You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Fixes Dependabot alert 437 by updating the memory example's transitive deepmerge-ts dependency from 7.1.5 to 8.0.2. A version-scoped pnpm override targets @prisma/config@7.10.0; remove it when Prisma adopts a patched release. Only the workspace configuration and lockfile change.
The update addresses the published GHSA-ggr8-5vv4-36mx advisory. Prisma continues to use the supported deepmerge export for its existing plain-object configuration. Please include maintainer security review of the dependency override.
Test plan
Frozen install, build, all workspace type checks, distribution checks, lint, and formatting passed using the verification skill's complete command sequence, run sequentially.
All 6,931 repository tests passed, including Docker coverage against local Colima.
All 15 Prisma tests passed; configuration loading, schema validation, client generation, and SQLite behavior were verified.
Two consecutive adversarial review rounds, each with two fresh independent reviewers, found no blocking issues. Commit hooks preserved the reviewed files; the secret scan found no secrets.
Verification used a mounted temporary directory, RUST_LOG=debug, and suppression of the environment-injected UNDICI-EHPA warning. No tests were skipped to obtain these results.
Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.
This PR includes no changesets
When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fixes Dependabot alert 437 by updating the memory example's transitive
deepmerge-tsdependency from 7.1.5 to 8.0.2. A version-scoped pnpm override targets@prisma/config@7.10.0; remove it when Prisma adopts a patched release. Only the workspace configuration and lockfile change.The update addresses the published GHSA-ggr8-5vv4-36mx advisory. Prisma continues to use the supported
deepmergeexport for its existing plain-object configuration. Please include maintainer security review of the dependency override.Test plan
RUST_LOG=debug, and suppression of the environment-injectedUNDICI-EHPAwarning. No tests were skipped to obtain these results.Issue number
Dependabot alert 437
Checks
pnpm testand workspace example/type checks passed.