Skip to content

Bump knex from 3.1.0 to 3.3.0 - #12

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/knex-3.3.0
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/knex-3.3.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 15, 2026

Copy link
Copy Markdown

Bumps knex from 3.1.0 to 3.3.0.

Release notes

Sourced from knex's releases.

3.3.0

New features

Bug fixes

Misc

New Contributors

Full Changelog: knex/knex@3.2.10...3.3.0

3.2.10

Bug fixes

... (truncated)

Changelog

Sourced from knex's changelog.

3.3.0 - 26 June, 2026

New features

  • feat: add support for returning in mariadb #4572
  • feat: mariadb driver support #6415
  • Fixes _setNullableState not respecting schema #6025
  • feat: add connectionPool option for bringing an external pool #6414
  • Added knex.migrate.to and knex.migrate.before #6420
  • feat: set error.cause for tarn acquire connection error #5681

Bug fixes

  • Fix FOR UPDATE OF with explicit schema #5791
  • Fix sqlite conditional insert/merge when inserting multiple rows #6185
  • Fix: Stream postProcessResponse error is not catchable with .on('error') #6033
  • fix(pg): preserve updateFrom binding order #6454
  • fix: #6451, support token-credential in mssql auth #6465
  • fix(types): #6452 - .where type regression for invalid types #6463
  • fix: #6460 unhandled error on connection timeout with stream #6462
  • fix: #6455, correctly state tedious as dependency needed for mssql #6464
  • fix(pg,mssql): preserve binding order in delete and update queries #6438

Misc

  • chore: bump tarn@3.1.0 #6492
  • micro-optimization in wrappingFormatter #6456
  • cleanup flake in the cancellation tests #6486
  • Update docs: timeout section #6471
  • ci: make npm install resilient to transient network failures #6468
  • Update homepage urls #6450
  • chore: add mariadb to docker-compose #6466
  • chore: set codecov to default coverage provider #6448

3.2.10 - 2 May, 2026

Bug fixes

  • fix: bump lodash to ^4.18.1, close #6433 #6446
  • Fix: Properly Escape Aliases in Analytic Functions #6392

Misc

  • chore: auto-update the docs' knex version on publish #6447
  • chore: skip re-running tests on automated release commit #6443
  • chore: sync docker images we use to ghcr #6445
  • chore: fixes for release-drafter workflow #6442
  • chore: new publish/release workflow #6441
  • docs: Update changelog for version 3.2.9 #6440
  • docs: sync website changelog from 3.0.0 to 3.2.8 #6426

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for knex since your current version.


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [knex](https://github.com/knex/knex) from 3.1.0 to 3.3.0.
- [Release notes](https://github.com/knex/knex/releases)
- [Changelog](https://github.com/knex/knex/blob/master/CHANGELOG.md)
- [Commits](knex/knex@3.1.0...3.3.0)

---
updated-dependencies:
- dependency-name: knex
  dependency-version: 3.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 15, 2026
suciudan added a commit that referenced this pull request Sep 15, 2026
Resolve the five pending dependency updates and remove the remaining esbuild security alert. The React plugin update failed because version 6 requires Vite 8 while the dashboard used Vite 7.

- Upgrade Vite to 8.3.0 with Vitest 5.0.0, React plugin 6.1.1, and Testing Library React 16.3.3. Group future updates to this toolchain in Dependabot.
- Update Knex to 3.3.0 across its three workspaces and Nodemailer to the patched 10.0.x line (lockfile: 10.0.10).
- Scope an esbuild 0.25.12 resolution to the legacy Drizzle loader, removing GHSA-67mh-4wv8-2f99. The current Payload/Drizzle dependency tree still includes that loader. Add CI regression checks for TypeScript transforms, relative configuration imports, and the real OTP template through a stubbed SES transport.
- Run the full dependency audit in CI without severity exclusions and document the override's compatibility risk and removal conditions.

Validation on Node 24.21.0 / Yarn 4.9.2: immutable install; full audit with no advisories; API/SDK unit suites; 112 dashboard integration tests on disposable SQLite; dashboard types and lint (one pre-existing warning); both production builds; five new dependency compatibility tests; and a disposable MySQL check covering schema creation, insert, lookup, and transaction rollback passed. No UI or application logic changes. No email, production requests, deployments, or package publishing.

Replaces #11, #12, #13, #14, and #15 after this validated replacement merges. Addresses Dependabot alert #1 by changing the dependency tree, without dismissing the alert.

Prepared with AI assistance. All five required hosted CI checks passed, including the full dependency audit, compatibility regressions, integration suites, and both application builds.
@suciudan

Copy link
Copy Markdown
Owner

Implemented in merged PR #16 (#16), with the Vite 8 toolchain compatibility fix and patched esbuild. All five required CI checks and the full audit passed. Closing this superseded update.

@suciudan suciudan closed this Sep 15, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 15, 2026

Copy link
Copy Markdown
Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/knex-3.3.0 branch September 15, 2026 08:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant