Skip to content

fix(security): patch hono, ajv, and uuid vulnerabilities - #29514

Merged
aqrln merged 1 commit into
mainfrom
fix-pnpm-audit
Apr 27, 2026
Merged

fix(security): patch hono, ajv, and uuid vulnerabilities#29514
aqrln merged 1 commit into
mainfrom
fix-pnpm-audit

Conversation

@aqrln

@aqrln aqrln commented Apr 24, 2026

Copy link
Copy Markdown
Member

Summary

Resolves the production-dependency vulnerabilities flagged by pnpm audit --prod in CI (.github/workflows/test-template.yml).

Before: 8 moderate-severity vulns across hono, ajv, and uuid. After: No known vulnerabilities found.

Changes

packages/client-engine-runtime/package.json

  • Bump uuid from 11.1.014.0.0 to pick up GHSA-w5hq-g745-h8pq (missing buffer bounds check in v3/v5/v6). We only call v4() and v7() with no arguments, so the API surface is unchanged; see the changelog review below.

package.json (pnpm.overrides)

  • hono: >=4.12.4>=4.12.14 (existing override bumped to cover six new hono advisories; pulled in via prisma > @prisma/dev > hono).
  • ajv@^8.0.0: >=8.18.0 — patches GHSA-2g4f-4pwh-qvx6 ReDoS (via @prisma/dev > @prisma/streams-local > ajv). Scoped to the v8 line so ajv@6 (used by webpack etc.) is untouched.
  • @azure/core-rest-pipeline@^1.0.0: >=1.14.0 — newer 1.x dropped uuid as a dependency entirely, which eliminates the vulnerable transitive path through adapter-mssql > mssql > tedious > @azure/identity > @azure/core-rest-pipeline > uuid.
  • @azure/msal-node>uuid: >=14.0.0 — selector-style override for the remaining transitive uuid@8.3.2 path. Only rewires uuid inside @azure/msal-node; other consumers' uuid versions are untouched.

uuid 11.1.0 → 14.0.0 changelog review

Our only uuid usage is v4() and v7() with no arguments, in packages/client-engine-runtime/src/interpreter/generators.ts. The transitive path through @azure/msal-node also only calls v4().

Version Breaking change Impact
12.0.0 Drop node@16 None — Prisma requires ^20.19 || ^22.12 || >=24.0.
12.0.0 Require TypeScript ≥ 5.2 None — Prisma CLI peers on typescript: ">=5.4.0", internal TS is 5.4.5.
12.0.0 Remove CommonJS support (ESM-only) Handled. esbuild inlines uuid into our CJS output (same as nanoid@5 already does). For msal-node's require('uuid'), Node's require(esm) is available from Node 20.19 (our minimum), verified locally. uuid@14 has no top-level await.
13.0.0 Make browser exports the default (rename dist-node / dist) None — both node and default conditions are still wired correctly.
14.0.0 Require global crypto (node@20+) None — Web Crypto is a stable Node global since v19.0.0.
14.0.0 Drop node@18 None.
14.0.0 TypeScript ≥ 5.4.3 None.
14.0.0 security fix v3/v5/v6 throw RangeError on bad offset/buf None — we don't call those.

Verification

  • pnpm audit --prodNo known vulnerabilities found.
  • pnpm build at the repo root → 44/44 tasks succeed.
  • @prisma/client-engine-runtime vitest: 195/195 pass (includes generators.test.ts format checks for v4 / v7).
  • @prisma/adapter-mssql vitest: 86/86 pass (exercises the overridden Azure chain at import/type-check time).
  • Verified require('uuid') works at runtime on Node 24 from packages/client-engine-runtime and from @azure/msal-node's CJS GuidGenerator.

Not included

The root pnpm audit (without --prod) still reports many dev-only advisories (wrangler, vite, jest → braces/picomatch, webpack, etc.). CI only runs --prod, so those don't block the build; fixing them is out of scope.

