Skip to content

build(deps): bump the migrator-prod group across 1 directory with 2 updates#422

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/migrator/migrator-prod-9aae35224a
Open

build(deps): bump the migrator-prod group across 1 directory with 2 updates#422
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/migrator/migrator-prod-9aae35224a

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github May 8, 2026

Bumps the migrator-prod group with 2 updates in the /migrator directory: cassandra-driver and umzug.

Updates cassandra-driver from 4.8.0 to 4.9.0

Changelog

Sourced from cassandra-driver's changelog.

4.9.0

2026-04-23

This release marks the first release of the driver under the Apache Software
Foundation, following its donation from DataStax.

Features

  • [NODEJS-692] - Add Node.js v24 support
  • [CASSNODEJS-2] - Update CONTRIBUTING.md after ASF donation, drop Node.js 18 support
  • [CASSNODEJS-4] - Update DRIVER_NAME after donation to ASF
  • [CASSNODEJS-3] - Public CI after Donation

Bug fixes

  • [PR #432] - Fix retry on socket error
  • [NODEJS-693] - Remove broken jsdoc from 4.8.0
  • [NODEJS-691] - Fix generated timestamp on retry
Commits
  • 1c0a7df ninja-fix: Changelog and version bump for 4.9.0
  • e5957d6 CASSNODEJS-3: Public CI after Donation
  • d3ddcbf CASSNODEJS-4 Update DRIVER_NAME after donation to ASF
  • 65507c5 Bump picomatch from 2.3.1 to 2.3.2
  • b0a6b61 Bump serialize-javascript and mocha
  • 8fa4399 Bump tar-fs from 2.1.2 to 2.1.4
  • 6c70446 CASSNODEJS-2 Update CONTRIBUTING.md after ASF donation (#453)
  • 3b4ce72 Donation to Apache Cassandra and ASF
  • acea0b9 NODEJS-691 Fix generated timestamp on retry (#438)
  • c0a6c5f Added NPM badge to README.md (#437)
  • Additional commits viewable in compare view

Updates umzug from 3.8.2 to 3.8.3

Release notes

Sourced from umzug's releases.

v3.8.3

mostly just a security patch update

pnpm audit --prod output before 4272daa25ac2fed4e71973f04253f8219f42c26c:

┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high                │ Validator is Vulnerable to Incomplete Filtering of One │
│                     │ or More Instances of Special Elements                  │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package             │ validator                                              │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ <13.15.22                                              │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions    │ >=13.15.22                                             │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths               │ . > @rushstack/ts-command-line@4.19.1 >                │
│                     │ @rushstack/terminal@0.10.0 >                           │
│                     │ @rushstack/node-core-library@4.0.2 > z-schema@5.0.5 >  │
│                     │ validator@13.11.0                                      │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info           │ https://github.com/advisories/GHSA-vghf-hv5q-vc2g      │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high                │ Picomatch has a ReDoS vulnerability via extglob        │
│                     │ quantifiers                                            │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package             │ picomatch                                              │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=4.0.0 <4.0.4                                         │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions    │ >=4.0.4                                                │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths               │ . > tinyglobby@0.2.13 > fdir@6.4.4 > picomatch@4.0.2   │
│                     │                                                        │
│                     │ . > tinyglobby@0.2.13 > picomatch@4.0.2                │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info           │ https://github.com/advisories/GHSA-c2c7-rcm5-vvqj      │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ moderate            │ validator.js has a URL validation bypass vulnerability │
│                     │ in its isURL function                                  │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package             │ validator                                              │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ <13.15.20                                              │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions    │ >=13.15.20                                             │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths               │ . > @rushstack/ts-command-line@4.19.1 >                │
</tr></table> 

... (truncated)

Commits

@dependabot dependabot Bot added dependencies Issues about dependencies, or pull requests that update a dependency file javascript Pull requests that update javascript code labels May 8, 2026
@dependabot dependabot Bot requested a review from juanmrad as a code owner May 8, 2026 22:17
@dependabot dependabot Bot added the dependencies Issues about dependencies, or pull requests that update a dependency file label May 8, 2026
@dependabot dependabot Bot added the javascript Pull requests that update javascript code label May 8, 2026
@dependabot dependabot Bot requested review from dom-notion and julietshen as code owners May 8, 2026 22:17
…pdates

Bumps the migrator-prod group with 2 updates in the /migrator directory: [cassandra-driver](https://github.com/apache/cassandra-nodejs-driver) and [umzug](https://github.com/sequelize/umzug).


Updates `cassandra-driver` from 4.8.0 to 4.9.0
- [Changelog](https://github.com/apache/cassandra-nodejs-driver/blob/trunk/CHANGELOG.md)
- [Commits](apache/cassandra-nodejs-driver@v4.8.0...v4.9.0)

Updates `umzug` from 3.8.2 to 3.8.3
- [Release notes](https://github.com/sequelize/umzug/releases)
- [Changelog](https://github.com/sequelize/umzug/blob/main/CHANGELOG.md)
- [Commits](sequelize/umzug@v3.8.2...v3.8.3)

---
updated-dependencies:
- dependency-name: cassandra-driver
  dependency-version: 4.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: migrator-prod
- dependency-name: umzug
  dependency-version: 3.8.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: migrator-prod
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/migrator/migrator-prod-9aae35224a branch from b25c34d to 5e01c21 Compare May 13, 2026 22:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Issues about dependencies, or pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants