor$executeRawnow throwPrismaClientValidationErrorinstead of a generic error. #29718moduleFormatinference for theprisma-clientgenerator in TypeScript projects usingmodule: "node16"or"nodenext". Generated output now follows the nearestpackage.jsontype, defaulting to CommonJS when absent. #29712Bytesvalues now own standaloneArrayBuffers rather than exposing unrelated contents from Node.js's sharedBufferpool. This applies to both regular and raw query results. #29701Client extensions and observability
Result-extension
computecallbacks now receive the current model name as a typed second argument:The model name is also preserved when multiple extensions compose the same computed field. #29782
Improved OpenTelemetry context for remotely executed queries:
$on('query')callbacks run within the matchingdb_queryspan.#28892
Driver adapters
MariaDB
@prisma/adapter-mariadbnow accepts an existingmariadbpool. External pools remain caller-owned unlessdisposeExternalPool: trueis supplied. #27992release()and transaction-specific listeners are removed before reuse. #29612mysql://andmariadb://connection strings. #29026PostgreSQL, Neon, and Prisma Postgres Serverless
40P01are now reported asP2034transaction write conflicts. #29717RESTRICTviolations using SQLSTATE23001are now reported asP2003, preserving an available field or constraint name. #29554@prisma/adapter-pgnow preserves database constraint names when reporting unique constraint violations throughP2002. #29587P2002, falling back to parsed field names when no constraint name is available. #29801BytesandDateTime. #29747SQLite
@prisma/adapter-better-sqlite3now converts previously unhandled SQLite result codes into typed database errors instead of exposing raw driver errors.SQLITE_BUSYfamily is now mapped to socket timeout errors, with numeric extended result codes preserved where available.#29794
CLI and Migrate
prisma generatecan now offer to install Prisma's agent skills. The opt-in prompt:--no-hintsis used or Prisma skills are already installed.#29690
A globally installed CLI now warns during
prisma generatewhen its version differs from the project's localprismaor@prisma/client, and recommends running the local CLI. The check is best-effort and does not fail generation. #29593prisma versionandprisma version --jsonnow include the resolved Prisma CLI package path, making global-versus-local installation issues easier to diagnose. #29573Empty or generator-only schema files now report
Schema must contain a datasource blockfromdb pull,db push, andmigrate dev, rather than reaching the schema engine and potentially producing inconsistent errors. #29657CLI commands now tolerate corrupt, unreadable, or unwritable command-state files. Invalid state is reinitialized, writes are atomic, and persistence failures fall back to in-memory state. #29609
Studio now recognizes semicolon-delimited
sqlserver://connection strings before reporting the existing explicit message that SQL Server is not supported by Studio. #29623The AI-agent safety checkpoint now also covers interactive
prisma db pushconfirmations involving data-loss warnings, rather than only invocations using--accept-data-loss. #29793Performance and reliability
Dependencies
fast-uridependency to a patched release addressing production audit advisories affecting versions through3.1.3. #29758v7.9.1Compare Source
Today, we're issuing a patch release to resolve a security advisory in a transitive dependency of Prisma CLI (via
@prisma/dev).This fixes #29780.
It does not actually affect
@prisma/devor Prisma CLI so no urgent action is required, but it is recommended to upgrade nevertheless to avoid false positives from security scanners.v7.9.0Compare Source
Today, we are excited to share the
7.9.0stable release 🎉🌟 Star this repo for notifications about new releases, bug fixes & features — or follow us on X!
Highlights
ORM
Tab completions for the Prisma CLI
Typing out CLI commands from memory is now optional. Prisma ships shell tab completions for
bash,zsh,fish, and PowerShell, covering commands, subcommands, options, flags, and even option values.Setting it up. Most projects run Prisma through a package manager, so completions are enabled through
@bomb.sh/tab's package-manager integration — install it once, then source the completion for your package manager and shell:@bomb.sh/tabdelegates to any locally-installed CLI that ships completions, sopnpm prisma <TAB>,pnpm exec prisma <TAB>,yarn prisma <TAB>, andbun x prisma <TAB>all complete Prisma's commands, options, and values — no per-project setup. (npxandbunxdon't support completion themselves; usenpm execandbun x.)If instead you have Prisma installed globally on your
PATH, source its own completion directly:source <(prisma complete zsh)(or thebash/fish/powershellvariant).This is built on
@bomb.sh/tab, the same completion library that powers other CLIs in the ecosystem — including Cloudflare, Nuxt, and Vitest — so the package-manager completions you enable for Prisma work for those tools too. A wonderful community contribution from @AmirSa12 (#28351) — thank you!prisma.mp4
Prisma ORM, ready for AI agents
Coding agents are now a first-class audience for Prisma, and 7.9.0 brings the first wave of work to make Prisma projects safe and productive for them to work in.