Resolves the production vulnerabilities flagged by `pnpm audit --prod` in CI:

- Bump `uuid` to 14.0.0 in `@prisma/client-engine-runtime` to pick up
  the fix for GHSA-w5hq-g745-h8pq (v3/v5/v6 missing bounds check).
- Bump the existing `hono` override from `>=4.12.4` to `>=4.12.14` to
  cover six new advisories in the hono chain (pulled in via
  `prisma > @prisma/dev > hono`).
- Add an `ajv@^8.0.0` override to `>=8.18.0` to patch
  GHSA-2g4f-4pwh-qvx6 ReDoS, scoped to the v8 line so ajv@6 (used by
  webpack etc.) is untouched.
- Add an `@azure/core-rest-pipeline@^1.0.0` override to `>=1.14.0`.
  Newer 1.x versions dropped their `uuid` dependency entirely, which
  eliminates the vulnerable transitive path through
  `adapter-mssql > mssql > tedious > @azure/identity > @azure/core-rest-pipeline > uuid`.
- Add a scoped `@azure/msal-node>uuid` override to `>=14.0.0` for the
  remaining transitive `uuid@8.3.2` path. Only msal-node's uuid is
  rewired; other consumers keep their existing versions. The CJS build
  of msal-node's `GuidGenerator` loads uuid via `require('uuid')`,
  which works on our supported Node range (20.19+, 22.12+, 24+) via
  `require(esm)`.
@coderabbitai

coderabbitai Bot commented Apr 24, 2026

Copy link
Copy Markdown
Contributor

Summary by CodeRabbit

  • Chores
    • Updated runtime package dependencies and transitive dependency versions to improve overall application stability, compatibility, and security posture
    • Enhanced dependency version constraints and management configuration throughout the application ecosystem to ensure consistent library versions across all components, effectively reducing potential compatibility issues and improving system reliability

Walkthrough

Dependency version updates across configuration files. The root pnpm.overrides section increases the hono minimum version and introduces new constraint overrides for ajv, @azure/core-rest-pipeline, and uuid (under @azure/msal-node). The client-engine-runtime package updates its direct uuid dependency from 11.1.0 to 14.0.0.

Changes

Cohort / File(s) Summary
pnpm dependency overrides
package.json
Increased hono minimum from >=4.12.4 to >=4.12.14; added new override constraints for ajv (^8.0.0), @azure/core-rest-pipeline (^1.0.0), and uuid nested under @azure/msal-node.
Runtime dependency update
packages/client-engine-runtime/package.json
Updated uuid dependency from 11.1.0 to 14.0.0.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title accurately and concisely summarizes the main change—patching security vulnerabilities in hono, ajv, and uuid—which is the primary objective of the PR.
Description check ✅ Passed The description provides comprehensive detail about the vulnerability fixes, dependency updates, changelog review, and verification steps—all directly relevant to the changeset.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix-pnpm-audit
✨ Simplify code
  • Create PR with simplified code
  • Commit simplified code in branch fix-pnpm-audit

Comment @coderabbitai help to get the list of available commands and usage tips.

@aqrln aqrln added this to the 7.9.0 milestone Apr 24, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Inline comments:
In `@package.json`:
- Line 173: Update verification for the "@azure/msal-node>uuid": ">=14.0.0"
override: ensure your deployment and CI use Node 20+ (or higher) and that
`@azure/msal-node` version in package.json is compatible with uuid v14's
ESM-only/crypto API changes; if not, either pin uuid to a supported v8/v12 range
or upgrade `@azure/msal-node` to a release that explicitly supports uuid v14/Node
20+, add an "engines" hint in package.json to require Node 20+, and run
end-to-end authentication flows to validate there are no runtime
RangeError/interop issues from uuid’s stricter validation or module system
differences.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro

Run ID: c80ac9e5-9c39-4938-88e4-af3ad024e919

📥 Commits

Reviewing files that changed from the base of the PR and between 62b44ac and e781317.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (2)
  • package.json
  • packages/client-engine-runtime/package.json

Comment thread package.json
@github-actions

Copy link
Copy Markdown
Contributor

size-limit report 📦

Path Size
packages/client/runtime/index-browser.js 2.29 KB (0%)
packages/client/runtime/index-browser.d.ts 3.37 KB (0%)
packages/cli/build/index.js 2.54 MB (0%)
packages/client/prisma-client-0.0.0.tgz 26.82 MB (-0.01% 🔽)
packages/cli/prisma-0.0.0.tgz 13.53 MB (0%)
packages/bundle-size/da-workers-libsql/output.tgz 1.33 MB (+0.01% 🔺)
packages/bundle-size/da-workers-neon/output.tgz 1.39 MB (+0.01% 🔺)
packages/bundle-size/da-workers-pg/output.tgz 1.39 MB (+0.01% 🔺)
packages/bundle-size/da-workers-planetscale/output.tgz 1.33 MB (+0.01% 🔺)
packages/bundle-size/da-workers-d1/output.tgz 1.31 MB (+0.01% 🔺)

@codspeed-hq

codspeed-hq Bot commented Apr 24, 2026

Copy link
Copy Markdown

Merging this PR will improve performance by 22.3%

⚠️ Different runtime environments detected

Some benchmarks with significant performance changes were compared across different runtime environments,
which may affect the accuracy of the results.

Open the report in CodSpeed to investigate

⚡ 1 improved benchmark
✅ 16 untouched benchmarks
⏩ 30 skipped benchmarks1

Performance Changes

Benchmark BASE HEAD Efficiency
getBinaryTargetForCurrentPlatform 2 ms 1.7 ms +22.3%

Comparing fix-pnpm-audit (e781317) with main (62b44ac)

Open in CodSpeed

Footnotes

  1. 30 benchmarks were skipped, so the baseline results were used instead. If they were deleted from the codebase, click here and archive them to remove them from the performance reports.

@aqrln
aqrln merged commit ec30a5d into main Apr 27, 2026
252 of 253 checks passed
@aqrln
aqrln deleted the fix-pnpm-audit branch April 27, 2026 09:08
OIRNOIR pushed a commit to OIRNOIR/YouTube-Helper-Server that referenced this pull request Jul 28, 2026
This PR contains the following updates:

| Package | Type | Update | Change | Pending |
|---|---|---|---|---|
| [@prisma/adapter-pg](https://github.com/prisma/prisma) ([source](https://github.com/prisma/prisma/tree/HEAD/packages/adapter-pg)) | imports | minor | [`7.8.0` -> `7.9.0`](https://renovatebot.com/diffs/npm/@prisma%2fadapter-pg/7.8.0/7.9.0) | `7.9.1` |
| [@prisma/client](https://www.prisma.io) ([source](https://github.com/prisma/prisma/tree/HEAD/packages/client)) | imports | minor | [`7.8.0` -> `7.9.0`](https://renovatebot.com/diffs/npm/@prisma%2fclient/7.8.0/7.9.0) | `7.9.1` |
| [prisma](https://www.prisma.io) ([source](https://github.com/prisma/prisma/tree/HEAD/packages/cli)) | imports | minor | [`7.8.0` -> `7.9.0`](https://renovatebot.com/diffs/npm/prisma/7.8.0/7.9.0) | `7.9.1` |

---

### Release Notes

<details>
<summary>prisma/prisma (@&#8203;prisma/adapter-pg)</summary>

### [`v7.9.0`](https://github.com/prisma/prisma/releases/tag/7.9.0)

[Compare Source](prisma/orm@7.8.0...7.9.0)

Today, we are excited to share the `7.9.0` stable release 🎉

**🌟 Star this repo for notifications about new releases, bug fixes & features — or [follow us on X](https://pris.ly/x)!**

##### Highlights

##### ORM

##### Tab completions for the Prisma CLI

Typing out CLI commands from memory is now optional. Prisma ships **shell tab completions** for `bash`, `zsh`, `fish`, and PowerShell, covering commands, subcommands, options, flags, and even option values.

