Files
pgadmin4/web/package.json
T
Ashesh Vashi 8812025a8a chore(deps): Bump patch/minor dependency bumps (#10176)
Consolidates 20 open dependabot PRs (JS + Python) into one bump, applied
directly rather than cherry-picked (PR branches were stale and would have
reverted unrelated fixes like the yarn packageManager pin). Adds further
same-major patch/minor bumps found by auditing beyond dependabot's own PR
list.

JS (web + runtime): axios, brace-expansion, form-data, undici, js-yaml,
dompurify, @babel/core, webpack, sharp, electron, eslint, react-checkbox-tree,
autoprefixer, eslint-plugin-jest, globals, jest, jest-environment-jsdom, svgo,
terser-webpack-plugin, typescript-eslint, webpack-bundle-analyzer,
@date-io/date-fns, @szhsin/react-menu, @tanstack/react-query, @types/react,
ajv, anti-trojan-source, ip-address, marked, moment-timezone, papaparse,
postcss, react, react-dom, react-draggable, react-timer-hook, sql-formatter,
zustand.

Python: certifi, selenium (version-gated: 4.45.0 requires Python >=3.10,
4.44.0 kept for <=3.9 to preserve Python 3.9 support).

Reverted / excluded, with reasons:
- azure-mgmt-resource 26.0.0: moved ResourceManagementClient from
  azure.mgmt.resource to azure.mgmt.resource.resources, breaking
  pgadmin/misc/cloud/azure/__init__.py at import time. Caught by the Python
  regression suite. Kept at 25.0.0.
- @simonwep/pickr 1.10.0: switched its build tool to tsup, which marks its
  UMD bundle as an ES module via Symbol.toStringTag instead of the
  __esModule flag Babel's interop helper checks for. Babel double-wraps the
  export, so `new Pickr(...)` resolves to a non-constructor and crashes
  every dialog that mounts a color picker -- reproduces only in the
  production/minified webpack build, not the dev bundle or Jest. Pinned to
  ~1.9.1 (tilde, not caret) so a future install can't silently float back to
  1.10.x.
- paramiko 3->5 (#9927): structurally blocked by sshtunnel 0.4.0 still
  referencing paramiko.DSSKey.
- @mui/material / @mui/x-date-pickers 7/8->9 (#10091, #10092): known
  UI-breaking, needs the accompanying component fixes tracked on a separate
  branch, not a bare version bump.
- react-arborist, @tanstack/react-virtual, react-frame-component: same-major
  bumps available but excluded -- core object-browser tree, already-fragile
  virtualization code, or tilde-pinned range respectively.
- A handful of JS packages hit Yarn 4.15's registry quarantine gate (blocks
  just-published versions); backed off to the next-older version instead of
  forcing through.

Added core-js as an explicit devDependency: it was never declared despite
webpack's Babel config (useBuiltIns: 'usage', corejs: 3) requiring it --
it only worked because @simonwep/pickr 1.9.1 happened to pull it in
transitively, which broke when pickr was briefly bumped.

Verified: eslint (web + runtime), full JS test suite (149/149 suites,
916/916 tests), webpack production build compiles clean, Python regression
suite (2388/2388, excl. Selenium), Selenium feature_tests (17/19 pass; the
2 failures trace to a local pldbgapi-extension gap, unrelated to any
bumped dependency).
2026-07-23 15:28:38 +05:30