Agent skills installed with
prisma init(#29689)prisma initnow installs the prisma/skills catalog into freshly scaffolded projects. Agents such as Claude Code, Cursor, Codex, and Windsurf start out with current, version-relevant Prisma knowledge instead of relying on whatever happened to be in their training data. The install is best-effort and never blocks scaffolding; opt out at any time with--no-skills.A safer default around destructive commands (#29684, #29691, #29713)
Prisma's AI safety checkpoint refuses to run destructive commands when it detects that an AI agent is at the keyboard, unless the user has given explicit consent. In this release we:
AI_AGENT/AGENTconventions so future agents are caught without a code change.db push --accept-data-loss, which previously bypassed the checkpoint even though it can drop data.migrate-resettool from theprisma mcpserver entirely — resetting a database drops it, and that is not an operation an agent should be handed as a first-class tool. An agent that needs a reset must run the CLI, where the checkpoint applies.Bug Fixes
Many of the fixes below are community contributions — thank you to everyone who reported and fixed these!
Prisma Client
OmitOptsgeneric default letstscreuse cached type instantiations again, bringing type-checking on large schemas back from minutes to seconds (#29592, from @nfl1ryxditimo12).XORtype helper now rejects primitive values such asdata: 5, which were previously accepted at compile time even though the runtime rejected them (#29735, from @kyungseopk1m).$queryRawand$executeRawnow fail fast with a clear validation error when passed an invalidDate, instead of silently serializing it asnulland corrupting the value sent to the database (#29697, from @jibin7jose).///documentation comment that contains a*/sequence; the comment terminator is now escaped when doc comments are emitted, in both the TypeScript and JavaScript generators (#29736, from @kyungseopk1m).PrismaClientconstructor; both now include a copy-pasteable example and a link to the driver adapters docs (#29624).P2039(PrismaClientKnownRequestError) carrying the original code and message, instead of an opaque failure, which keeps schema-drift-style problems debuggable (#29512).prisma-client-jsgenerator no longer emits a strayundefinedstatement when generating from a schema that declares only enums or types and no models (#29738, from @kyungseopk1m).maxWait) while it is still starting: the discarded transaction now sends an explicitROLLBACKbefore the connection is returned to the pool, instead of releasing it mid-transaction. Previously, on adapters like@prisma/adapter-pgand@prisma/adapter-neon, the next query to reuse that connection could fail withthere is already a transaction in progress— or silently commit the leaked transaction's work (#29727, from @lazerg).CLI
prisma validate(and other schema-loading commands) no longer hangs forever on a multi-file schema whose directories contain a symlink cycle, and no longer reports the same file twice when a directory is reachable under two spellings (e.g./tmp→/private/tmpon macOS) (#29740, from @kyungseopk1m).%APPDATA%\Prisma) instead of acwd-relativenode_modules\.cache, which eliminated duplicate cache directories and the bloated Serverless/Docker bundles they caused (#29730, from @santichausis; closes #22574, #6670, #11577).Driver Adapters
Bytescolumn no longer emits Node.js'DEP0005deprecation warning, thanks to an upstreampostgres-byteabump (#29538, from @kolia-zamnius).ColumnNotFound(P2022) errors now parse both quoted and unquoted PostgreSQL column names, including identifiers containing spaces, matching the fix previously applied toadapter-pg(#29737, from @kyungseopk1m).Bytes?(@db.VarBinary) field tonullno longer fails with an implicit-conversion error; the adapter now sends the parameter typed asVarBinaryinstead of letting SQL Server default it tonvarchar(#29630, from @AnupamKumar-1).Schema Engine
prisma migrate statusnow reports a rolled-back migration that still exists on disk as unapplied, instead of incorrectly treating the schema as up to date (prisma/prisma-engines#5817, from @goutamadwant).ALTER TABLEstatements on PostgreSQL, avoiding a database error when a single table has multiple changes in one migration (prisma/prisma-engines#4906, from @eruditmorina).Security
honosecurity advisories at their source:@prisma/devwas updated to a version that no longer depends onhonoConfiguration
📅 Schedule: (in timezone Europe/Berlin)
* 18-21 * * 5)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.