**Setting it up.** Most projects run Prisma through a package manager, so completions are enabled through `@bomb.sh/tab`'s package-manager integration — install it once, then source the completion for your package manager and shell:

```bash

# 1. Install @&#8203;bomb.sh/tab globally
npm install -g @&#8203;bomb.sh/tab

# 2. Wire up your package manager + shell (pnpm shown; swap in npm / yarn / bun):
echo 'source <(tab pnpm zsh)'  >> ~/.zshrc            # zsh
echo 'source <(tab pnpm bash)' >> ~/.bashrc           # bash
tab pnpm fish > ~/.config/fish/completions/pnpm.fish  # fish
tab pnpm powershell > ~/.tab-pnpm.ps1                 # PowerShell (then dot-source it from $PROFILE)
```

`@bomb.sh/tab` delegates to any locally-installed CLI that ships completions, so `pnpm prisma <TAB>`, `pnpm exec prisma <TAB>`, `yarn prisma <TAB>`, and `bun x prisma <TAB>` all complete Prisma's commands, options, and values — no per-project setup. (`npx` and `bunx` don't support completion themselves; use `npm exec` and `bun x`.)

If instead you have Prisma installed globally on your `PATH`, source its own completion directly: `source <(prisma complete zsh)` (or the `bash` / `fish` / `powershell` variant).

This is built on [`@bomb.sh/tab`](https://github.com/bombshell-dev/tab/), the same completion library that powers other CLIs in the ecosystem — including Cloudflare, Nuxt, and Vitest — so the package-manager completions you enable for Prisma work for those tools too. A wonderful community contribution from [@&#8203;AmirSa12](https://github.com/AmirSa12) ([#&#8203;28351](prisma/orm#28351)) — thank you!

<https://github.com/user-attachments/assets/1f916a60-ee4d-40be-bb7d-74035d48ca83>

##### Prisma ORM, ready for AI agents

Coding agents are now a first-class audience for Prisma, and 7.9.0 brings the first wave of work to make Prisma projects safe and productive for them to work in.

**Agent skills installed with `prisma init`** ([#&#8203;29689](prisma/orm#29689))

`prisma init` now installs the [prisma/skills](https://github.com/prisma/skills) catalog into freshly scaffolded projects. Agents such as Claude Code, Cursor, Codex, and Windsurf start out with current, version-relevant Prisma knowledge instead of relying on whatever happened to be in their training data. The install is best-effort and never blocks scaffolding; opt out at any time with `--no-skills`.

```terminal
npx prisma@latest init
```

![prisma init scaffolds a project and installs the Prisma agent skills catalog](https://github.com/user-attachments/assets/8244a6dc-cdad-4028-a652-bb5ac6e4b271)

**A safer default around destructive commands** ([#&#8203;29684](prisma/orm#29684), [#&#8203;29691](prisma/orm#29691), [#&#8203;29713](prisma/orm#29713))

Prisma's AI safety checkpoint refuses to run destructive commands when it detects that an AI agent is at the keyboard, unless the user has given explicit consent. In this release we:

- **Broadened agent detection** to cover today's landscape — Codex CLI (now on Linux as well as macOS), Qwen Code, GitHub Copilot CLI, OpenCode, Cline, Goose, Amp, Crush, Augment Code, Antigravity, Replit Agent, and Devin — plus generic `AI_AGENT` / `AGENT` conventions so future agents are caught without a code change.
- **Extended the guard to `db push --accept-data-loss`**, which previously bypassed the checkpoint even though it can drop data.
- **Removed the `migrate-reset` tool from the `prisma mcp` server** entirely — resetting a database drops it, and that is not an operation an agent should be handed as a first-class tool. An agent that needs a reset must run the CLI, where the checkpoint applies.

##### Bug Fixes

Many of the fixes below are **community contributions** — thank you to everyone who reported and fixed these!

