Skip to content

deps(deps): bump pg and @types/pg#24

Closed
dependabot[bot] wants to merge 4 commits intomainfrom
dependabot/npm_and_yarn/main/multi-d574a1ab67
Closed

deps(deps): bump pg and @types/pg#24
dependabot[bot] wants to merge 4 commits intomainfrom
dependabot/npm_and_yarn/main/multi-d574a1ab67

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Jan 27, 2026

Bumps pg and @types/pg. These dependencies needed to be updated together.
Updates pg from 8.13.1 to 8.17.2

Changelog

Sourced from pg's changelog.

All major and minor releases are briefly explained below.

For richer information consult the commit log on github with referenced pull requests.

We do not include break-fix version release in this file.

pg@8.17.0

  • Throw correct error if database URL parsing fails.

pg@8.16.0

pg@8.15.0

  • Add support for esm importing. CommonJS importing is still also supported.

pg@8.14.0

pg@8.13.0

pg@8.12.0

pg-pool@8.10.0

  • Emit release event when client is returned to the pool.

pg@8.9.0

pg@8.8.0

pg-pool@3.5.0

... (truncated)

Commits

Updates @types/pg from 8.11.10 to 8.16.0

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

dependabot bot and others added 4 commits January 27, 2026 22:10
Security fix: js-yaml 4.1.0 → 4.1.1 (prototype pollution fix)
…dates (#14)

Dependency updates with security fixes for glob, lodash (prototype pollution), qs, and tar
…ning (#13)

Portfolio redesign with CI/CD, Vercel fixes, and security hardening

Major changes:
- Complete UI/UX redesign with modern components
- GitHub Actions CI/CD pipeline (lint, build, security, lighthouse)
- Vercel deployment fixes (CORS, rate limiting, SPA routing)
- CodeQL security fixes (path traversal, rate limiting)
- Dependency updates and vulnerability fixes
Bumps [pg](https://github.com/brianc/node-postgres/tree/HEAD/packages/pg) and [@types/pg](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/pg). These dependencies needed to be updated together.

Updates `pg` from 8.13.1 to 8.17.2
- [Changelog](https://github.com/brianc/node-postgres/blob/master/CHANGELOG.md)
- [Commits](https://github.com/brianc/node-postgres/commits/pg@8.17.2/packages/pg)

Updates `@types/pg` from 8.11.10 to 8.16.0
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/pg)

---
updated-dependencies:
- dependency-name: pg
  dependency-version: 8.17.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
- dependency-name: "@types/pg"
  dependency-version: 8.16.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Jan 27, 2026

Labels

The following labels could not be found: automated. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Jan 27, 2026
@github-actions
Copy link

⚠️ Minor update - Manual review recommended

This is a minor version update for a runtime dependency.

Dependencies: pg, @types/pg
Update type: Minor

Please review:

  1. Check the changelog for new features
  2. Ensure backward compatibility
  3. Test locally if making significant changes

CI will run automatically. Merge manually after reviewing.

@Xza85hrf Xza85hrf closed this Jan 28, 2026
@Xza85hrf Xza85hrf deleted the dependabot/npm_and_yarn/main/multi-d574a1ab67 branch January 28, 2026 16:29
@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Jan 28, 2026

OK, I won't notify you again about this release, but will get in touch when a new version is available. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant