parse-server icon indicating copy to clipboard operation
parse-server copied to clipboard

refactor: Upgrade pg-promise from 11.14.0 to 11.15.0

Open parseplatformorg opened this issue 4 months ago β€’ 5 comments

snyk-top-banner

Snyk has created this PR to upgrade pg-promise from 11.14.0 to 11.15.0.

:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 1 version ahead of your current version.

  • The recommended version was released a month ago.

Release notes
Package name: pg-promise
  • 11.15.0 - 2025-07-06
    • Updated underlying pg driver + pg-query-stream to their latest versions
    • Bumped minimum supported NodeJS version to 16
  • 11.14.0 - 2025-06-04
    • Extending EventContext with property queryFilePath, as per PR-951
    • Added NodeJS v24 compatibility badge.
    • Dependencies updated.
from pg-promise GitHub release notes

[!IMPORTANT]

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

Summary by CodeRabbit

  • Chores
    • Updated the "pg-promise" dependency to version 11.15.0.

parseplatformorg avatar Aug 05 '25 09:08 parseplatformorg

I will reformat the title to use the proper commit message syntax.

πŸš€ Thanks for opening this pull request!

πŸ“ Walkthrough

Walkthrough

The pg-promise dependency version in package.json was updated from 11.14.0 to 11.15.0. No other dependencies or configurations were modified.

Changes

Cohort / File(s) Change Summary
Dependency Version Update
package.json
Bumped "pg-promise" dependency from 11.14.0 to 11.15.0.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~2 minutes

[!NOTE]

⚑️ Unit Test Generation is now available in beta!

Learn more here, or try it out under "Finishing Touches" below.


πŸ“œ Recent review details

Configuration used: CodeRabbit UI Review profile: CHILL Plan: Pro

πŸ“₯ Commits

Reviewing files that changed from the base of the PR and between 587abdd45fed1c782209b32e8b5d1a0aef09bdf0 and aba28b9e2bb9d2986562a27418ee3b7d8cd2e280.

β›” Files ignored due to path filters (1)
  • package-lock.json is excluded by !**/package-lock.json
πŸ“’ Files selected for processing (1)
  • package.json (1 hunks)
πŸ”‡ Additional comments (2)
package.json (2)

55-55: Dependency bump looks safe and matches current Node engine constraints
[email protected] only raises the minimum Node requirement to β‰₯16, while the project already enforces β‰₯18 (Line 149), so no engine-range conflict.


55-55: Commit lockfile & manually verify Postgres tests
I ran the Postgres-only test suite locally but saw no test output, so I couldn’t confirm there are no regressions with [email protected]. To ensure driver-level changes haven’t broken anything:

  • Commit the regenerated lockfile (package-lock.json or pnpm-lock.yaml) so CI stays reproducible.
  • Verify that the Postgres matrix passes in CI (npm run test:postgres:testonly) or locally and share the logs.

Quick sanity check you can run locally:

npm ci
npm run test:postgres:testonly

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❀️ Share
πŸͺ§ Tips

Chat

There are 3 ways to chat with CodeRabbit:

  • Review comments: Directly reply to a review comment made by CodeRabbit. Example:
    • I pushed a fix in commit <commit_id>, please review it.
    • Explain this complex logic.
    • Open a follow-up GitHub issue for this discussion.
  • Files and specific lines of code (under the "Files changed" tab): Tag @coderabbitai in a new review comment at the desired location with your query. Examples:
    • @coderabbitai explain this code block.
  • PR comments: Tag @coderabbitai in a new PR comment to ask questions about the PR branch. For the best results, please provide a very specific query, as very limited context is provided in this mode. Examples:
    • @coderabbitai gather interesting stats about this repository and render them as a table. Additionally, render a pie chart showing the language distribution in the codebase.
    • @coderabbitai read src/utils.ts and explain its main purpose.
    • @coderabbitai read the files in the src/scheduler package and generate a class diagram using mermaid and a README in the markdown format.

Support

Need help? Create a ticket on our support page for assistance with any issues or questions.

CodeRabbit Commands (Invoked using PR comments)

  • @coderabbitai pause to pause the reviews on a PR.
  • @coderabbitai resume to resume the paused reviews.
  • @coderabbitai review to trigger an incremental review. This is useful when automatic reviews are disabled for the repository.
  • @coderabbitai full review to do a full review from scratch and review all the files again.
  • @coderabbitai summary to regenerate the summary of the PR.
  • @coderabbitai generate sequence diagram to generate a sequence diagram of the changes in this PR.
  • @coderabbitai generate unit tests to generate unit tests for this PR.
  • @coderabbitai resolve resolve all the CodeRabbit review comments.
  • @coderabbitai configuration to show the current CodeRabbit configuration for the repository.
  • @coderabbitai help to get help.

Other keywords and placeholders

  • Add @coderabbitai ignore anywhere in the PR description to prevent this PR from being reviewed.
  • Add @coderabbitai summary to generate the high-level summary at a specific location in the PR description.
  • Add @coderabbitai anywhere in the PR title to generate the title automatically.

CodeRabbit Configuration File (.coderabbit.yaml)

  • You can programmatically configure CodeRabbit by adding a .coderabbit.yaml file to the root of your repository.
  • Please see the configuration documentation for more information.
  • If your editor has YAML language server enabled, you can add the path at the top of this file to enable auto-completion and validation: # yaml-language-server: $schema=https://coderabbit.ai/integrations/schema.v2.json

Documentation and Community

  • Visit our Documentation for detailed information on how to use CodeRabbit.
  • Join our Discord Community to get help, request features, and share feedback.
  • Follow us on X/Twitter for updates and announcements.

coderabbitai[bot] avatar Aug 05 '25 09:08 coderabbitai[bot]

:tada: Snyk checks have passed. No issues have been found so far.

:white_check_mark: security/snyk check is complete. No issues have been found. (View Details)

parseplatformorg avatar Aug 05 '25 09:08 parseplatformorg

Codecov Report

:white_check_mark: All modified and coverable lines are covered by tests. :white_check_mark: Project coverage is 93.01%. Comparing base (587abdd) to head (aba28b9).

Additional details and impacted files
@@           Coverage Diff           @@
##            alpha    #9838   +/-   ##
=======================================
  Coverage   93.01%   93.01%           
=======================================
  Files         187      187           
  Lines       15096    15096           
  Branches      174      174           
=======================================
  Hits        14041    14041           
  Misses       1043     1043           
  Partials       12       12           

:umbrella: View full report in Codecov by Sentry.
:loudspeaker: Have feedback on the report? Share it here.

:rocket: New features to boost your workflow:
  • :snowflake: Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • :package: JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

codecov[bot] avatar Aug 05 '25 09:08 codecov[bot]