**Prisma Client**

- Fixed a severe TypeScript performance regression introduced in Prisma 7: restoring the `OmitOpts` generic default lets `tsc` reuse cached type instantiations again, bringing type-checking on large schemas back from minutes to seconds ([#&#8203;29592](prisma/orm#29592), from [@&#8203;nfl1ryxditimo12](https://github.com/nfl1ryxditimo12)).
- The `XOR` type helper now rejects primitive values such as `data: 5`, which were previously accepted at compile time even though the runtime rejected them ([#&#8203;29735](prisma/orm#29735), from [@&#8203;kyungseopk1m](https://github.com/kyungseopk1m)).
- `$queryRaw` and `$executeRaw` now fail fast with a clear validation error when passed an invalid `Date`, instead of silently serializing it as `null` and corrupting the value sent to the database ([#&#8203;29697](prisma/orm#29697), from [@&#8203;jibin7jose](https://github.com/jibin7jose)).
- The generated client is no longer corrupted by a `///` documentation comment that contains a `*/` sequence; the comment terminator is now escaped when doc comments are emitted, in both the TypeScript and JavaScript generators ([#&#8203;29736](prisma/orm#29736), from [@&#8203;kyungseopk1m](https://github.com/kyungseopk1m)).
- Improved the runtime and TypeScript error messages shown when a driver adapter is missing from the `PrismaClient` constructor; both now include a copy-pasteable example and a link to the [driver adapters docs](https://pris.ly/d/driver-adapters) ([#&#8203;29624](prisma/orm#29624)).
- Unmapped database errors from driver adapters now surface as a user-facing `P2039` (`PrismaClientKnownRequestError`) carrying the original code and message, instead of an opaque failure, which keeps schema-drift-style problems debuggable ([#&#8203;29512](prisma/orm#29512)).
- The `prisma-client-js` generator no longer emits a stray `undefined` statement when generating from a schema that declares only enums or types and no models ([#&#8203;29738](prisma/orm#29738), from [@&#8203;kyungseopk1m](https://github.com/kyungseopk1m)).
- Fixed a connection leak when an interactive transaction times out (`maxWait`) while it is still starting: the discarded transaction now sends an explicit `ROLLBACK` before the connection is returned to the pool, instead of releasing it mid-transaction. Previously, on adapters like `@prisma/adapter-pg` and `@prisma/adapter-neon`, the next query to reuse that connection could fail with `there is already a transaction in progress` — or silently commit the leaked transaction's work ([#&#8203;29727](prisma/orm#29727), from [@&#8203;lazerg](https://github.com/lazerg)).

**CLI**

- `prisma validate` (and other schema-loading commands) no longer hangs forever on a multi-file schema whose directories contain a symlink cycle, and no longer reports the same file twice when a directory is reachable under two spellings (e.g. `/tmp` → `/private/tmp` on macOS) ([#&#8203;29740](prisma/orm#29740), from [@&#8203;kyungseopk1m](https://github.com/kyungseopk1m)).
- On Windows, engine binaries are now cached in a stable, user-level directory (`%APPDATA%\Prisma`) instead of a `cwd`-relative `node_modules\.cache`, which eliminated duplicate cache directories and the bloated Serverless/Docker bundles they caused ([#&#8203;29730](prisma/orm#29730), from [@&#8203;santichausis](https://github.com/santichausis); closes [#&#8203;22574](prisma/orm#22574), [#&#8203;6670](prisma/orm#6670), [#&#8203;11577](prisma/orm#11577)).

