Files
pgadmin4/web/package.json
T
Ashesh Vashi 5627944f87 chore(deps): bump JavaScript and Python third-party dependencies (#10023)
Combined fix for 8 packages flagged by GitHub Dependabot (collapsing
6 of them from open dependabot bump PRs and 4 from transitive
vulnerabilities with no existing PR). All eight are transitive — no
direct dep changes — so we override via `resolutions` in web/package.json
and let yarn collapse duplicate-version entries during install.

Resolved (pre → post via resolution):

  Runtime:
    ws                    8.20.0    -> 8.21.0    (patched 8.20.1)

  Dev:
    @xmldom/xmldom        0.7.13    -> 0.8.13    (patched 0.8.13)
    serialize-javascript  6.0.2,
                          7.0.5     -> 7.0.5     (patched 7.0.5)
    ip-address            10.1.0,
                          10.2.0    -> 10.2.0    (patched 10.1.1)
    postcss               8.5.8,
                          8.5.15    -> 8.5.15    (patched 8.5.10)
    qs                    6.15.0    -> 6.15.2    (patched 6.15.2)
    @tootallnate/once     2.0.0     -> 2.0.1     (patched 2.0.1)
    tar (7.x lineage)     7.5.13    -> 7.5.16    (patched 7.5.11)

The tar 6.2.1 lineage (consumed via ^6.1.2/^6.1.11) is unaffected by
these CVEs (alert ranges are 7.x-only), so the resolution is scoped
`tar@npm:^7.5.4` to leave it on 6.2.1.

Supersedes open dependabot PRs #9956 (ws), #9962 (tar), #9966
(@tootallnate/once), and #9974 (qs) — one CI cycle instead of four.

Verification:
- yarn install — clean (only pre-existing peer-dep warnings about
  @mui/system, aspen-core, eve, etc.; no new ones)
- yarn run test:js-once — 824 / 824 pass across 140 test suites
- yarn run bundle:dev — webpack compiled successfully
- All 8 packages confirmed at safe versions via lockfile audit;
  duplicate entries collapsed (yarn.lock net -64 lines)

Out of scope (cannot fix here):
- paramiko (#276 #278): no patched version exists; bump-to-5.0.0
  PRs #9927/#9930 audited 2026-05-20 and deferred to Q4 2026 over
  SSH bastion compat risk
- elliptic (#176): no patched version, dev-only, low severity
- flatted (#224): alert is stale; lockfile already at 3.4.2 (patched);
  will auto-dismiss on next dependabot rescan

* chore(deps): bump Python deps to latest 3.9-compatible

Picks up five Python dependency bumps that are 3.9-safe (still resolve
under Python 3.9 per PyPI requires_python). Four supersede open
dependabot PRs:

- certifi              2026.4.22  -> 2026.5.20
    (no gate; CA bundle refresh; supersedes dependabot #9977 / #9979)

- typer                0.25.*     -> 0.26.*
    (py > 3.9 row only; supersedes dependabot #9995 / #9999)

- testscenarios        0.6.1      -> 0.6.2
    (py > 3.9 row only; supersedes dependabot #9980)

- urllib3              2.6.*      -> 2.7.*  (py > 3.9 row only)
    Picks up two HIGH-severity security fixes in urllib3 2.7.0
    (2026-05-07): GHSA-mf9v-mfxr-j63j (decompression-bomb safeguards
    bypassed under drain_conn / Brotli stream patterns) and
    GHSA-qccp-gfcp-xxvc (ProxyManager.connection_from_url did not
    strip sensitive headers on cross-host redirects). 2.7.0 requires
    Python >=3.10, which the existing 'python_version > 3.9' gate
    already enforces.

- Flask-Security-Too   5.4.*      -> 5.6.* (py <= 3.9 row only)
    Closes a roughly 2-year gap between the 3.9 row (last pin from
    March 2024) and the py > 3.9 row (already on 5.8.*). 5.5/5.6
    only touched flows pgAdmin doesn't use (register V2, MFA / WebAuthn
    templates, username recovery/changing, secret_key rotation) and
    config pgAdmin overrides (default hash bcrypt->argon2 sidestepped
    by SECURITY_PASSWORD_HASH = 'pbkdf2_sha512'). The contract changes
    that mattered (LoginForm.validate -> is_active, UserMixin.is_locked
    hook, single-kwarg find_user) are all already exercised in
    production via the existing FST 5.8.* / Python 3.10+ deployments.
2026-06-08 16:02:43 +05:30

196 lines
6.9 KiB
JSON

{
"//": [
"IMPORTANT:",
"If runtime or build time dependencies are changed in this file, the ",
"committer *must* ensure the DEB and RPM package maintainers are informed ",
"as soon as possible."
],
"license": "PostgreSQL",
"devDependencies": {
"@babel/core": "^7.29.0",
"@babel/eslint-parser": "^7.28.6",
"@babel/eslint-plugin": "^7.27.1",
"@babel/plugin-syntax-jsx": "^7.28.6",
"@babel/plugin-transform-class-properties": "^7.28.6",
"@babel/plugin-transform-object-rest-spread": "^7.28.6",
"@babel/plugin-transform-runtime": "^7.29.0",
"@babel/preset-env": "^7.29.2",
"@babel/preset-react": "^7.28.5",
"@babel/preset-typescript": "^7.28.5",
"@emotion/memoize": "^0.9.0",
"@emotion/react": "^11.14.0",
"@emotion/styled": "^11.14.1",
"@emotion/utils": "^1.4.2",
"@svgr/webpack": "^8.1.0",
"@testing-library/dom": "10.4.1",
"@testing-library/jest-dom": "^6.9.1",
"@testing-library/react": "16.3.2",
"@testing-library/user-event": "^14.6.1",
"@types/jest": "^30.0.0",
"autoprefixer": "^10.5.0",
"axios-mock-adapter": "^2.1.0",
"babel-loader": "^10.1.1",
"browserify": "^17.0.1",
"buffer": "^6.0.3",
"copy-webpack-plugin": "^14.0.0",
"cross-env": "^10.1.0",
"css-loader": "^7.1.4",
"css-minimizer-webpack-plugin": "^8.0.0",
"eslint": "^9.39.4",
"eslint-plugin-jest": "^29.15.2",
"eslint-plugin-react": "^7.37.5",
"eslint-plugin-unused-imports": "^4.4.1",
"exports-loader": "^5.0.0",
"globals": "^17.5.0",
"html-react-parser": "^5.2.17",
"image-minimizer-webpack-plugin": "^4.1.4",
"imports-loader": "^5.0.0",
"jest": "^30.3.0",
"jest-environment-jsdom": "^30.3.0",
"loader-utils": "^3.3.1",
"mini-css-extract-plugin": "^2.10.2",
"postcss-loader": "^8.2.1",
"process": "^0.11.10",
"prop-types": "^15.8.1",
"resize-observer-polyfill": "^1.5.1",
"shim-loader": "^1.0.1",
"style-loader": "^4.0.0",
"stylis": "^4.4.0",
"svgo": "^4.0.1",
"svgo-loader": "^4.0.0",
"terser-webpack-plugin": "^5.5.0",
"typescript": "^6.0.3",
"typescript-eslint": "^8.59.0",
"url-loader": "^4.1.1",
"webfonts-loader": "^8.1.1",
"webpack": "^5.106.2",
"webpack-bundle-analyzer": "^5.3.0",
"webpack-cli": "^6.0.1",
"yarn-audit-html": "7.3.2"
},
"optionalDependencies": {
"sharp": "^0.34.4"
},
"dependencies": {
"@codemirror/lang-json": "^6.0.2",
"@codemirror/lang-sql": "^6.10.0",
"@date-io/core": "^3.2.0",
"@date-io/date-fns": "3.x",
"@emotion/sheet": "^1.4.0",
"@fluentui/keyboard-key": "^0.4.23",
"@fortawesome/fontawesome-free": "latest",
"@mui/icons-material": "^7.3.10",
"@mui/material": "^7.3.10",
"@mui/x-date-pickers": "^8.28.3",
"@nozbe/microfuzz": "^1.0.0",
"@projectstorm/react-diagrams": "^7.0.4",
"@simonwep/pickr": "^1.9.1",
"@szhsin/react-menu": "^4.5.1",
"@tanstack/react-query": "^5.100.9",
"@tanstack/react-table": "^8.21.3",
"@tanstack/react-virtual": "^3.13.24",
"@types/react": "^19.2.14",
"@types/react-dom": "^19.2.3",
"@xterm/addon-fit": "^0.11.0",
"@xterm/addon-search": "^0.16.0",
"@xterm/addon-web-links": "^0.12.0",
"@xterm/xterm": "^6.0.0",
"ajv": "^8.18.0",
"anti-trojan-source": "^1.8.1",
"aspen-decorations": "^1.1.1",
"axios": "^1.16.0",
"babelify": "~10.0.0",
"bignumber.js": "^10.0.2",
"brace": "^0.11.1",
"chart.js": "^4.5.1",
