Repository navigation
Commit f0295b7
committed
fix(deps): bump pgx v5.8.0->v5.9.2 (GO-2026-5004) and js-yaml 3.14.2->3.15.0
pgx/v5: SQL injection via dollar-quoted string literal placeholder confusion
(GO-2026-5004). The root module calls pgxpool.Conn.QueryRow via
internal/database/connection.go:353 so the vulnerability is reachable.
Fixed in v5.9.2; non-breaking minor bump.
js-yaml: npm audit fix applied js-yaml 3.14.2->3.15.0 (safe, non-breaking).1 parent 1267f2c commit f0295b7
3 files changed
Lines changed: 6 additions & 6 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
109 | 109 | | |
110 | 110 | | |
111 | 111 | | |
112 | | - | |
| 112 | + | |
113 | 113 | | |
114 | 114 | | |
115 | 115 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
250 | 250 | | |
251 | 251 | | |
252 | 252 | | |
253 | | - | |
254 | | - | |
| 253 | + | |
| 254 | + | |
255 | 255 | | |
256 | 256 | | |
257 | 257 | | |
| |||
0 commit comments