203 lines
7.1 KiB
JSON

{
"//": [
"IMPORTANT:",
"If runtime or build time dependencies are changed in this file, the ",
"committer *must* ensure the DEB and RPM package maintainers are informed ",
"as soon as possible."
],
"license": "PostgreSQL",
"devDependencies": {
"@babel/core": "^7.29.6",
"@babel/eslint-parser": "^7.28.6",
"@babel/eslint-plugin": "^7.27.1",
"@babel/plugin-syntax-jsx": "^7.28.6",
"@babel/plugin-transform-class-properties": "^7.28.6",
"@babel/plugin-transform-object-rest-spread": "^7.28.6",
"@babel/plugin-transform-runtime": "^7.29.0",
"@babel/preset-env": "^7.29.2",
"@babel/preset-react": "^7.28.5",
"@babel/preset-typescript": "^7.28.5",
"@emotion/memoize": "^0.9.0",
"@emotion/react": "^11.14.0",
"@emotion/styled": "^11.14.1",
"@emotion/utils": "^1.4.2",
"@svgr/webpack": "^8.1.0",
"@testing-library/dom": "10.4.1",
"@testing-library/jest-dom": "^6.9.1",
"@testing-library/react": "16.3.2",
"@testing-library/user-event": "^14.6.1",
"@types/jest": "^30.0.0",
"autoprefixer": "^10.5.4",
"axios-mock-adapter": "^2.1.0",
"babel-loader": "^10.1.1",
"browserify": "^17.0.1",
"buffer": "^6.0.3",
"copy-webpack-plugin": "^14.0.0",
"core-js": "^3.49.0",
"cross-env": "^10.1.0",
"css-loader": "^7.1.4",
"css-minimizer-webpack-plugin": "^8.0.0",
"eslint": "^9.39.4",
"eslint-plugin-jest": "^29.15.5",
"eslint-plugin-react": "^7.37.5",
"eslint-plugin-unused-imports": "^4.4.1",
"exports-loader": "^5.0.0",
"globals": "^17.7.0",
"html-react-parser": "^5.2.17",
"image-minimizer-webpack-plugin": "^4.1.4",
"imports-loader": "^5.0.0",
"jest": "^30.4.2",
"jest-environment-jsdom": "^30.4.1",
"loader-utils": "^3.3.1",
"mini-css-extract-plugin": "^2.10.2",
"postcss-loader": "^8.2.1",
"process": "^0.11.10",
"prop-types": "^15.8.1",
"resize-observer-polyfill": "^1.5.1",
"shim-loader": "^1.0.1",
"style-loader": "^4.0.0",
"stylis": "^4.4.0",
"svgo": "^4.0.2",
"svgo-loader": "^4.0.0",
"terser-webpack-plugin": "^5.6.1",
"typescript": "^6.0.3",
"typescript-eslint": "^8.65.0",
"url-loader": "^4.1.1",
"webfonts-loader": "^8.1.1",
"webpack": "^5.108.4",
"webpack-bundle-analyzer": "^5.3.1",
"webpack-cli": "^6.0.1",
"yarn-audit-html": "7.3.2"
},
"optionalDependencies": {
"sharp": "^0.35.3"
},
"dependencies": {
"@codemirror/lang-json": "^6.0.2",
"@codemirror/lang-sql": "^6.10.0",
"@date-io/core": "^3.2.0",
"@date-io/date-fns": "^3.2.1",
"@emotion/sheet": "^1.4.0",
"@fluentui/keyboard-key": "^0.4.23",
"@fortawesome/fontawesome-free": "latest",
"@mui/icons-material": "^7.3.10",
"@mui/material": "^7.3.10",
"@mui/x-date-pickers": "^8.28.3",
"@nozbe/microfuzz": "^1.0.0",
"@projectstorm/react-diagrams": "^7.0.4",
"@simonwep/pickr": "~1.9.1",
"@szhsin/react-menu": "^4.5.2",
"@tanstack/react-query": "^5.101.4",
"@tanstack/react-table": "^8.21.3",
"@tanstack/react-virtual": "^3.13.24",
"@types/react": "^19.2.17",
"@types/react-dom": "^19.2.3",
"@xterm/addon-fit": "^0.11.0",
"@xterm/addon-search": "^0.16.0",
"@xterm/addon-web-links": "^0.12.0",
"@xterm/xterm": "^6.0.0",
"ajv": "^8.20.0",
"anti-trojan-source": "^1.12.0",
"aspen-decorations": "^1.1.1",
"axios": "^1.18.1",
"babelify": "~10.0.0",
"bignumber.js": "^10.0.2",
"brace": "^0.11.1",
"chart.js": "^4.5.1",
"chartjs-plugin-zoom": "^2.2.0",
"codemirror": "^6.0.2",
"convert-units": "^2.3.4",
"date-fns": "^4.4.0",
"diff-arrays-of-objects": "^1.1.10",
"dompurify": "^3.4.12",
"hotkeys-js": "^4.0.4",
"html-to-image": "1.11.13",
"immutability-helper": "^3.1.1",
"insert-if": "^1.2.0",
"ip-address": "^10.2.0",
"json-bignumber": "^1.1.1",
"leaflet": "^1.9.4",
"lodash": "4.*",
"lossless-json": "^4.3.0",
"marked": "^18.0.7",
"moment": "^2.30.1",
"moment-timezone": "^0.6.3",
"notificar": "^1.0.1",
"notistack": "^3.0.2",
"papaparse": "^5.5.4",
"path-fx": "^2.1.2",
"postcss": "^8.5.20",
"rc-dock": "^4.0.0-alpha.2",
"react": "^19.2.7",
"react-arborist": "^3.5.0",
"react-aspen": "^1.2.0",
"react-checkbox-tree": "^2.0.2",
"react-data-grid": "https://github.com/pgadmin-org/react-data-grid.git#8ddaa7bed99c8329e39b8ff37ba156f7fc8e85d4",
"react-dnd": "^16.0.1",
"react-dnd-html5-backend": "^16.0.1",
"react-dom": "^19.2.7",
"react-draggable": "^4.7.0",
"react-dropzone": "^15.0.0",
"react-frame-component": "~5.2.6",
"react-leaflet": "^4.2.1",
"react-new-window": "^1.0.1",
"react-resize-detector": "^12.3.0",
"react-rnd": "^10.5.3",
"react-select": "^5.10.2",
"react-timer-hook": "^4.0.6",
"react-virtualized-auto-sizer": "^2.0.3",
"snapsvg-cjs": "^0.0.6",
"socket.io-client": "^4.8.3",
"split.js": "^1.6.5",
"sql-formatter": "^15.8.2",
"uplot": "^1.6.32",
"uplot-react": "^1.2.4",
"use-resize-observer": "^9.1.0",
"valid-filename": "^4.0.0",
"vanilla-jsoneditor": "^3.12.0",
"wkx": "^0.5.0",
"zustand": "^5.0.14"
},
"resolutions": {
"rc-resize-observer": "1.4.0",
"@xmldom/xmldom": "^0.8.13",
"serialize-javascript": "^7.0.5",
"ip-address": "^10.2.0",
"postcss": "^8.5.20",
"ws": "^8.20.1",
"qs": "^6.15.2",
"@tootallnate/once": "^2.0.1",
"tar@npm:^7.5.4": "^7.5.15",
"ttf2woff2/node-gyp": "^11.2.0",
"js-yaml@npm:^3.13.1": "^3.15.0",
"form-data@npm:^4.0.5": "^4.0.6",
"brace-expansion@npm:^1.1.7": "^1.1.16",
"brace-expansion@npm:^5.0.5": "^5.0.7"
},
"scripts": {
"linter": "yarn run eslint -c .eslintrc.js .",
"webpacker": "yarn run webpack --config webpack.config.js --progress",
"webpacker:watch": "yarn run webpack --config webpack.config.js --progress --watch",
"bundle:watch": "yarn run linter && yarn run webpacker:watch",
"bundle:dev": "yarn run linter && yarn run webpacker",
"bundle:analyze": "cross-env NODE_ENV=production ANALYZE=true yarn run bundle:dev",
"bundle": "cross-env NODE_ENV=production NODE_OPTIONS=--max-old-space-size=3072 yarn run bundle:dev && yarn run git:hash",
"git:hash": "git log -1 --format=\"%H %as\" > commit_hash",
"test:js-once": "yarn run linter && yarn run jest --maxWorkers=50%",
"test:js": "yarn run test:js-once --watch",
"test:js-file": "yarn run test:js-once -t",
"test:js-coverage": "yarn run test:js-once --collect-coverage",
"test:feature": "yarn run bundle && python regression/runtests.py --pkg feature_tests",
"test": "yarn run test:js-once && yarn run bundle && python regression/runtests.py",
"pep8": "pycodestyle --config=../.pycodestyle ../docs ../pkg ../tools ../web",
"auditjs-html": "yarn audit --json | yarn run yarn-audit-html --output ../auditjs.html",
"auditjs": "yarn audit --groups dependencies",
"auditpy": "safety check --full-report -i 51668 -i 52495",
"audit-all": "yarn run auditjs && yarn run auditpy"
},
"packageManager": "yarn@4.15.0",
"browserslist": [
"defaults and fully supports es6-module"
]
}