Skip to content

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Nov 19, 2025

This PR contains the following updates:

Package Change Age Confidence
@prisma/client (source) 6.19.0 -> 7.0.0 age confidence
prisma (source) 6.19.0 -> 7.0.0 age confidence

Release Notes

prisma/prisma (@​prisma/client)

v7.0.0

Compare Source

prisma/prisma (prisma)

v7.0.0

Compare Source


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
@renovate renovate bot requested a review from batazor as a code owner November 19, 2025 12:52
@sonarqubecloud
Copy link

resolution: {integrity: sha512-jOiHyAZsmnr8LqoPGmCjYAaiuWwjAPLgY8ZX2XrmHawt99/u1y6RgrZMTeoPfpUbV96HOalYgz1qzkRbw54Pmg==}
engines: {node: '>=18.0.0'}

[email protected]:

Check failure

Code scanning / Semgrep PRO

Semgrep Finding: ssc-8ce60f61-41f7-464d-a644-ebfdf4803041 Error

Affected versions of hono are vulnerable to Improper Authorization. Hono's JWT authentication middleware does not validate the JWT aud (Audience) claim by default. As a result, services sharing the same issuer/keys can accept tokens intended for other audiences, leading to confused-deputy/token-mix-up attacks and unauthorized cross-service API access.
@batazor batazor added this pull request to the merge queue Nov 20, 2025
Merged via the queue into main with commit 4dc068e Nov 20, 2025
29 of 47 checks passed
@batazor batazor deleted the renovate/major-prisma-monorepo branch November 20, 2025 23:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants