mirror of
https://github.com/pgadmin-org/pgadmin4.git
synced 2026-08-17 16:34:44 -05:00
Python (requirements.txt): - boto3 1.42.* -> 1.43.* (#9908) - psycopg 3.3.3 -> 3.3.4 (#9911) for python_version >= '3.10' JavaScript (web/package.json, web/yarn.lock): - axios 1.15.2 -> 1.16.0 (matches dependabot's #9907 in /runtime, applied to /web for cross-package consistency) Electron runtime (runtime/package.json, runtime/yarn.lock): - axios 1.15.2 -> 1.16.0 (#9907) - electron 41.3.0 -> 41.5.0 (#9910) - eslint 10.2.1 -> 10.3.0 (#9912) - globals 17.5.0 -> 17.6.0 (#9909) follow-redirects 1.15.11 -> 1.16.0 transitively Skipped (genuine breaking changes, deferred to a future minor): - @mui/material 7 -> 9 (#9843) - @mui/x-date-pickers 8 -> 9 (#9888) Verified in an isolated worktree: - jest: 140/0/0 suites, 824/0/0 tests - eslint: clean (silent) - pycodestyle: 0 violations project-wide - python regression: 1879/0/308 (PG18, --exclude feature_tests) The axios 1.16.0 release notes call out three observable changes; only the first is potentially relevant to pgAdmin and is a bugfix: - Fetch adapter now enforces maxBodyLength / maxContentLength (these were silently ignored on the fetch adapter before 1.16.0). pgAdmin does not set these limits, so behaviour is unchanged. - Proxy requests preserve user-supplied Host headers — pgAdmin does not proxy through axios. - Basic-auth credentials embedded in URLs are URL-decoded — pgAdmin does not construct credential-embedded URLs. psycopg 3.3.4 brings three bugfixes: spurious connection-timeout in C extension on long-uptime systems, client-side adaptation of enums whose names need quoting, and consistent Cursor.statusmessage after executemany(). electron 41.5.0 is a patch within the 41.x line carrying Chromium security backports plus a Windows frameless-window resize regression fix and a low-level mouse-hook teardown fix.