diff --git a/bun.lock b/bun.lock index f514e7687..8633f5cfc 100644 --- a/bun.lock +++ b/bun.lock @@ -9,7 +9,7 @@ "@google/generative-ai": "^0.24.1", "@libredb/libredb": "^0.2.2", "@monaco-editor/react": "^4.7.0", - "@platformatic/kafka": "2.11.0", + "@platformatic/kafka": "2.12.0", "@radix-ui/react-accordion": "^1.2.20", "@radix-ui/react-alert-dialog": "^1.1.23", "@radix-ui/react-aspect-ratio": "^1.1.15", @@ -55,7 +55,7 @@ "ioredis": "^5.11.1", "jose": "^6.2.12", "lucide-react": "^1.41.0", - "monaco-editor": "^0.56.0", + "monaco-editor": "^0.57.0", "mongodb": "^7.6.0", "mssql": "^12.7.0", "mysql2": "^3.24.3", @@ -123,7 +123,7 @@ "ssh2", ], "overrides": { - "adm-zip": "^0.6.0", + "adm-zip": "^0.6.1", "lodash": "^4.18.1", "tedious": "^20.0.5", }, @@ -520,25 +520,25 @@ "@nestjs/core": ["@nestjs/core@12.0.1", "", { "dependencies": { "fast-safe-stringify": "2.1.1", "iterare": "1.2.1", "path-to-regexp": "8.4.2", "tslib": "2.8.1", "uid": "2.0.2" }, "peerDependencies": { "@nestjs/common": "^12.0.0", "@nestjs/microservices": "^12.0.0", "@nestjs/platform-express": "^12.0.0", "@nestjs/websockets": "^12.0.0", "reflect-metadata": "^0.1.12 || ^0.2.0", "rxjs": "^7.1.0" }, "optionalPeers": ["@nestjs/microservices", "@nestjs/platform-express", "@nestjs/websockets"] }, "sha512-rU6tAi8vDdyzHgN0iW0J4UJvziroOqzHqzlqL7phOSPizaXVEePfv+OUOsdJEOh0Qd14mslc3udOheLrAEcZow=="], - "@next/env": ["@next/env@16.3.5", "", {}, "sha512-NWEXVDMqoEo0ktmU6u0sE2Vg0LOcsD7NnOTJNo3/fEaTfsg+F1bMIxuDmQbda4e3yTIQwVdUREF2yIuMOusKtg=="], + "@next/env": ["@next/env@16.3.6", "", {}, "sha512-x9Vblze1EbtltQYnNH38xCPWU3TVfBd1eXqA3+w9+BTpedkkdNpAaltXlGQ/nsc1+E0mVTNrtcbX3GoO09zeLQ=="], "@next/eslint-plugin-next": ["@next/eslint-plugin-next@16.3.6", "", { "dependencies": { "@eslint-community/eslint-utils": "4.9.1", "fast-glob": "3.3.1" } }, "sha512-jowwDX+7DOlDIjJLgTMxudw+k37QnWu1JkZLkSi9MaJBfDYcfhAPMKBhXL0idYzFN/AGg//axnOR4cLkHX/Rng=="], - "@next/swc-darwin-arm64": ["@next/swc-darwin-arm64@16.3.5", "", { "os": "darwin", "cpu": "arm64" }, "sha512-pMmGgETfKvElucLHtVaeiMRbp2zUbvKx7b1yGko0liBz3cw1mKSggWN/Rp/wPz8z+E1O82u3r4L1Co+ZS5hokQ=="], + "@next/swc-darwin-arm64": ["@next/swc-darwin-arm64@16.3.6", "", { "os": "darwin", "cpu": "arm64" }, "sha512-E/7GEqaUkt8mk/T8v9lAnrhzR06kdq1ZBkC12F8tAMkdIadwNp3H1KqHynDHrpcTlGCUdq/qu6vUL2aYVyYBdw=="], - "@next/swc-darwin-x64": ["@next/swc-darwin-x64@16.3.5", "", { "os": "darwin", "cpu": "x64" }, "sha512-76VaGYvf6HPa5/w12yLkE3dXTn9AfdEviI79oEL3aZoAmRLc9rWitjWqyjViVysK/ht/y9YKzFkBrUdi/wGkow=="], + "@next/swc-darwin-x64": ["@next/swc-darwin-x64@16.3.6", "", { "os": "darwin", "cpu": "x64" }, "sha512-yBE893/nDWTlaiBD1p+qgt7NUen4U5R6FXyH0s67Npq1S3E0cVSef1WIXC2xBRgQvwAvJq6DnS6Y6PrY0cy4Ew=="], - "@next/swc-linux-arm64-gnu": ["@next/swc-linux-arm64-gnu@16.3.5", "", { "os": "linux", "cpu": "arm64" }, "sha512-zKDELJ5jSQMHeO/hmXUQsAzagX4bQD4OiMi3pQ5FbUj+yK506oLVHnKA2YXMlbg1EHHqJYtyePOgByIDXD1lqw=="], + "@next/swc-linux-arm64-gnu": ["@next/swc-linux-arm64-gnu@16.3.6", "", { "os": "linux", "cpu": "arm64" }, "sha512-KJDpjBqBPYlvkivmyrp+Qys6k/7ksbqGQvRVc6ZEGfR+cjQxx+nUkJaWmNZJsmoOrqYNbaXByF8wa0lBwDhB3Q=="], - "@next/swc-linux-arm64-musl": ["@next/swc-linux-arm64-musl@16.3.5", "", { "os": "linux", "cpu": "arm64" }, "sha512-7Vql0pgzCoHagv6+FNOZoqmJqA52c6zeVbhtS/47qFozO1MSx4ms7x7GHiciY8R5CDsSMKMQjJEryoJLcsBIbA=="], + "@next/swc-linux-arm64-musl": ["@next/swc-linux-arm64-musl@16.3.6", "", { "os": "linux", "cpu": "arm64" }, "sha512-mqNg2K+hvWskSRb/QM+Ix412DvBsuSF0XV+frTSw5vmoucNnIlynFwKYew8D01bfATErMOM7Bujrf0BA5DRKFA=="], - "@next/swc-linux-x64-gnu": ["@next/swc-linux-x64-gnu@16.3.5", "", { "os": "linux", "cpu": "x64" }, "sha512-NH/xzehyHEFWE2nlcZon7TB/0+H4shfWCi7S1zka815XCOhJDYZhoeJtOYy0dh0WVRWACVXSyGNFFytoMxUhRg=="], + "@next/swc-linux-x64-gnu": ["@next/swc-linux-x64-gnu@16.3.6", "", { "os": "linux", "cpu": "x64" }, "sha512-nFncBNGAYouRHjRVaITs9beZRfhX4ssVwpnvPIAbkZVH6LtGoAVlH4bJ8Cnf9SOo9bsXgPFer/GdHtEE3JNOkw=="], - "@next/swc-linux-x64-musl": ["@next/swc-linux-x64-musl@16.3.5", "", { "os": "linux", "cpu": "x64" }, "sha512-lV4+EhWMfS8jcC+EH2nn/Cm5cn6XsgbE07bU9tMH8fCo0tNAqhyzi1b5wQ/Tn6NGFTvKDY65w3ZH95EjwBRAnQ=="], + "@next/swc-linux-x64-musl": ["@next/swc-linux-x64-musl@16.3.6", "", { "os": "linux", "cpu": "x64" }, "sha512-5Mf3cHDGR/Iz0ng2Bj3zUR3p5QS9YK3Hn2QiAfavFmyF48zwThAjpFoiTKNIcOHLYS4zEk+gzyJ/9deQ2ZB8yQ=="], - "@next/swc-win32-arm64-msvc": ["@next/swc-win32-arm64-msvc@16.3.5", "", { "os": "win32", "cpu": "arm64" }, "sha512-/wKzAREX2RF++MhicjDbg8tGn2AiBIM0+EFeTFKoUEUbW5D6amCJehd5Z5G1H5/gxNdgnwoXMcHz24H/c2tGkQ=="], + "@next/swc-win32-arm64-msvc": ["@next/swc-win32-arm64-msvc@16.3.6", "", { "os": "win32", "cpu": "arm64" }, "sha512-0jkJy0C2kbrJWTk4YLa3xk80pVBpx8FCHJym7CnUfDAXe/FWv5qT7SQJbR0KuemyxaEDlEx5WT4VQJoTW+/9Qw=="], - "@next/swc-win32-x64-msvc": ["@next/swc-win32-x64-msvc@16.3.5", "", { "os": "win32", "cpu": "x64" }, "sha512-LNdCHzgLFc+UeqMS84LzXPaeBRKyqDN9OMyFAr1OrB0XrNw78IRrEVtZvvA7245W/HsaoeVOQX9jPjPk8jojwA=="], + "@next/swc-win32-x64-msvc": ["@next/swc-win32-x64-msvc@16.3.6", "", { "os": "win32", "cpu": "x64" }, "sha512-/YXjI1e5OXcZ7YpxRwgP/1jAV/SBKTzeVKqN2mk7mLpcICsyn3Gl5+dIfDTJp70M0ccMhyMMRso4v6mPDCGepg=="], "@node-rs/crc32": ["@node-rs/crc32@1.10.8", "", { "optionalDependencies": { "@node-rs/crc32-android-arm-eabi": "1.10.8", "@node-rs/crc32-android-arm64": "1.10.8", "@node-rs/crc32-darwin-arm64": "1.10.8", "@node-rs/crc32-darwin-x64": "1.10.8", "@node-rs/crc32-freebsd-x64": "1.10.8", "@node-rs/crc32-linux-arm-gnueabihf": "1.10.8", "@node-rs/crc32-linux-arm64-gnu": "1.10.8", "@node-rs/crc32-linux-arm64-musl": "1.10.8", "@node-rs/crc32-linux-x64-gnu": "1.10.8", "@node-rs/crc32-linux-x64-musl": "1.10.8", "@node-rs/crc32-win32-arm64-msvc": "1.10.8", "@node-rs/crc32-win32-ia32-msvc": "1.10.8", "@node-rs/crc32-win32-x64-msvc": "1.10.8" } }, "sha512-gOYKFwkojSdWrSmreCcGocRcAXSpRkNZYxv6nscmtddSWBKVGypdMbfLxu5qgmymdaCNApajuwZblYEfs7HswA=="], @@ -700,7 +700,7 @@ "@platformatic/dynamic-buffer": ["@platformatic/dynamic-buffer@0.3.1", "", {}, "sha512-xQD5JSkQc4D15suOk7FezGDmh6Vb5e4phDoFZ/ASpa3Ft+3fOVwFOENmHtC1561zm/xHnKwI91NbMF8inpbk0Q=="], - "@platformatic/kafka": ["@platformatic/kafka@2.11.0", "", { "dependencies": { "@platformatic/dynamic-buffer": "^0.3.1", "@platformatic/wasm-utils": "^0.2.1", "ajv": "^8.17.1", "ajv-draft-04": "^1.0.0", "avsc": "^5.7.9", "debug": "^4.4.3", "fastq": "^1.19.1", "mnemonist": "^0.40.3", "scule": "^1.3.0" }, "optionalDependencies": { "@node-rs/crc32": "^1.10.6", "protobufjs": "^8.0.0" } }, "sha512-mEkmYN+Crx1Tz4BjtRV4RW2L3AcGdxAbuVMGuO9Qv6vZ1iLOfmqyKxWb+CH1SxxvkzPrHE0EyIiuAD2cF1MVIg=="], + "@platformatic/kafka": ["@platformatic/kafka@2.12.0", "", { "dependencies": { "@platformatic/dynamic-buffer": "^0.3.1", "@platformatic/wasm-utils": "^0.2.1", "ajv": "^8.17.1", "ajv-draft-04": "^1.0.0", "avsc": "^5.7.9", "debug": "^4.4.3", "fastq": "^1.19.1", "mnemonist": "^0.40.3", "scule": "^1.3.0" }, "optionalDependencies": { "@node-rs/crc32": "^1.10.6", "protobufjs": "^8.0.0" } }, "sha512-h3ucWWP7s4uBMUcj07wyaGQfscBNlFZ/UKqff3yexPG2Es6tuEVv+6dO5G9DBIDW80wuj0xPGqTREjZPw2M9UQ=="], "@platformatic/wasm-utils": ["@platformatic/wasm-utils@0.2.1", "", { "dependencies": { "@platformatic/dynamic-buffer": "^0.3.1" } }, "sha512-5rNl4h5n+hZG4LjiItQ7bVfHBqTypjldP46NXrOYW64cZr87ahngK1s9nEtCpByWg7WWjRLSxyCytgJK5gNdwQ=="], @@ -1186,9 +1186,9 @@ "@xhmikosr/os-filter-obj": ["@xhmikosr/os-filter-obj@4.1.0", "", { "dependencies": { "system-architecture": "^1.0.0" } }, "sha512-y5ArHvQ7BVule/+L9yE2nYMhceiJhgsqo58lOfnisQ7bg+Kjfmkgr7JBuVFiTkl+ErdShpp829QstZQyLugl8g=="], - "@xyflow/react": ["@xyflow/react@12.11.6", "", { "dependencies": { "@xyflow/system": "0.0.82", "classcat": "^5.0.3", "zustand": "^4.4.0" }, "peerDependencies": { "@types/react": ">=17", "@types/react-dom": ">=17", "react": ">=17", "react-dom": ">=17" }, "optionalPeers": ["@types/react", "@types/react-dom"] }, "sha512-9XsEJNHjatKYndszKTF/bsU7FOP9dJ6V/EQwzy3oMdtqgBuUq7BjKSwkEo+C7s4qHstHQfwwoHA3E8QfpPxZZQ=="], + "@xyflow/react": ["@xyflow/react@12.12.0", "", { "dependencies": { "@xyflow/system": "0.0.83", "classcat": "^5.0.3", "zustand": "^4.4.0" }, "peerDependencies": { "@types/react": ">=17", "@types/react-dom": ">=17", "react": ">=17", "react-dom": ">=17" }, "optionalPeers": ["@types/react", "@types/react-dom"] }, "sha512-74oXI0Rgm1Eu33cHQAd74J6oVgCH9mbFyTVQbsGgp2kmWwh0HdtBr2VP04z8mbPD+M/xO69nqG5dDEt7/EN2rQ=="], - "@xyflow/system": ["@xyflow/system@0.0.82", "", { "dependencies": { "@types/d3-drag": "^3.0.7", "@types/d3-interpolate": "^3.0.4", "@types/d3-selection": "^3.0.10", "@types/d3-transition": "^3.0.8", "@types/d3-zoom": "^3.0.8", "d3-drag": "^3.0.0", "d3-interpolate": "^3.0.1", "d3-selection": "^3.0.0", "d3-zoom": "^3.0.0" } }, "sha512-4DKnL3CGtCGLRSmgDqaajRVgeksMXq/Yw4wPfdMfm7JvdIiWHGzVYOfFUztiATwdBXZqUU6HhehwUdbV9G23PQ=="], + "@xyflow/system": ["@xyflow/system@0.0.83", "", { "dependencies": { "@types/d3-drag": "^3.0.7", "@types/d3-interpolate": "^3.0.4", "@types/d3-selection": "^3.0.10", "@types/d3-transition": "^3.0.8", "@types/d3-zoom": "^3.0.8", "d3-drag": "^3.0.0", "d3-interpolate": "^3.0.1", "d3-selection": "^3.0.0", "d3-zoom": "^3.0.0" } }, "sha512-a//eDjez3WZF47aaPTfVUDD0OINOq+WVwBZCRTqG+m0a5euX8EwlJ4jMY1Wxz0Ocj4xOeekJ70V22Pq0ll8RJw=="], "@zumer/snapdom": ["@zumer/snapdom@2.15.0", "", {}, "sha512-rdayfg832lYhy2v2DRr4LwzhIT0ZMeGKYicVmtzbji95KhUd7Z1g6/5jTsDEU4q32a6ywbIpAixO45hubsEftQ=="], @@ -1200,7 +1200,7 @@ "acorn-jsx": ["acorn-jsx@5.3.2", "", { "peerDependencies": { "acorn": "^6.0.0 || ^7.0.0 || ^8.0.0" } }, "sha512-rq9s+JNhf0IChjtDXxllJ7g41oZk5SlXtp0LHwyA5cejwn7vKmKp4pPri6YEePv2PU65sAsegbXtIinmDFDXgQ=="], - "adm-zip": ["adm-zip@0.6.0", "", {}, "sha512-XleryMhbuksdKtofnWZ9Sk+4CUTbms4Mb/EU32SZwToAyZ5RgVos/ki8n+yr0LWHOGKuakbXTuuYNHLQjhddgg=="], + "adm-zip": ["adm-zip@0.6.1", "", {}, "sha512-Xwrja8nx9e5o2N1my4DsKCeKpdrnACyr1wtbPxBDgGzKzKyE9kRtBFA8mWldI+RVlD7CBZNWY/wQ2+ydwOR6kQ=="], "agent-base": ["agent-base@7.1.4", "", {}, "sha512-MnA+YT8fwfJPgBx3m60MNqakm30XOkyIoH1y6huTQvC0PwZG7ki8NacLBcrPbNoo8vEZy7Jpuk7+jMO+CUovTQ=="], @@ -1342,7 +1342,7 @@ "caniuse-lite": ["caniuse-lite@1.0.30001810", "", {}, "sha512-TITQPUkaz+aVk5GL6NhOdwk1aEaNTSDPsGFWrTuhKGtjTF70jL/Oht2W4c6rXUe5fu7Ie19VIahAXHIIiWWNeg=="], - "cassandra-driver": ["cassandra-driver@4.9.0", "", { "dependencies": { "@types/node": "^20.14.8", "adm-zip": "~0.5.10", "long": "~5.2.3" } }, "sha512-svYpdkLIGjD0WmuuwkkeYbfBdPX1zksK2cDyT1mWjX53OVTzuWBOVy54K6PPij8GgYpIG+K82OryrBv/xNeuWg=="], + "cassandra-driver": ["cassandra-driver@4.10.0", "", { "dependencies": { "adm-zip": "~0.6.0", "long": "~5.2.3" } }, "sha512-DHyFC6RMK28nvndZfecbGUozoYbb5NjFmlniczao8zA1IplurcshR2i6rvxpEu3Q9G45tjin4yU+iKwA10ZUtA=="], "cbor-extract": ["cbor-extract@2.2.2", "", { "dependencies": { "node-gyp-build-optional-packages": "5.1.1" }, "optionalDependencies": { "@cbor-extract/cbor-extract-darwin-arm64": "2.2.2", "@cbor-extract/cbor-extract-darwin-x64": "2.2.2", "@cbor-extract/cbor-extract-linux-arm": "2.2.2", "@cbor-extract/cbor-extract-linux-arm64": "2.2.2", "@cbor-extract/cbor-extract-linux-x64": "2.2.2", "@cbor-extract/cbor-extract-win32-x64": "2.2.2" }, "bin": { "download-cbor-prebuilds": "bin/download-prebuilds.js" } }, "sha512-hlSxxI9XO2yQfe9g6msd3g4xCfDqK5T5P0fRMLuaLHhxn4ViPrm+a+MUfhrvH2W962RGxcBwEGzLQyjbDG1gng=="], @@ -1502,7 +1502,7 @@ "dom-accessibility-api": ["dom-accessibility-api@0.5.16", "", {}, "sha512-X7BJ2yElsnOJ30pZF4uIIDfBEVgF4XEBxL9Bxhy6dnrm5hkzqmsWHGTiHqRiITNhMyFLyAiWndIJP7Z1NTteDg=="], - "dompurify": ["dompurify@3.4.8", "", { "optionalDependencies": { "@types/trusted-types": "^2.0.7" } }, "sha512-yb1cEmaOum7wFvOCSQxyfgVlv5D47Rc30iZWoMpbDIWTnJ6grDDQyu2KFJzB2k7u0pMuJcQ1zphH//fFnw2tjQ=="], + "dompurify": ["dompurify@3.4.15", "", { "optionalDependencies": { "@types/trusted-types": "^2.0.7" } }, "sha512-EUBjM+B+lkDE41iE82DDSCfkoPGfXx8IxFxPMjNzm/Uk4xDet77rTN9wqlxlVg71kK7XGuUMv6wUxJUwwv+Xyw=="], "dotenv": ["dotenv@17.3.1", "", {}, "sha512-IO8C/dzEb6O3F9/twg6ZLXz164a2fhTnEWb95H23Dm4OuN+92NmEAlTrupP9VW6Jm3sO26tQlqyvyi4CsnY9GA=="], @@ -1686,7 +1686,7 @@ "forwarded": ["forwarded@0.2.0", "", {}, "sha512-buRG0fpBtRHSTCOASe6hD258tEubFoRLb4ZNA6NxMVHNw2gOcwHo9wyablzMzOA5z9xA9L1KNjk/Nt6MT9aYow=="], - "framer-motion": ["framer-motion@13.4.0", "", { "dependencies": { "motion-dom": "^13.3.0", "motion-utils": "^13.3.0", "tslib": "^2.4.0" }, "peerDependencies": { "react": "^18.0.0 || ^19.0.0", "react-dom": "^18.0.0 || ^19.0.0" }, "optionalPeers": ["react", "react-dom"] }, "sha512-HCpqKM9BTu6UYKtj0u6J1QNxojnnirNcghcSDZ+SkpiL3myxvtsgXPS3ZGEELC2eSma7YiA937rAEXtRyydSXQ=="], + "framer-motion": ["framer-motion@13.4.3", "", { "dependencies": { "motion-dom": "^13.4.2", "motion-utils": "^13.3.0", "tslib": "^2.4.0" }, "peerDependencies": { "react": "^18.0.0 || ^19.0.0", "react-dom": "^18.0.0 || ^19.0.0" }, "optionalPeers": ["react", "react-dom"] }, "sha512-mPQe1GtRHWS30zRGaQAfmlIg0baA0jRhkpbFPT1d+s9bZPjMW6pJSjWM6ArmUEjzMgEm089ZL1wd8aPv1/5DJQ=="], "fresh": ["fresh@2.0.0", "", {}, "sha512-Rx/WycZ60HOaqLKAi6cHRKKI7zxWbJ31MhntmtwMoaTeF7XFH9hhBp8vITaMidfljRQ6eYWCKkaTK+ykVJHP2A=="], @@ -2012,7 +2012,7 @@ "lru.min": ["lru.min@1.1.5", "", {}, "sha512-5J9ysMYUpYIg9RF2vJpy9SinEmSviFSe0GyPpCQ4L5QSkLAgeLXlTAOu2ZwWUU5m+0SBl6gUU1R1ZQB3aKypfA=="], - "lucide-react": ["lucide-react@1.47.0", "", { "peerDependencies": { "react": "^16.5.1 || ^17.0.0 || ^18.0.0 || ^19.0.0" } }, "sha512-o8C23aXpNQypRY73W7fW02EyvWJinEMXgKeGjFoKym0zj3Q73hD97A1IQps1g8C14HTGsOpZL0Am+xjfgFZAbg=="], + "lucide-react": ["lucide-react@1.48.0", "", { "peerDependencies": { "react": "^16.5.1 || ^17.0.0 || ^18.0.0 || ^19.0.0" } }, "sha512-R0CIKY/fXiC6y9xRBADgsK+VW2p/pcTJOMhLZf1T+uG+vJUvyUR02nGOgmIIC7MPkiNK4Ox8QDnbqF8rJYWPZQ=="], "lz-string": ["lz-string@1.5.0", "", { "bin": { "lz-string": "bin/bin.js" } }, "sha512-h5bgJWpxJNswbU7qCrV0tIKQCaS3blPDrqKWx+QxzuzL1zGUzij9XCWLrSLsJPu5t+eWA/ycetzYAO5IOMcWAQ=="], @@ -2058,7 +2058,7 @@ "mnemonist": ["mnemonist@0.40.5", "", { "dependencies": { "obliterator": "^2.0.4" } }, "sha512-egXDkYJsKZCizjk8FydZ3g8TOigBwt+dIaehgKcQSAE3DCkCTWG4N94trvwR1ZYeAHo1exxE+ZhZOUuj01HdNw=="], - "monaco-editor": ["monaco-editor@0.56.0", "", { "dependencies": { "dompurify": "3.4.8", "marked": "14.0.0" } }, "sha512-sXboRm3BeBeLm938eaiyLMe0OxzfXIlZvbv4ir/jVgQy1zDhWjgmny0WoN45fuDKhCCQsYMbBJrv/A6jd8aCUg=="], + "monaco-editor": ["monaco-editor@0.57.0", "", { "dependencies": { "dompurify": "3.4.15", "marked": "14.0.0" } }, "sha512-5BkI9KGoqrNvBGUe15/QlZq3OooZ8WLg1AxTpaqHRCP3HNpzPPZKE2EDz8M7c+VRmCeUw1Brp4cx/PWm3kI/5A=="], "mongodb": ["mongodb@7.6.0", "", { "dependencies": { "@mongodb-js/saslprep": "^1.4.11", "bson": "^7.2.0", "mongodb-connection-string-url": "^7.0.1" }, "peerDependencies": { "@aws-sdk/credential-providers": "^3.806.0", "@mongodb-js/zstd": "^7.0.0", "gcp-metadata": "^7.0.1", "kerberos": "^7.0.0", "mongodb-client-encryption": "^7.2.0", "snappy": "^7.3.2", "socks": "^2.8.6" }, "optionalPeers": ["@aws-sdk/credential-providers", "@mongodb-js/zstd", "gcp-metadata", "kerberos", "mongodb-client-encryption", "snappy", "socks"] }, "sha512-WbZ6OCjYw2c53LOjfkQa+reXr7kIiOVpXXglnASFuiMtif0BvsMwHe3ClJHLm1/r7wJFwaasfFtD6iYIktB01g=="], @@ -2066,7 +2066,7 @@ "moo": ["moo@0.5.3", "", {}, "sha512-m2fmM2dDm7GZQsY7KK2cme8agi+AAljILjQnof7p1ZMDe6dQ4bdnSMx0cPppudoeNv5hEFQirN6u+O4fDE0IWA=="], - "motion-dom": ["motion-dom@13.3.0", "", { "dependencies": { "motion-utils": "^13.3.0" } }, "sha512-AmAnB6pHdZ1vHGzWzuzteG6Q3j1lHKeX/lbST6jGlgm0cjvLUgaCk1xhOuPMOy5SgovN6wnnUdwFrkcsus7Ftg=="], + "motion-dom": ["motion-dom@13.4.4", "", { "dependencies": { "motion-utils": "^13.3.0" } }, "sha512-z2qN3RUABSci4G7cr5aHTFhqPNCWJsEMMfRlzxqtANQsSCIbVJmHvMV288m5x7doEQBTYbRTWbKdztmquCn4Sw=="], "motion-utils": ["motion-utils@13.3.0", "", {}, "sha512-sgSschQp7EseHInIlR7hBbMuvet3RA0bs28KPZAXJcGKGdxHGvh1ogpYDilY3bOMtl73EqPNmp75sAKHYPU5sg=="], @@ -2094,7 +2094,7 @@ "negotiator": ["negotiator@1.1.0", "", { "dependencies": { "content-type": "^2.1.0" } }, "sha512-NMPBRMJgiQHjbd8phG3Vebdx4kZ1H121rbl5IkMqeOsahptB9BKo/d7oJ3zTXqTgagn2bWlNSXkh0QUGM31RYg=="], - "next": ["next@16.3.5", "", { "dependencies": { "@next/env": "16.3.5", "@swc/helpers": "0.5.23", "baseline-browser-mapping": "^2.9.19", "caniuse-lite": "^1.0.30001579", "postcss": "8.5.23", "styled-jsx": "5.1.6" }, "optionalDependencies": { "@next/swc-darwin-arm64": "16.3.5", "@next/swc-darwin-x64": "16.3.5", "@next/swc-linux-arm64-gnu": "16.3.5", "@next/swc-linux-arm64-musl": "16.3.5", "@next/swc-linux-x64-gnu": "16.3.5", "@next/swc-linux-x64-musl": "16.3.5", "@next/swc-win32-arm64-msvc": "16.3.5", "@next/swc-win32-x64-msvc": "16.3.5", "sharp": "^0.35.4" }, "peerDependencies": { "@opentelemetry/api": "^1.1.0", "@playwright/test": "^1.51.1", "babel-plugin-react-compiler": "*", "react": "^18.2.0 || 19.0.0-rc-de68d2f4-20241204 || ^19.0.0", "react-dom": "^18.2.0 || 19.0.0-rc-de68d2f4-20241204 || ^19.0.0", "sass": "^1.3.0" }, "optionalPeers": ["@opentelemetry/api", "@playwright/test", "babel-plugin-react-compiler", "sass"], "bin": { "next": "dist/bin/next" } }, "sha512-MdtsTgzyfCPRLC6uJ1mN8ao7lyJ4BB0U6Inhnx3gta1UcCIdHK3yxLG0E8OWQteWD8/Q0qb8A5o7wJaL8M9y2w=="], + "next": ["next@16.3.6", "", { "dependencies": { "@next/env": "16.3.6", "@swc/helpers": "0.5.23", "baseline-browser-mapping": "^2.9.19", "caniuse-lite": "^1.0.30001579", "postcss": "8.5.23", "styled-jsx": "5.1.6" }, "optionalDependencies": { "@next/swc-darwin-arm64": "16.3.6", "@next/swc-darwin-x64": "16.3.6", "@next/swc-linux-arm64-gnu": "16.3.6", "@next/swc-linux-arm64-musl": "16.3.6", "@next/swc-linux-x64-gnu": "16.3.6", "@next/swc-linux-x64-musl": "16.3.6", "@next/swc-win32-arm64-msvc": "16.3.6", "@next/swc-win32-x64-msvc": "16.3.6", "sharp": "^0.35.4" }, "peerDependencies": { "@opentelemetry/api": "^1.1.0", "@playwright/test": "^1.51.1", "babel-plugin-react-compiler": "*", "react": "^18.2.0 || 19.0.0-rc-de68d2f4-20241204 || ^19.0.0", "react-dom": "^18.2.0 || 19.0.0-rc-de68d2f4-20241204 || ^19.0.0", "sass": "^1.3.0" }, "optionalPeers": ["@opentelemetry/api", "@playwright/test", "babel-plugin-react-compiler", "sass"], "bin": { "next": "dist/bin/next" } }, "sha512-L+otWM/aQbYTx98aZhgEoMb4bZAXx1YVW4UMA/vuCyCoWG5HJyZUili8QAkqzrcC+5///tsz3s0M+SlyB5bLMw=="], "next-themes": ["next-themes@0.4.6", "", { "peerDependencies": { "react": "^16.8 || ^17 || ^18 || ^19 || ^19.0.0-rc", "react-dom": "^16.8 || ^17 || ^18 || ^19 || ^19.0.0-rc" } }, "sha512-pZvgD5L0IEvX5/9GWyHMf3m8BKiVQwsCMHfoFosXtXBMnaS0ZnIJ9ST4b4NqLVKDEm8QBxoNNGNaBv2JNF6XNA=="], @@ -2296,7 +2296,7 @@ "react-remove-scroll-bar": ["react-remove-scroll-bar@2.3.8", "", { "dependencies": { "react-style-singleton": "^2.2.2", "tslib": "^2.0.0" }, "peerDependencies": { "@types/react": "*", "react": "^16.8.0 || ^17.0.0 || ^18.0.0 || ^19.0.0" }, "optionalPeers": ["@types/react"] }, "sha512-9r+yi9+mgU33AKcj6IbT9oRCO78WriSj6t/cF8DWBZJ9aOGPOTEDvdUDz1FwKim7QXWwmHqtdHnRJfhAxEG46Q=="], - "react-resizable-panels": ["react-resizable-panels@4.12.4", "", { "peerDependencies": { "react": "^18.0.0 || ^19.0.0", "react-dom": "^18.0.0 || ^19.0.0" } }, "sha512-SOsSj4e9U7vxL15MbgTfl35IO4vxSW4Xb0b1gtJVbRPWv7FOezcgOA00Mi0jP8XqC3y7jOQxpsGs/9zLKHPitA=="], + "react-resizable-panels": ["react-resizable-panels@4.13.3", "", { "peerDependencies": { "react": "^18.0.0 || ^19.0.0", "react-dom": "^18.0.0 || ^19.0.0" } }, "sha512-k41s4nP8IXiGjnso8TsZLzoRbuxBb6buTJUOrFWrYpmbV4PGH5GHYM2RvNWWBRIJ6e+Zxlf3m9Tubk8VoPU9Ww=="], "react-style-singleton": ["react-style-singleton@2.2.3", "", { "dependencies": { "get-nonce": "^1.0.0", "tslib": "^2.0.0" }, "peerDependencies": { "@types/react": "*", "react": "^16.8.0 || ^17.0.0 || ^18.0.0 || ^19.0.0 || ^19.0.0-rc" }, "optionalPeers": ["@types/react"] }, "sha512-b6jSvxvVnyptAiLjbkWLE/lOnR4lfTtDAl+eUC7RZy+QQWc6wRzIV2CE6xBuMmDxc2qIihtDCZD5NPOFl7fRBQ=="], @@ -2428,7 +2428,7 @@ "sql-escaper": ["sql-escaper@1.5.1", "", {}, "sha512-4toX5E1fQbBrpfXidaHnF0669nkAdETeIPTs2SUjxxD7RRIs9ICG4gtpmfc68JCEKehsdwLFqBu9VlQqZ1P1gg=="], - "sql-formatter": ["sql-formatter@15.8.2", "", { "dependencies": { "argparse": "^2.0.1", "nearley": "^2.20.1" }, "bin": { "sql-formatter": "bin/sql-formatter-cli.cjs" } }, "sha512-kTYRg5FIcvsDtYUG2Qn9pYT6xKwiLJN5TTIvc5Mur6hIg4pSfdpHu8Yyu5bqESLHnVM3mXzD446cb2+uEaKZXg=="], + "sql-formatter": ["sql-formatter@15.9.0", "", { "dependencies": { "argparse": "^2.0.1", "nearley": "^2.20.1" }, "bin": { "sql-formatter": "bin/sql-formatter-cli.cjs" } }, "sha512-3A/N+v+mA5/PDU+FlO4uTFE0L/Mmg63c/Ny161Qv2b1Mxp9IX8War+LLmq17LA/Kgu4KXAR7iutK2JaHWJMMtw=="], "ssh2": ["ssh2@1.17.0", "", { "dependencies": { "asn1": "^0.2.6", "bcrypt-pbkdf": "^1.0.2" }, "optionalDependencies": { "cpu-features": "~0.0.10", "nan": "^2.23.0" } }, "sha512-wPldCk3asibAjQ/kziWQQt1Wh3PgDFpC0XpwclzKcdT1vql6KeYxf5LIt4nlFkUeR8WuphYMKqUA56X4rjbfgQ=="], @@ -2862,8 +2862,6 @@ "cacheable-request/get-stream": ["get-stream@9.0.1", "", { "dependencies": { "@sec-ant/readable-stream": "^0.4.1", "is-stream": "^4.0.1" } }, "sha512-kVCxPF3vQM/N0B1PmoqVUqgHP+EeVjmZSQn+1oCRPxd2P21P2F19lIgbR3HBosbB1PUhOAoctJnfEn2GbN2eZA=="], - "cassandra-driver/@types/node": ["@types/node@20.19.43", "", { "dependencies": { "undici-types": "~6.21.0" } }, "sha512-6oYBAi5ikg4Pl+kGsoYtawUMBT2zZMCvPNF7pVLnHZfd1zf38DRiWn/gT01RYCdUqkv7Fhr+C9ot4/tb+2sVvA=="], - "cli-highlight/yargs": ["yargs@16.2.2", "", { "dependencies": { "cliui": "^7.0.2", "escalade": "^3.1.1", "get-caller-file": "^2.0.5", "require-directory": "^2.1.1", "string-width": "^4.2.0", "y18n": "^5.0.5", "yargs-parser": "^20.2.2" } }, "sha512-Nt9ZJjXTv5R8MHbqby/wXQ6Gi0Bb3TcYZkR1bzuL4yB2OxWPkXknz513gEF0GoA6tn00UpbPvERW8rzCuWCA6w=="], "easy-table/ansi-regex": ["ansi-regex@5.0.1", "", {}, "sha512-quJQXlTSUGL2LH9SUXo8VwsY4soanhgo6LNSm84E1LBcE8s3O0wpdiRzyR9z/ZZJMlMWv37qOOb9pdJlMUEKFQ=="], @@ -3152,8 +3150,6 @@ "cacheable-request/get-stream/is-stream": ["is-stream@4.0.1", "", {}, "sha512-Dnz92NInDqYckGEUJv689RbRiTSEHCQ7wOVeALbkOz999YpqT46yMRIGtSNl2iCL1waAZSx40+h59NV/EwzV/A=="], - "cassandra-driver/@types/node/undici-types": ["undici-types@6.21.0", "", {}, "sha512-iwDZqg0QAGrg9Rav5H4n0M64c3mkR59cJ6wQp+7C4nI0gsmExaedaYLNO44eT4AtBBwjbTiGPMlt2Md0T9H9JQ=="], - "cli-highlight/yargs/cliui": ["cliui@7.0.4", "", { "dependencies": { "string-width": "^4.2.0", "strip-ansi": "^6.0.0", "wrap-ansi": "^7.0.0" } }, "sha512-OcRE68cOsVMXp1Yvonl/fzkQOyjLSu/8bhPDfQt0e0/Eb283TKP20Fs2MqoPsr9SwA595rRCA+QMzYc9nBP+JQ=="], "cli-highlight/yargs/yargs-parser": ["yargs-parser@20.2.9", "", {}, "sha512-y11nGElTIV+CT3Zv9t7VKl+Q3hTQoT9a1Qzezhhl6Rp21gJ/IVTW7Z3y9EWXhuUBC2Shnf+DX0antecpAwSP8w=="], diff --git a/docs/BACKLOG.md b/docs/BACKLOG.md index a21a989e4..255397acc 100644 --- a/docs/BACKLOG.md +++ b/docs/BACKLOG.md @@ -37,7 +37,7 @@ None of it is a GitHub issue. - [Release pipeline](#release-pipeline) — REL1–REL4 · 4 - [Chart configuration surface](#chart-configuration-surface) — N1 · 1 - [Security Phase 1 deferrals](#security-phase-1-deferrals) — H1–H14 · 4 -- [Security Phase 2 deferrals](#security-phase-2-deferrals) — C3–C11 · 7 +- [Security Phase 2 deferrals](#security-phase-2-deferrals) — C3–C11 · 6 - [Security Phase 3 deferrals](#security-phase-3-deferrals) — K4 - [Security scanner triage](#security-scanner-triage) — SCAN1 · 1 - [Agent M1 deferrals (#328)](#agent-m1-deferrals-328) — A1–A8 · 7 @@ -3406,34 +3406,6 @@ a CC BY-SA database with no note connecting them. tarballs, names the sample database's separate terms explicitly, and is regenerated from the lockfile rather than hand-maintained. -### C10. The last DOMPurify advisories are held open by Monaco's pin - -`dompurify` via `monaco-editor` is the only advisory chain that reaches a user. Everything else -`bun audit` reports — `minimatch`, `brace-expansion`, `flatted`, `picomatch`, `esbuild`, `@babel/core`, -`undici` — arrives through `eslint`, `typescript-eslint`, `knip`, `tsup`, `workflow` and `@ai-sdk/*`, -and none of it is in the image. `undici` was checked specifically, because the agent runtime sits in -`devDependencies` by design yet reaches the standalone build: building with `DOCKER_BUILD=true` shows -no `undici` anywhere under `.next/standalone`, since `@ai-sdk/provider-utils` reaches it through a -`createRequire` call that output tracing cannot follow. - -#374 moved the shipped copy from 3.2.7 to 3.4.8 by upgrading Monaco itself, clearing 14 of the 17. -**Four remain** on GitHub Advanced Security's count, and none can be closed here: they need 3.4.9, -3.4.11, 3.4.12 and 3.4.13. Monaco pins dompurify exactly, and 0.56.0 is its newest release. - -**Do not "fix" these with a `package.json` override.** Monaco ships DOMPurify inlined in its prebuilt -`min/vs` bundle and nothing in `src/` imports the package. An override would change a lockfile entry no -shipped code reads, leave the bundle byte-identical, and turn `bun audit` and Trivy green at once. The -GHAS findings land on `bun.lock:`, which is the tell: every one of those tools reads the -manifest, not the artefact. - -Two related non-findings, so they are not re-derived. `dompurify` is dual-licensed (MPL-2.0 OR -Apache-2.0), so the copyleft half can simply not be chosen. And the LGPL-3.0 `@img/sharp-libvips-*` -binaries never reach the runtime image, because the runner stage copies `node_modules` selectively and -nothing in `src/` uses `next/image`. - -**Done when:** Monaco ships a dompurify at or past 3.4.13. Re-check on each Monaco release, and verify -by grepping the staged bundle for the version literal rather than trusting the lockfile. - ### C11. The published SBOM carries no component for the bundled Node.js runtime #584 gave `SECURITY.md` a hand-maintained **Bundled Node.js runtime** table: the pinned version, the diff --git a/docs/providers/cassandra.md b/docs/providers/cassandra.md index 3a776f52e..520f51e75 100644 --- a/docs/providers/cassandra.md +++ b/docs/providers/cassandra.md @@ -16,7 +16,7 @@ | **Status** | Implemented & shipped | | **Database type id** | `cassandra` | | **Family** | SQL (`src/lib/db/providers/sql/cassandra/`) | -| **Driver** | [`cassandra-driver`](https://www.npmjs.com/package/cassandra-driver) 4.9.0 — Apache-2.0, pure JS (no `binding.gyp`, no `.node`, no postinstall) ([§3.1](#31-a-driver-that-costs-no-distribution-channel-anything)) | +| **Driver** | [`cassandra-driver`](https://www.npmjs.com/package/cassandra-driver) 4.10.0 — Apache-2.0, pure JS (no `binding.gyp`, no `.node`, no postinstall) ([§3.1](#31-a-driver-that-costs-no-distribution-channel-anything)) | | **Query language** | `sql` — CQL is SQL-*shaped*: no JOIN, no subquery, no OFFSET, no EXPLAIN ([§5.4](#54-dialect-traps-a-user-will-hit)) | | **Default port** | `9042` — the native protocol. Thrift (9160) is gone from 4.0 onwards; 7000/7001 are internode and 7199 is JMX | | **Connection pooling** | The driver's own, one session per connection: core 1 connection per local host, 2048 requests in flight per connection | @@ -1465,7 +1465,7 @@ first and then the remaining columns alphabetically, with all twenty table optio Nothing in the database holds the author's own bytes. **`cql` IS NOT A MONACO LANGUAGE ID**, and every row above says `sql` because of it. The installed -monaco-editor 0.56.0 bundle registers 89 ids and `cql` is not among them; an unregistered id degrades +monaco-editor 0.57.0 bundle registers 89 ids and `cql` is not among them; an unregistered id degrades to plain text with no throw and nothing observable. `sql` is the closest registered dialect, so a `CREATE TABLE` renders correctly and the CQL-only spellings (`PRIMARY KEY ((a), b)`, `frozen
`, a `$$ ... $$` function body) are highlighted as whatever the SQL tokenizer makes diff --git a/docs/providers/clickhouse.md b/docs/providers/clickhouse.md index ad7b7b9c5..5e967dead 100644 --- a/docs/providers/clickhouse.md +++ b/docs/providers/clickhouse.md @@ -1074,7 +1074,7 @@ the author typed, so a reader must never be shown it as an original. The fixture carrying a `SETTINGS index_granularity = 8192` clause nobody wrote. `sql` is the right Monaco id and no part of it is a compromise: ClickHouse SQL is SQL, and the -installed monaco-editor 0.56.0 registers `sql`. The three ids this design had to refuse +installed monaco-editor 0.57.0 registers `sql`. The three ids this design had to refuse elsewhere, `plsql`, `tsql` and `cql`, are not registered at all and are not needed here. #### The read takes NO identifier position, and that is the security decision diff --git a/docs/providers/duckdb.md b/docs/providers/duckdb.md index 837254459..8a8b31edc 100644 --- a/docs/providers/duckdb.md +++ b/docs/providers/duckdb.md @@ -880,7 +880,7 @@ Every declared kind publishes a definition text, so **all four declare `hasSourc one object and answers a document of exactly one part. `sql` is the honest Monaco id rather than a compromise. DuckDB's dialect is PostgreSQL-shaped, the -installed monaco-editor 0.56.0 registers no DuckDB id, and the text the engine publishes is ordinary +installed monaco-editor 0.57.0 registers no DuckDB id, and the text the engine publishes is ordinary SQL. This is unlike Oracle, SQL Server and Cassandra, where `plsql`, `tsql` and `cql` are not registrable ids in that bundle and `sql` really is a compromise those provider docs record. diff --git a/docs/providers/kafka.md b/docs/providers/kafka.md index da94f33fd..ccc3a1ff7 100644 --- a/docs/providers/kafka.md +++ b/docs/providers/kafka.md @@ -10,7 +10,7 @@ | **Status** | Implemented & shipped | | **Database type id** | `kafka` | | **Family** | Stream (`src/lib/db/providers/stream/kafka/`), the first provider in that family | -| **Driver** | `@platformatic/kafka` 2.11.0, pinned exactly, pure TypeScript, loaded under Bun and Node alike ([§2.5](#25-the-client-and-why)) | +| **Driver** | `@platformatic/kafka` 2.12.0, pinned exactly, pure TypeScript, loaded under Bun and Node alike ([§2.5](#25-the-client-and-why)) | | **Query language** | `json` with `queryDialect: "kafka"`: a JSON read request of this product's own schema, not MongoDB's JSON ([§5.1](#51-the-read-request)) | | **Default port** | `9092`, the port a stock broker listens on; the same number is the default under TLS, because a secured listener serves on whatever port its operator chose | | **Connection pooling** | One `Admin`, one `Consumer` and one fetch `ConnectionPool` per connection, all closed by `disconnect()` ([§3.4](#34-one-client-per-connection-and-no-fetch-session)) | @@ -102,7 +102,8 @@ A connect that fails after the client was built closes it again. ### 2.5 The client, and why -`@platformatic/kafka` 2.11.0, used fetch-only, was chosen by a broker-side measurement before any code was written (#1088, section 3.2 and Appendix B). +`@platformatic/kafka`, used fetch-only, was chosen at 2.11.0 by a broker-side measurement before any code was written (#1088, section 3.2 and Appendix B). +2.12.0 was taken only after the live read-only check passed on it ([§11.4](#114-the-live-read-only-check)). Reading by partition, offset and timestamp through its `listOffsets`, `listOffsetsWithTimestamps` and a fetch registered no consumer group and never created `__consumer_offsets`, under Bun and Node. Its `consume()` in MANUAL mode, with explicit offsets and `autocommit: false`, joins the group and leaves an `Empty` group registered after `close()`, so `consume()` is never called. All four codecs, gzip, snappy, lz4 and zstd, decode with no native addon: snappy and lz4 come from WebAssembly, gzip and zstd from `node:zlib`, and the optional `@node-rs/crc32` falls back to WebAssembly. @@ -629,6 +630,8 @@ With `--tripwire` it first reads every seeded topic on a broker never asked for Its log searches for an automatic topic creation and for the never-joined group id are each paired with a control that finds that kind of line in the broker's whole log. Measured on 2026-09-25: every check passed on `kafka` (57, with the tripwire), on `redpanda` (39), on `kafka-cluster` (47), and on `kafka-auth` as `reader` (7), and every snapshot after a run equalled the one before it. +Measured again on 2026-09-28 with `@platformatic/kafka` 2.12.0: the same four counts, eight of eight with `--failover`, and every snapshot after a run equalled the one before it. +The same day, under Node through `next start`, a connect, the topic listing and two reads on a broker never asked for a group coordinator left `__consumer_offsets` absent, and the group seed that followed created it. Against the provider with one rule broken at a time, the check failed each time: a `disconnect()` that closes nothing, `autocreateTopics: true`, a `metadata([])` answered from the cache, lag that ignores the committed offset, a transaction filter that keeps aborted records, a group listing without the `consumer` type, and a lag listing that shows one partition twice. A config write made during the run from outside the provider, setting `orders` to the `compression.type=gzip` line `codec-gzip` already holds, failed the check too; the check as first committed, which compared bare lines as a set, passed it. @@ -732,7 +735,7 @@ See [`docs/API_DOCS.md`](../API_DOCS.md) for the full request and response contr - Source: [`src/lib/db/providers/stream/kafka/`](../../src/lib/db/providers/stream/kafka/) - Design: [#1088](https://github.com/libredb/libredb-studio/issues/1088) -- Client: [`@platformatic/kafka`](https://github.com/platformatic/kafka), version 2.11.0 +- Client: [`@platformatic/kafka`](https://github.com/platformatic/kafka), version 2.12.0 - Kafka protocol: - KIP-848, the consumer group protocol: - KIP-516, topic identifiers: diff --git a/docs/providers/mssql.md b/docs/providers/mssql.md index 4c08f3938..5e3426749 100644 --- a/docs/providers/mssql.md +++ b/docs/providers/mssql.md @@ -886,7 +886,7 @@ sentence names the catalog view and the column the decision came from instead. encryption at all. **`sql` and not `tsql`.** -MEASURED in #789: `tsql` is not among the 89 language ids the installed monaco-editor 0.56.0 bundle +MEASURED in #789: `tsql` is not among the 89 language ids the installed monaco-editor 0.57.0 bundle registers, and an unregistered id degrades to plain text silently. So a T-SQL definition renders under the generic `sql` grammar, and T-SQL-only spellings (`OUTER APPLY`, `MERGE ... OUTPUT`, `@variable`) draw as plain identifiers. diff --git a/docs/providers/mysql.md b/docs/providers/mysql.md index 5958fb113..f048f3bce 100644 --- a/docs/providers/mysql.md +++ b/docs/providers/mysql.md @@ -1114,7 +1114,7 @@ CALL bulk26a1.seed(); parts. **Every kind either server declares can answer**, which makes this the one provider in the fleet with no kind that declares nothing: MySQL's six and MariaDB's eight each have a `SHOW CREATE` form. The Monaco language id is `mysql` on all eight; `mysql` is an id the installed monaco-editor -0.56.0 bundle really registers, unlike `plsql`, `tsql` and `cql`. +0.57.0 bundle really registers, unlike `plsql`, `tsql` and `cql`. Measured 2026-09-13 on **MySQL 26.7.0** and **MariaDB 12.3.2** against the two committed fixtures. diff --git a/docs/providers/oracle.md b/docs/providers/oracle.md index 58e14ee6f..1d0221cb9 100644 --- a/docs/providers/oracle.md +++ b/docs/providers/oracle.md @@ -1332,7 +1332,7 @@ The owner is the segment the DECLARATION assigns to the `schema` container level is the LAST path segment; neither is read by a literal index. **The Monaco language id is `sql`, and that is a compromise this provider states rather than hides.** -MEASURED on the installed monaco-editor 0.56.0: `plsql` is not among the 89 language ids the bundle +MEASURED on the installed monaco-editor 0.57.0: `plsql` is not among the 89 language ids the bundle registers, and an unregistered id degrades to plain text SILENTLY, with no throw and nothing observable. A PL/SQL body therefore renders under the SQL grammar, which highlights the DML and misses `IS`, `BEGIN`, `EXCEPTION` and the block structure. diff --git a/docs/providers/postgres.md b/docs/providers/postgres.md index f239ec77d..4473fee5c 100644 --- a/docs/providers/postgres.md +++ b/docs/providers/postgres.md @@ -716,7 +716,7 @@ One writer for both, because two copies are two chances for the read to answer " `pg_get_function_identity_arguments()` is not used, for the reason [§3.1.4](#314-what-the-object-surface-declares-and-which-catalog-answers-for-it) gives: it renders parameter names. **`pgsql` is a real Monaco language id and is no compromise here.** -It is among the ids the installed `monaco-editor` 0.56.0 registers, unlike `plsql` and `tsql`, which Oracle and SQL Server have to render under `sql`. +It is among the ids the installed `monaco-editor` 0.57.0 registers, unlike `plsql` and `tsql`, which Oracle and SQL Server have to render under `sql`. A PL/pgSQL body inside a `$function$` dollar-quoted string is highlighted as PostgreSQL SQL rather than as a procedural language, which is the closest this bundle can come. ### 3.1.6 Object edit (#789) diff --git a/docs/providers/redis.md b/docs/providers/redis.md index bcea89ec6..5f30015b1 100644 --- a/docs/providers/redis.md +++ b/docs/providers/redis.md @@ -1026,7 +1026,7 @@ reach this arm is a declaration somebody removed. |---|---|---| | `id` | `definition` | one part, always: a library has one Lua text | | `label` | `Definition` | rendered as-is | -| `language` | the kind's declared `sourceLanguage`, which is `lua` | `lua` IS a Monaco language id the installed 0.56.0 bundle registers, unlike `plsql`, `tsql` and `cql` | +| `language` | the kind's declared `sourceLanguage`, which is `lua` | `lua` IS a Monaco language id the installed 0.57.0 bundle registers, unlike `plsql`, `tsql` and `cql` | | `form` | `complete` | the text runs as given: it is what `FUNCTION LOAD` was handed | | `origin` | `stored` | the author's own bytes. Measured on Redis 8.10.0: `WITHCODE` answers the shebang line and the body exactly as they were loaded, with no reformatting | diff --git a/package.json b/package.json index 1e7c08e56..cb09057bd 100644 --- a/package.json +++ b/package.json @@ -126,9 +126,9 @@ "oracledb", "ssh2" ], - "//overrides": "Transitive dependencies held above what their parent's range would otherwise resolve to. lodash: recharts asks for ^4.17.21 and CVE-2026-4800 (arbitrary code execution via untrusted input in template imports) is fixed in 4.18.0. The fix is inside the parent's range, so this only forces resolution forward - remove the entry once recharts raises its own floor. Nothing in this repository imports lodash directly. adm-zip: cassandra-driver asks for ~0.5.10 and CVE-2026-39244 (denial of service through a crafted ZIP that forces excessive memory allocation) is fixed in 0.6.0, which is OUTSIDE that range - so unlike lodash above this holds the dependency past what its parent would ever resolve to, and it must be re-checked whenever cassandra-driver moves. The vulnerable path is not reachable from this product: adm-zip has exactly one consumer in the driver, lib/datastax/cloud/index.js, whose init() returns immediately unless a `cloud` option is set, and that option is only for Astra DB secure-connect bundles, which no connection here sets. The pin is taken anyway rather than argued away, and 0.6.0 was verified against the live server: the cloud module loads, an adm-zip write and read round-trips, and a connect plus query answers on Apache Cassandra 5.0.9.", + "//overrides": "Transitive dependencies held above what their parent's range would otherwise resolve to. lodash: recharts asks for ^4.17.21 and CVE-2026-4800 (arbitrary code execution via untrusted input in template imports) is fixed in 4.18.0. The fix is inside the parent's range, so this only forces resolution forward - remove the entry once recharts raises its own floor. Nothing in this repository imports lodash directly. adm-zip: cassandra-driver 4.10.0 asks for ~0.6.0 and CVE-2026-77301 (denial of service through uncontrolled memory allocation) is fixed in 0.6.1. The fix is inside the parent's range, so like lodash this only forces resolution forward - remove the entry once cassandra-driver raises its own floor to 0.6.1. CVE-2026-76845 (arbitrary file overwrite through a symlink) has no fixed release yet. Neither path is reachable from this product: adm-zip has exactly one consumer in the driver, lib/datastax/cloud/index.js, whose init() returns immediately unless a `cloud` option is set, and that option is only for Astra DB secure-connect bundles, which no connection here sets. The pin is taken anyway rather than argued away, and 0.6.1 was verified against the live server: the cloud module loads, an adm-zip write and read round-trips, and a connect plus query answers on Apache Cassandra 5.0.9.", "overrides": { - "adm-zip": "^0.6.0", + "adm-zip": "^0.6.1", "lodash": "^4.18.1", "tedious": "^20.0.5" }, @@ -170,13 +170,13 @@ "security:check": "node scripts/security-check.mjs", "test:e2e:base-path": "playwright test --config=playwright.base-path.config.ts" }, - "//dependencies": "@duckdb/node-api is pinned to an exact version. Its versions carry a prerelease suffix (1.5.5-r.4 = DuckDB 1.5.5, driver revision 4), and npm and bun treat a caret over a prerelease tag inconsistently - `^1.5.5-r.4` would resolve forward across 1.x in a way neither tool agrees on - so the range is written out. The driver is four packages, not one: @duckdb/node-api -> @duckdb/node-bindings -> a per-platform, per-libc @duckdb/node-bindings--[-musl] holding duckdb.node next to the ~70 MB libduckdb.so it links against. None of the four declares a scripts block or a binding.gyp, so no trustedDependencies entry is needed. Bumping it is a provider change, not a routine bump (see docs/providers/duckdb.md and the tri-sync rule in CLAUDE.md). @platformatic/kafka is pinned exactly too, because the Kafka provider was measured against 2.11.0, so bumping it is a provider change too. ajv is listed although nothing in this repository imports it: @platformatic/kafka loads ajv-draft-04, whose optional peer is ajv ^8.5.0 and which requires ajv/dist/core at load time, and bun hoists ajv-draft-04 to the top of node_modules, where ajv was otherwise eslint's 6.x with no dist/core. Without this entry the Kafka client fails to load in a clean install (a Docker build, CI); with it ajv 8 sits at the top and eslint keeps its 6.x nested. That is why knip.json ignores ajv, and tests/unit/db/kafka/dependency-resolution.test.ts fails if the entry goes. The entry fixes this repository's own install only: a host that installs the published package with bun and leaves an ajv 6 at the top of its own node_modules meets the same failure, which the provider's connect() refuses with a DatabaseConfigError naming ajv/dist/core, and docs/providers/kafka.md section 2.5 says what such a host needs.", + "//dependencies": "@duckdb/node-api is pinned to an exact version. Its versions carry a prerelease suffix (1.5.5-r.4 = DuckDB 1.5.5, driver revision 4), and npm and bun treat a caret over a prerelease tag inconsistently - `^1.5.5-r.4` would resolve forward across 1.x in a way neither tool agrees on - so the range is written out. The driver is four packages, not one: @duckdb/node-api -> @duckdb/node-bindings -> a per-platform, per-libc @duckdb/node-bindings--[-musl] holding duckdb.node next to the ~70 MB libduckdb.so it links against. None of the four declares a scripts block or a binding.gyp, so no trustedDependencies entry is needed. Bumping it is a provider change, not a routine bump (see docs/providers/duckdb.md and the tri-sync rule in CLAUDE.md). @platformatic/kafka is pinned exactly too, because the Kafka provider was measured against 2.11.0 and re-verified live against 2.12.0 (docs/providers/kafka.md section 11.4), so bumping it is a provider change too. ajv is listed although nothing in this repository imports it: @platformatic/kafka loads ajv-draft-04, whose optional peer is ajv ^8.5.0 and which requires ajv/dist/core at load time, and bun hoists ajv-draft-04 to the top of node_modules, where ajv was otherwise eslint's 6.x with no dist/core. Without this entry the Kafka client fails to load in a clean install (a Docker build, CI); with it ajv 8 sits at the top and eslint keeps its 6.x nested. That is why knip.json ignores ajv, and tests/unit/db/kafka/dependency-resolution.test.ts fails if the entry goes. The entry fixes this repository's own install only: a host that installs the published package with bun and leaves an ajv 6 at the top of its own node_modules meets the same failure, which the provider's connect() refuses with a DatabaseConfigError naming ajv/dist/core, and docs/providers/kafka.md section 2.5 says what such a host needs.", "dependencies": { "@duckdb/node-api": "1.5.5-r.5", "@google/generative-ai": "^0.24.1", "@libredb/libredb": "^0.2.2", "@monaco-editor/react": "^4.7.0", - "@platformatic/kafka": "2.11.0", + "@platformatic/kafka": "2.12.0", "@radix-ui/react-accordion": "^1.2.20", "@radix-ui/react-alert-dialog": "^1.1.23", "@radix-ui/react-aspect-ratio": "^1.1.15", @@ -222,7 +222,7 @@ "ioredis": "^5.11.1", "jose": "^6.2.12", "lucide-react": "^1.41.0", - "monaco-editor": "^0.56.0", + "monaco-editor": "^0.57.0", "mongodb": "^7.6.0", "mssql": "^12.7.0", "mysql2": "^3.24.3", diff --git a/src/components/ShortcutsDialog.tsx b/src/components/ShortcutsDialog.tsx index b1b90da1b..f8cfe9365 100644 --- a/src/components/ShortcutsDialog.tsx +++ b/src/components/ShortcutsDialog.tsx @@ -76,7 +76,7 @@ function isTypingTarget(target: EventTarget | null): boolean { if (!(target instanceof HTMLElement)) return false; if (target instanceof HTMLInputElement || target instanceof HTMLTextAreaElement) return true; if (target.isContentEditable) return true; - // Monaco 0.56 focuses a `div.native-edit-context`, not a textarea or a contentEditable + // Monaco 0.57 focuses a `div.native-edit-context`, not a textarea or a contentEditable // element, so neither check above sees it - and `?` is the positional-parameter // placeholder in SQLite and MySQL, so missing this let the dialog eat the keystroke // mid-query. `.monaco-editor` is Monaco's own stable root class, not an internal we're diff --git a/src/lib/db/providers/document/couchbase/objects.ts b/src/lib/db/providers/document/couchbase/objects.ts index b6cf34c26..f73c22eff 100644 --- a/src/lib/db/providers/document/couchbase/objects.ts +++ b/src/lib/db/providers/document/couchbase/objects.ts @@ -196,7 +196,7 @@ export const COUCHBASE_OBJECT_KINDS: readonly ObjectKindSpec[] = Object.freeze([ // statement this product composed from the keys. The index KEYS are in // `describeObject`, which is where a fact the catalog does publish belongs. hasSource: true, - // SQL++, and `sql` is the closest id the installed monaco-editor 0.56.0 registers. + // SQL++, and `sql` is the closest id the installed monaco-editor 0.57.0 registers. // There is no `n1ql` and no `sqlpp` in its 89 ids, and an unregistered id degrades to // plain text with no throw and nothing observable. sourceLanguage: "sql", diff --git a/src/lib/db/providers/sql/cassandra/driver-transport.ts b/src/lib/db/providers/sql/cassandra/driver-transport.ts index 168a7c07a..8ac282fec 100644 --- a/src/lib/db/providers/sql/cassandra/driver-transport.ts +++ b/src/lib/db/providers/sql/cassandra/driver-transport.ts @@ -2,12 +2,13 @@ * The one file in this provider that knows `cassandra-driver` exists * (issue #424, Phase 4). * - * `cassandra-driver` 4.9.0 is pure JavaScript - no `binding.gyp`, no `.node`, no + * `cassandra-driver` 4.10.0 is pure JavaScript - no `binding.gyp`, no `.node`, no * postinstall - so unlike `oracledb` or `better-sqlite3` it adds no native module - * to any distribution channel. It was exercised under bun 1.3.14 before this - * provider was written: three sessions, 2500 concurrent prepared inserts, a - * 400-statement batch, `eachRow` auto-paging 500 rows and `stream()` over 2000. - * The historical bun segfault reports do not reproduce on this version. + * to any distribution channel. It was exercised under bun 1.3.14 on 4.9.0, whose + * `lib/` 4.10.0 ships byte-identical, before this provider was written: three + * sessions, 2500 concurrent prepared inserts, a 400-statement batch, `eachRow` + * auto-paging 500 rows and `stream()` over 2000. The historical bun segfault + * reports do not reproduce on this version. * * It DOES `require('kerberos')` inside a try/catch as an optional dependency, so * the package is listed in `serverExternalPackages` (next.config.ts) and in tsup's diff --git a/src/lib/db/providers/sql/cassandra/index.ts b/src/lib/db/providers/sql/cassandra/index.ts index e0b311e19..75d768740 100644 --- a/src/lib/db/providers/sql/cassandra/index.ts +++ b/src/lib/db/providers/sql/cassandra/index.ts @@ -1,7 +1,7 @@ /** * Apache Cassandra Database Provider (issue #424, Phase 4) * - * CQL over the native protocol through `cassandra-driver` 4.9.0, with every + * CQL over the native protocol through `cassandra-driver` 4.10.0, with every * statement, catalog read and metric going through the `CassandraTransport` seam - * so this file names no driver class and `seam-guard.test.ts` fails the build if it * starts to. The driver lives in `driver-transport.ts`; the catalog and diff --git a/src/lib/db/providers/sql/cassandra/objects.ts b/src/lib/db/providers/sql/cassandra/objects.ts index 184c15821..f609017dd 100644 --- a/src/lib/db/providers/sql/cassandra/objects.ts +++ b/src/lib/db/providers/sql/cassandra/objects.ts @@ -158,7 +158,7 @@ export const CASSANDRA_CONTAINER_LEVELS: ContainerLevels = Object.freeze([ /** * The Monaco id every readable kind here renders under, and the reason it is a compromise. * - * `cql` IS NOT A MONACO LANGUAGE ID. Measured against the installed monaco-editor 0.56.0 + * `cql` IS NOT A MONACO LANGUAGE ID. Measured against the installed monaco-editor 0.57.0 * bundle in this epic: it registers 89 ids and `cql` is not one of them, and an unregistered * id degrades to plain text with no throw and nothing observable. `sql` is the closest * registered dialect, so a `CREATE TABLE` renders correctly and CQL-only spellings diff --git a/src/lib/db/providers/sql/duckdb/index.ts b/src/lib/db/providers/sql/duckdb/index.ts index 9bbbd8ee1..fa305d6a6 100644 --- a/src/lib/db/providers/sql/duckdb/index.ts +++ b/src/lib/db/providers/sql/duckdb/index.ts @@ -449,7 +449,7 @@ export class DuckDBProvider extends SQLBaseProvider { // publishes a definition text for each of them and no fifth kind is declared, so // the "declares nothing" half of this engine's row in #789 is empty. `sql` is the // honest id rather than a compromise: DuckDB's dialect is PostgreSQL-shaped, the - // installed monaco-editor 0.56.0 registers no DuckDB id, and the text the engine + // installed monaco-editor 0.57.0 registers no DuckDB id, and the text the engine // publishes is ordinary SQL. The `macro` text is the only `partial` form ON THIS // ENGINE, not in the fleet: the #789 design names PostgreSQL `view` and // `materialized_view` and Couchbase `function` as producers of the same arm, and diff --git a/src/lib/db/providers/sql/mssql.ts b/src/lib/db/providers/sql/mssql.ts index bb8086ec0..7d9dbd275 100644 --- a/src/lib/db/providers/sql/mssql.ts +++ b/src/lib/db/providers/sql/mssql.ts @@ -439,7 +439,7 @@ const TRIGGER_KIND = "trigger"; * stopped highlighting. * * `sql` and NOT `tsql`. MEASURED in #789: `tsql` is not among the 89 language ids the - * installed monaco-editor 0.56.0 bundle registers, and neither are `plsql` and `cql`, so + * installed monaco-editor 0.57.0 bundle registers, and neither are `plsql` and `cql`, so * the one id in the bundle that highlights this dialect is the generic one. T-SQL keywords * the generic grammar does not know (`OUTER APPLY`, `MERGE ... OUTPUT`) render as plain * identifiers, which is a compromise `docs/providers/mssql.md` records rather than hides. diff --git a/src/lib/db/providers/sql/mysql.ts b/src/lib/db/providers/sql/mysql.ts index d445fc12f..78790bb77 100644 --- a/src/lib/db/providers/sql/mysql.ts +++ b/src/lib/db/providers/sql/mysql.ts @@ -1083,7 +1083,7 @@ const BULK_DETAIL_SQL: Record = Object.fromEntries * `hasSource` and miss its language: an absent or unregistered Monaco id degrades to plain text * with no throw and nothing observable, which is a Source tab that silently stops highlighting. * - * `mysql` is a language id the installed monaco-editor 0.56.0 bundle really registers, unlike + * `mysql` is a language id the installed monaco-editor 0.57.0 bundle really registers, unlike * `plsql`, `tsql` and `cql`, which the design's first-pass table named and the bundle does not * have. The same id serves MariaDB: the two servers share one dialect for everything here * except the ORACLE-mode package, whose text Monaco highlights as MySQL with the quoted diff --git a/src/lib/db/providers/sql/oracle.ts b/src/lib/db/providers/sql/oracle.ts index d495a1ba9..0c3e2f64b 100644 --- a/src/lib/db/providers/sql/oracle.ts +++ b/src/lib/db/providers/sql/oracle.ts @@ -287,7 +287,7 @@ const PACKAGE_BODY_OBJECT_TYPE = { dictionary: "PACKAGE BODY", metadata: "PACKAG * no "declares nothing" list for this provider, and the integration suite asserts that * emptiness in both directions so a tenth kind cannot quietly gain a Source tab. * - * `sql` and NOT `plsql`. MEASURED on the installed monaco-editor 0.56.0: `plsql` is not + * `sql` and NOT `plsql`. MEASURED on the installed monaco-editor 0.57.0: `plsql` is not * among the 89 language ids the bundle registers, and an unregistered id degrades to plain * text SILENTLY, with no throw and nothing observable. A PL/SQL body therefore renders under * the SQL grammar, which highlights the DML and misses `IS`/`BEGIN`/`EXCEPTION`. That is a diff --git a/src/lib/editor/monaco-theme.ts b/src/lib/editor/monaco-theme.ts index 65cfd6d60..28ac6e28c 100644 --- a/src/lib/editor/monaco-theme.ts +++ b/src/lib/editor/monaco-theme.ts @@ -11,7 +11,7 @@ import type * as Monaco from "monaco-editor"; * their own `monaco` instance. * * `editor.defineTheme` registers on the Monaco INSTANCE, not on the mount, and monaco-editor - * 0.56.0 documents it as "Define a new theme or update an existing theme" + * 0.57.0 documents it as "Define a new theme or update an existing theme" * (`monaco-editor/esm/vs/editor/editor.api.d.ts:1124`), so calling this from every mount's * `beforeMount` rewrites the same two entries with the same payload rather than accumulating * per-mount state. diff --git a/tests/components/ShortcutsDialog.test.tsx b/tests/components/ShortcutsDialog.test.tsx index 7cede5f6e..fa2960b69 100644 --- a/tests/components/ShortcutsDialog.test.tsx +++ b/tests/components/ShortcutsDialog.test.tsx @@ -79,7 +79,7 @@ describe("ShortcutsDialog", () => { }); test("pressing ? inside Monaco's edit-context element does not open the dialog", () => { - // Monaco 0.56 focuses a div.native-edit-context inside .monaco-editor — neither an + // Monaco 0.57 focuses a div.native-edit-context inside .monaco-editor — neither an // /