"chartjs-plugin-zoom": "^2.2.0",
"codemirror": "^6.0.2",
"convert-units": "^2.3.4",
"date-fns": "^4.1.0",
"diff-arrays-of-objects": "^1.1.10",
"dompurify": "^3.4.1",
"hotkeys-js": "^4.0.3",
"html-to-image": "1.11.11",
"immutability-helper": "^3.1.1",
"insert-if": "^1.2.0",
"ip-address": "^10.1.1",
"json-bignumber": "^1.1.1",
"leaflet": "^1.9.4",
"lodash": "4.*",
"marked": "^18.0.2",
"moment": "^2.30.1",
"moment-timezone": "^0.6.2",
"notificar": "^1.0.1",
"notistack": "^3.0.2",
"papaparse": "^5.5.3",
"path-fx": "^2.1.2",
"postcss": "^8.5.14",
"rc-dock": "^4.0.0-alpha.2",
"react": "^19.2.5",
"react-arborist": "^3.5.0",
"react-aspen": "^1.2.0",
"react-checkbox-tree": "^2.0.1",
"react-data-grid": "https://github.com/pgadmin-org/react-data-grid.git#8ddaa7bed99c8329e39b8ff37ba156f7fc8e85d4",
"react-dnd": "^16.0.1",
"react-dnd-html5-backend": "^16.0.1",
"react-dom": "^19.2.5",
"react-draggable": "^4.5.0",
"react-dropzone": "^15.0.0",
"react-frame-component": "~5.2.6",
"react-leaflet": "^4.2.1",
"react-new-window": "^1.0.1",
"react-resize-detector": "^12.3.0",
"react-rnd": "^10.5.3",
"react-select": "^5.10.2",
"react-timer-hook": "^4.0.5",
"react-virtualized-auto-sizer": "^2.0.3",
"snapsvg-cjs": "^0.0.6",
"socket.io-client": "^4.8.3",
"split.js": "^1.6.5",
"sql-formatter": "^15.7.3",
"uplot": "^1.6.32",
"uplot-react": "^1.2.4",
"use-resize-observer": "^9.1.0",
"valid-filename": "^4.0.0",
"vanilla-jsoneditor": "^3.12.0",
"wkx": "^0.5.0",
"zustand": "^5.0.12"
},
"resolutions": {
"rc-resize-observer": "1.4.0",
"@xmldom/xmldom": "^0.8.13",
"serialize-javascript": "^7.0.5",
"ip-address": "^10.1.1",
"postcss": "^8.5.10",
"ws": "^8.20.1",
"qs": "^6.15.2",
"@tootallnate/once": "^2.0.1",
"tar@npm:^7.5.4": "^7.5.15"
},
"scripts": {
"linter": "yarn run eslint -c .eslintrc.js .",
"webpacker": "yarn run webpack --config webpack.config.js --progress",
"webpacker:watch": "yarn run webpack --config webpack.config.js --progress --watch",
"bundle:watch": "yarn run linter && yarn run webpacker:watch",
"bundle:dev": "yarn run linter && yarn run webpacker",
"bundle:analyze": "cross-env NODE_ENV=production ANALYZE=true yarn run bundle:dev",
"bundle": "cross-env NODE_ENV=production NODE_OPTIONS=--max-old-space-size=3072 yarn run bundle:dev && yarn run git:hash",
"git:hash": "git log -1 --format=\"%H %as\" > commit_hash",
"test:js-once": "yarn run linter && yarn run jest --maxWorkers=50%",
"test:js": "yarn run test:js-once --watch",
"test:js-file": "yarn run test:js-once -t",
"test:js-coverage": "yarn run test:js-once --collect-coverage",
"test:feature": "yarn run bundle && python regression/runtests.py --pkg feature_tests",
"test": "yarn run test:js-once && yarn run bundle && python regression/runtests.py",
"pep8": "pycodestyle --config=../.pycodestyle ../docs ../pkg ../tools ../web",
"auditjs-html": "yarn audit --json | yarn run yarn-audit-html --output ../auditjs.html",
"auditjs": "yarn audit --groups dependencies",
"auditpy": "safety check --full-report -i 51668 -i 52495",
"audit-all": "yarn run auditjs && yarn run auditpy"
},
"packageManager": "yarn@4.15.0",
"browserslist": [
"defaults and fully supports es6-module"
]
}