**Driver Adapters**

- **[@&#8203;prisma/adapter-pg](https://github.com/prisma/adapter-pg)**, **[@&#8203;prisma/adapter-neon](https://github.com/prisma/adapter-neon)**, **[@&#8203;prisma/adapter-ppg](https://github.com/prisma/adapter-ppg)**: Reading a `Bytes` column no longer emits Node.js' `DEP0005` deprecation warning, thanks to an upstream `postgres-bytea` bump ([#&#8203;29538](prisma/orm#29538), from [@&#8203;kolia-zamnius](https://github.com/kolia-zamnius)).
- **[@&#8203;prisma/adapter-ppg](https://github.com/prisma/adapter-ppg)**: `ColumnNotFound` (`P2022`) errors now parse both quoted and unquoted PostgreSQL column names, including identifiers containing spaces, matching the fix previously applied to `adapter-pg` ([#&#8203;29737](prisma/orm#29737), from [@&#8203;kyungseopk1m](https://github.com/kyungseopk1m)).
- **[@&#8203;prisma/adapter-mssql](https://github.com/prisma/adapter-mssql)**: Setting a `Bytes?` (`@db.VarBinary`) field to `null` no longer fails with an implicit-conversion error; the adapter now sends the parameter typed as `VarBinary` instead of letting SQL Server default it to `nvarchar` ([#&#8203;29630](prisma/orm#29630), from [@&#8203;AnupamKumar-1](https://github.com/AnupamKumar-1)).

**Schema Engine**

- `prisma migrate status` now reports a rolled-back migration that still exists on disk as *unapplied*, instead of incorrectly treating the schema as up to date ([prisma/prisma-engines#5817](prisma/prisma-engines#5817), from [@&#8203;goutamadwant](https://github.com/goutamadwant)).
- Primary-key constraint renames are now rendered as separate `ALTER TABLE` statements on PostgreSQL, avoiding a database error when a single table has multiple changes in one migration ([prisma/prisma-engines#4906](prisma/prisma-engines#4906), from [@&#8203;eruditmorina](https://github.com/eruditmorina)).

##### Security

- Resolved the `hono` security advisories at their source: `@prisma/dev` was updated to a version that no longer depends on `hono` at all, so the CLI is no longer exposed to those advisories through that path. We also patched moderate-severity advisories in `ajv` and `uuid` across production dependencies ([#&#8203;29514](prisma/orm#29514)).
- Hardened the Prisma Platform credentials file (`~/.config/prisma-platform/auth.json`) and its directory to `0o600` / `0o700` so OAuth tokens are no longer world-readable, bringing Prisma in line with the GitHub, AWS, and Google Cloud CLIs ([#&#8203;29568](prisma/orm#29568), from Jaeyoung Yun).
- Bumped the `openssl` crate in the schema engine binaries from 0.10.74 to 0.10.81 ([prisma/prisma-engines#5815](prisma/prisma-engines#5815)).

##### Prisma Studio

The bundled Prisma Studio moves from `0.27.3` to `0.33.0` ([#&#8203;29720](prisma/orm#29720)), gathering up everything shipped in the Studio releases in between.

##### Migrations view

Studio can now visualise your **migration history**. This view is powered by **[Prisma Next](https://www.prisma.io/docs/orm/next)** — the next major version of Prisma ORM, a full TypeScript rewrite (available now in [Early Access](https://www.prisma.io/docs/next/getting-started)) that keeps the schema-first workflow and model-first queries you know, but treats your schema as a versioned, inspectable **contract** instead of compiling it into a heavy generated client. Prisma Next records every migration and its contract snapshots in the database, and Studio reads them to draw the timeline and diff below. Databases managed with classic Prisma Migrate don't carry this ledger, so the view simply stays hidden there.

When the connected database has a Prisma Next migration ledger, a **Migrations** entry appears in the sidebar: a newest-first timeline of every applied migration with its name, apply time, operation count, and compact chips summarizing what changed (`+2 models`, `~2 models +3 fields`, `+1 model`, …). Selecting a migration opens a visual, FigJam-style diff canvas — added, removed, and changed models as colour-coded cards (`NEW` / `UPDATED` / `UNCHANGED`) with per-field before → after details, enum cards, and relation edges — next to a SQL panel of the executed statements and a Prisma-schema line diff. Switching migrations morphs the canvas rather than rebuilding it.

![The Studio Migrations view: walking a Prisma Next migration history, the diff canvas morphing between migrations](https://github.com/user-attachments/assets/2633b77a-b1d9-4c3f-b5c4-c10908f040d9)

<!-- On publishing: drag wip/demos/prisma-studio-migrations.webp into the GitHub release editor so it becomes a user-attachments URL. -->

##### Prisma Streams browser

Studio gains first-class support for Prisma Streams: a dedicated stream browser, live stream aggregations, stream diagnostics, routing-key browsing, and a WAL-history handoff straight from your tables, plus richer stream request observability with concise event-log and OpenTelemetry span summaries.

##### Working with SQL

- SQL execution, linting, and navigation are now **schema-aware**: unqualified identifiers resolve against the schema you've selected instead of always falling back to the adapter's default schema.
- SQL result visualizations are rendered with Studio-owned chart configuration, and there's an optional **Queries** view backed by query-insights snapshots.
- Added copy actions to the Query Details view.

##### Fixes

- Fixed editing PostgreSQL text-array cells when queries are compiled with inline values.
- Avoided cancelling and repeating introspection requests when Studio first mounts, removing duplicate startup work.

##### Thanks to our contributors

A heartfelt thank you to the community members whose contributions shaped this release:

[@&#8203;AmirSa12](https://github.com/AmirSa12), [@&#8203;kyungseopk1m](https://github.com/kyungseopk1m), [@&#8203;nfl1ryxditimo12](https://github.com/nfl1ryxditimo12), [@&#8203;jibin7jose](https://github.com/jibin7jose), [@&#8203;santichausis](https://github.com/santichausis), [@&#8203;kolia-zamnius](https://github.com/kolia-zamnius), [@&#8203;goutamadwant](https://github.com/goutamadwant), [@&#8203;eruditmorina](https://github.com/eruditmorina), [@&#8203;lazerg](https://github.com/lazerg), [@&#8203;AnupamKumar-1](https://github.com/AnupamKumar-1), [@&#8203;Swapanrishi](https://github.com/Swapanrishi), [@&#8203;anupamme](https://github.com/anupamme), and [@&#8203;oyi77](https://github.com/oyi77).

##### Prisma Compute is now in public beta

**"Push code, it runs."** [Prisma Compute](https://www.prisma.io/compute) — managed hosting for TypeScript apps that run right next to your database — is now available in [public beta](https://blog.prisma.io/blog/launching-prisma-compute-public-beta), and free to use while the beta lasts.

Compute deploys your app as a long-lived process on Bun, colocated with your Prisma Postgres database, so there are no cold starts, no request timeouts, and no separate hosting vendor to wire up. It's a fit for REST and GraphQL APIs, full-stack apps, streaming and gRPC, and the long-running, stateful AI agents that keep connections open and hold in-process caches — "self-hosting, without the painful parts".

- **Push-to-deploy** from the CLI or via GitHub integration. Every deployment is an immutable, versioned release with its own preview URL, and rolling back is simply promoting a previous version.
- **Branch-based environments** — each branch gets its own app and database, so you can preview a change before promoting it to production.
- **Auto-wires with Prisma Postgres** (or bring any database), with automatic health checks and self-recovery.
- **[Custom domains](https://blog.prisma.io/blog/prisma-compute-custom-domains)** — point a single CNAME at Prisma and Compute provisions and renews the TLS certificate for you, with no manual certificate uploads or private-key handling.

With Prisma ORM for type-safe data access, Prisma Postgres for the managed database, and now Prisma Compute for hosting, the whole stack lives in one place. Read the full story in the [Prisma Compute blog series](https://blog.prisma.io/blog/series/prisma-compute).

##### Enterprise support

Thousands of teams use Prisma and many of them already tap into our Enterprise & Agency Support Program for hands-on help with everything from schema integrations and performance tuning to security and compliance.

With this program you also get priority issue triage and bug fixes, expert scalability advice, and custom training so that your Prisma-powered apps stay rock-solid at any scale. Learn more or join: <https://prisma.io/enterprise>.

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about these updates again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNzIuMSIsInVwZGF0ZWRJblZlciI6IjQzLjI3Mi4xIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->

Reviewed-on: https://git.oirnoir.dev/OIRNOIR/YouTube-Helper-Server/pulls/30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants