Skip to content

chore: update dependencies to latest versions#65

Merged
Adammatthiesen merged 1 commit intomainfrom
adam/security
Jan 27, 2026
Merged

chore: update dependencies to latest versions#65
Adammatthiesen merged 1 commit intomainfrom
adam/security

Conversation

@Adammatthiesen
Copy link
Member

@Adammatthiesen Adammatthiesen commented Jan 27, 2026

This pull request updates the pnpm-lock.yaml file to upgrade several core @studiocms and @withstudiocms packages to their latest minor versions, refines dependencies for PostgreSQL support, and removes unused or outdated packages. These changes help keep the project up-to-date, improve compatibility, and simplify the dependency tree.

Dependency Upgrades and Cleanup

  • Upgraded @studiocms/md, @studiocms/ui, and studiocms to version 0.2.0, and removed some peer dependencies (such as astro, vite, and @astrojs/markdown-remark) from @studiocms/md. Also added @studiocms/ui@1.1.0. [1] [2] [3] [4]
  • Upgraded all @withstudiocms/* packages (auth-kit, cli-kit, component-registry, effect, kysely, sdk) to their 0.2.x versions, and updated their dependencies and peer dependencies accordingly. [1] [2] [3] [4] [5] [6]
  • Upgraded pg and related PostgreSQL packages (pg-cloudflare, pg-connection-string, pg-pool, pg-protocol) to the latest minor versions, and updated the peer dependencies in packages that use them. [1] [2] [3]

Removal of Unused and Outdated Packages

  • Removed older versions of @clack/core, @clack/prompts, @commander-js/extra-typings, commander, and figlet from the lock file, reflecting their removal from the dependency tree. [1] [2] [3] [4] [5] [6] [7]

Optional Dependency Adjustments

  • Marked several dependencies as optional, such as @libsql/client, mysql2, pg, kysely-turso, aws-ssl-profiles, and denque, to allow more flexible package installation. [1] [2] [3] [4] [5]

These changes collectively ensure that the project uses the latest stable versions of its dependencies, reduces unnecessary package bloat, and improves compatibility with newer environments.

Summary by CodeRabbit

  • Chores
    • Updated core dependencies to latest versions.
    • Added new dependency for enhanced functionality.

✏️ Tip: You can customize this high-level summary in your review settings.

- Bump @studiocms/md from 0.1.1 to 0.2.0
- Bump studiocms from 0.1.1 to 0.2.0
- Bump pg from 8.16.3 to 8.17.2
- Update package.json and pnpm-lock.yaml accordingly
@coderabbitai
Copy link

coderabbitai bot commented Jan 27, 2026

📝 Walkthrough

Walkthrough

This PR adds the PostgreSQL driver (pg) as a new dependency and updates two StudioCMS packages (studiocms and @studiocms/md) from version 0.1.1 to 0.2.0 in the www package.json file.

Changes

Cohort / File(s) Summary
Dependency updates
www/package.json
Added pg (^8.17.2) for PostgreSQL support; bumped studiocms and @studiocms/md from 0.1.1 to 0.2.0

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~2 minutes

Possibly related PRs

Suggested reviewers

  • dreyfus92
  • louisescher
  • RATIU5

Poem

🐰 A carrot for pg, so swift and so true,
StudioCMS updated—0.2.0, brand new!
Dependencies bundled with care, said the hare,
The web project blooms with more database flair! 🌱✨

🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title 'chore: update dependencies to latest versions' is directly related to the main change in the changeset, which updates multiple dependencies to newer versions as documented in the raw summary and PR objectives.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch adam/security

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@Adammatthiesen Adammatthiesen marked this pull request as ready for review January 27, 2026 20:57
@Adammatthiesen Adammatthiesen requested a review from a team as a code owner January 27, 2026 20:57
@Adammatthiesen Adammatthiesen merged commit ba6d8ca into main Jan 27, 2026
2 checks passed
@Adammatthiesen Adammatthiesen deleted the adam/security branch January 27, 2026 21:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants