-
-
Notifications
You must be signed in to change notification settings - Fork 206
Expand file tree
/
Copy pathpackage.json
More file actions
290 lines (290 loc) · 15.4 KB
/
Copy pathpackage.json
File metadata and controls
290 lines (290 loc) · 15.4 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
{
"name": "@libredb/studio",
"version": "0.17.0",
"description": "The database editor that deploys next to your data, not onto your laptop.",
"keywords": [
"sql",
"sql-ide",
"database-gui",
"database-editor",
"self-hosted",
"libredb",
"postgresql",
"mysql",
"oracle",
"sql-server",
"sqlite",
"libsql",
"duckdb",
"mongodb",
"redis",
"couchbase",
"clickhouse",
"druid",
"elasticsearch",
"opensearch",
"trino",
"cassandra"
],
"homepage": "https://github.com/libredb/libredb-studio",
"bugs": {
"url": "https://github.com/libredb/libredb-studio/issues"
},
"license": "MIT",
"private": false,
"publishConfig": {
"access": "public"
},
"repository": {
"type": "git",
"url": "https://github.com/libredb/libredb-studio"
},
"main": "./dist/index.js",
"module": "./dist/index.mjs",
"types": "./dist/index.d.ts",
"exports": {
".": {
"import": {
"types": "./dist/index.d.mts",
"default": "./dist/index.mjs"
},
"require": {
"types": "./dist/index.d.ts",
"default": "./dist/index.js"
}
},
"./providers": {
"import": {
"types": "./dist/providers.d.mts",
"default": "./dist/providers.mjs"
},
"require": {
"types": "./dist/providers.d.ts",
"default": "./dist/providers.js"
}
},
"./types": {
"import": {
"types": "./dist/types.d.mts",
"default": "./dist/types.mjs"
},
"require": {
"types": "./dist/types.d.ts",
"default": "./dist/types.js"
}
},
"./components": {
"import": {
"types": "./dist/components.d.mts",
"default": "./dist/components.mjs"
},
"require": {
"types": "./dist/components.d.ts",
"default": "./dist/components.js"
}
},
"./workspace": {
"import": {
"types": "./dist/workspace.d.mts",
"default": "./dist/workspace.mjs"
},
"require": {
"types": "./dist/workspace.d.ts",
"default": "./dist/workspace.js"
}
},
"./security": {
"import": {
"types": "./dist/security.d.mts",
"default": "./dist/security.mjs"
},
"require": {
"types": "./dist/security.d.ts",
"default": "./dist/security.js"
}
},
"./styles.css": "./dist/styles.css"
},
"bin": {
"libredb-studio": "bin/studio.js"
},
"files": [
"dist",
"bin"
],
"peerDependencies": {
"react": "^19",
"react-dom": "^19"
},
"engines": {
"node": ">=24.0.0"
},
"packageManager": "bun@1.4.2",
"//trustedDependencies": "Explicit allowlist of the ONLY dependencies permitted to execute code at install time. Without this field bun applies its own default allowlist, which synthesizes a `node-gyp rebuild` for any package shipping a binding.gyp - including better-sqlite3 13, whose `gypfile: false` says not to (it is N-API and ships prebuilts, so npm honours it and bun does not). These three are exactly the packages that ran scripts before the field existed; cpu-features (optional, ssh2) and unrs-resolver stay blocked as they already were.",
"trustedDependencies": [
"esbuild",
"oracledb",
"ssh2"
],
"//overrides": "Transitive dependencies held above what their parent's range would otherwise resolve to. lodash: recharts asks for ^4.17.21 and CVE-2026-4800 (arbitrary code execution via untrusted input in template imports) is fixed in 4.18.0. The fix is inside the parent's range, so this only forces resolution forward - remove the entry once recharts raises its own floor. Nothing in this repository imports lodash directly. adm-zip: cassandra-driver 4.10.0 asks for ~0.6.0 and CVE-2026-77301 (denial of service through uncontrolled memory allocation) is fixed in 0.6.1. The fix is inside the parent's range, so like lodash this only forces resolution forward - remove the entry once cassandra-driver raises its own floor to 0.6.1. CVE-2026-76845 (arbitrary file overwrite through a symlink) is advised against >= 0.5.9, <= 0.6.0 with no patched version named, so 0.6.1 is outside it too. Neither path is reachable from this product: adm-zip has exactly one consumer in the driver, lib/datastax/cloud/index.js, whose init() returns immediately unless a `cloud` option is set, and that option is only for Astra DB secure-connect bundles, which no connection here sets. The pin is taken anyway rather than argued away, and 0.6.1 was verified against the live server: the cloud module loads, an adm-zip write and read round-trips, and a connect plus query answers on Apache Cassandra 5.0.9.",
"overrides": {
"adm-zip": "^0.6.1",
"lodash": "^4.18.1",
"tedious": "^20.0.5"
},
"scripts": {
"shortcuts:sync": "bun scripts/sync-shortcuts.mjs",
"dev": "node scripts/copy-monaco.mjs && next dev",
"build": "node scripts/copy-monaco.mjs && next build",
"build:lib": "tsup && node scripts/copy-theme.mjs",
"attw": "rm -rf .attw && bun pm pack --quiet --destination .attw && attw .attw/*.tgz --profile node16 --exclude-entrypoints styles.css",
"lib:closure": "node scripts/check-lib-closure.mjs",
"prepublishOnly": "bun run build:lib && bun run attw",
"start": "next start",
"format": "biome format .",
"format:fix": "biome format --write .",
"lint": "oxlint && eslint . && node scripts/only-check.mjs",
"only:check": "node scripts/only-check.mjs",
"lint:oxc": "oxlint",
"typecheck": "tsc --noEmit",
"test": "bun tests/run-tests.ts",
"agent:eval": "bun tests/evals/real-model.ts",
"test:evals": "bun tests/run-tests.ts tests/evals",
"test:unit": "bun tests/run-tests.ts tests/unit",
"test:integration": "bun tests/run-tests.ts tests/integration",
"test:hooks": "bun tests/run-tests.ts tests/hooks",
"test:api": "bun tests/run-tests.ts tests/api",
"test:security": "bun tests/run-tests.ts tests/security",
"test:components": "bun tests/run-tests.ts tests/components tests/isolated",
"test:e2e": "bunx playwright test",
"test:coverage": "bun tests/run-tests.ts --coverage --merge-into=coverage/lcov.info",
"coverage:check": "node scripts/check-coverage.mjs coverage/lcov.info",
"test:coverage-html": "bun run test:coverage && genhtml coverage/lcov.info --output-directory coverage/html && echo '\n Open coverage/html/index.html in your browser'",
"knip": "knip",
"chart:check": "node scripts/sync-chart-version.mjs --check",
"chart:bump": "node scripts/sync-chart-version.mjs --write",
"distribution:check": "node scripts/distribution-check.mjs",
"distribution:matrix": "node scripts/distribution-check.mjs --matrix",
"channels:showcase": "node scripts/generate-channel-showcase.mjs",
"channels:showcase:check": "node scripts/generate-channel-showcase.mjs --check",
"readme:check": "node scripts/readme-check.mjs",
"security:check": "node scripts/security-check.mjs",
"test:e2e:base-path": "playwright test --config=playwright.base-path.config.ts"
},
"//dependencies": "@duckdb/node-api is pinned to an exact version. Its versions carry a prerelease suffix (1.5.5-r.4 = DuckDB 1.5.5, driver revision 4), and npm and bun treat a caret over a prerelease tag inconsistently - `^1.5.5-r.4` would resolve forward across 1.x in a way neither tool agrees on - so the range is written out. The driver is four packages, not one: @duckdb/node-api -> @duckdb/node-bindings -> a per-platform, per-libc @duckdb/node-bindings-<platform>-<arch>[-musl] holding duckdb.node next to the ~70 MB libduckdb.so it links against. None of the four declares a scripts block or a binding.gyp, so no trustedDependencies entry is needed. Bumping it is a provider change, not a routine bump (see docs/providers/duckdb.md and the tri-sync rule in CLAUDE.md). @platformatic/kafka is pinned exactly too, because the Kafka provider was measured against 2.11.0 and re-verified live against 2.12.0 (docs/providers/kafka.md section 11.4), so bumping it is a provider change too. ajv is listed although nothing in this repository imports it: @platformatic/kafka loads ajv-draft-04, whose optional peer is ajv ^8.5.0 and which requires ajv/dist/core at load time, and bun hoists ajv-draft-04 to the top of node_modules, where ajv was otherwise eslint's 6.x with no dist/core. Without this entry the Kafka client fails to load in a clean install (a Docker build, CI); with it ajv 8 sits at the top and eslint keeps its 6.x nested. That is why knip.json ignores ajv, and tests/unit/db/kafka/dependency-resolution.test.ts fails if the entry goes. The entry fixes this repository's own install only: a host that installs the published package with bun and leaves an ajv 6 at the top of its own node_modules meets the same failure, which the provider's connect() refuses with a DatabaseConfigError naming ajv/dist/core, and docs/providers/kafka.md section 2.5 says what such a host needs. @grpc/grpc-js and @grpc/proto-loader are pinned exactly for the two gRPC providers, etcd and Milvus, each measured against 1.14.5 and 0.8.1: its TLS rule for an IP address depends on grpc-js internals (build/src/channel-credentials.js sends the dial target as the TLS server name unless grpc.ssl_target_name_override is set, and Node 25 and later and Bun refuse an IP address there), so bumping either is a provider change, measured again. protobufjs is an exact devDependency and no runtime one: scripts/generate-etcd-descriptor.mjs, scripts/generate-milvus-descriptor.mjs and their tests import it, and the vendored version.proto imports google/protobuf/descriptor.proto, which only @grpc/proto-loader registers, in the protobufjs copy that proto-loader resolves. The generator therefore works only while bun dedupes proto-loader onto the one copy this pin puts at the top of node_modules, inside proto-loader's own range, so the pin moves only together with @grpc/proto-loader; @platformatic/kafka's optional protobufjs 8 then nests under that package, and tests/unit/db/etcd/dependency-resolution.test.ts and tests/unit/db/milvus/dependency-resolution.test.ts hold the whole layout. neo4j-driver-lite is pinned exactly at 6.2.0 because the neo4j provider is measured against this version (its value encodings, error codes and session behaviour), so a bump is a provider change, measured again; the lite build is used rather than neo4j-driver because the full one adds rxjs for a reactive API the provider never calls, and both carry the same neo4j-driver-core and neo4j-driver-bolt-connection, pinned to the same version. db2-node is pinned exactly for the Db2 provider, which was measured against 1.0.22 (docs/providers/db2.md, including the driver defects listed there and reported upstream as gurungabit/db2-node#12): it is a Rust DRDA client with no IBM code, one package carrying eight prebuilt N-API addons (linux x64 and arm64 for glibc and musl, darwin x64 and arm64, win32 x64 and arm64) that its generated index.js loads through static require literals, so file tracing delivers all eight and every channel prunes to the one or two it can load. Its scripts block holds only build, prepublishOnly and test, and it ships no binding.gyp, so an install runs nothing and no trustedDependencies entry is needed. The addons statically link Rust crates, among them rustls 0.23.37 and rustls-webpki 0.103.10, that npm audit, Dependabot and the CycloneDX SBOM cannot see; THIRD_PARTY_NOTICES.txt carries their notices (scripts/generate-db2-node-notices.sh writes it) and docs/THIRD_PARTY_LICENSES.md summarises them. Checked by hand against the RustSec advisory database on 2026-10-03, those two versions fall inside RUSTSEC-2026-0285 (rustls) and RUSTSEC-2026-0098, RUSTSEC-2026-0099 and RUSTSEC-2026-0104 (rustls-webpki), which only a new db2-node release can pick up, so bumping it is a provider change, measured again with the advisory check repeated.",
"dependencies": {
"@duckdb/node-api": "1.5.5-r.5",
"@google/generative-ai": "^0.24.1",
"@grpc/grpc-js": "1.14.5",
"@grpc/proto-loader": "0.8.1",
"@libredb/libredb": "^0.2.2",
"@monaco-editor/react": "^4.7.0",
"@platformatic/kafka": "2.12.0",
"@radix-ui/react-accordion": "^1.2.20",
"@radix-ui/react-alert-dialog": "^1.1.23",
"@radix-ui/react-aspect-ratio": "^1.1.15",
"@radix-ui/react-avatar": "^1.2.6",
"@radix-ui/react-checkbox": "^1.3.11",
"@radix-ui/react-collapsible": "^1.1.20",
"@radix-ui/react-context-menu": "^2.3.7",
"@radix-ui/react-dialog": "^1.1.23",
"@radix-ui/react-dropdown-menu": "^2.1.24",
"@radix-ui/react-hover-card": "^1.1.23",
"@radix-ui/react-label": "^2.1.15",
"@radix-ui/react-menubar": "^1.1.24",
"@radix-ui/react-navigation-menu": "^1.2.22",
"@radix-ui/react-popover": "^1.1.23",
"@radix-ui/react-progress": "^1.1.16",
"@radix-ui/react-radio-group": "^1.4.7",
"@radix-ui/react-scroll-area": "^1.2.18",
"@radix-ui/react-select": "^2.3.7",
"@radix-ui/react-separator": "^1.1.15",
"@radix-ui/react-slider": "^1.4.7",
"@radix-ui/react-slot": "^1.3.3",
"@radix-ui/react-switch": "^1.3.7",
"@radix-ui/react-tabs": "^1.1.21",
"@radix-ui/react-toggle": "^1.1.18",
"@radix-ui/react-toggle-group": "^1.1.19",
"@radix-ui/react-tooltip": "^1.2.16",
"@simplewebauthn/browser": "^14.0.0",
"@simplewebauthn/server": "^14.0.3",
"@tanstack/react-table": "^9.2.4",
"@tanstack/react-virtual": "^3.14.10",
"@xyflow/react": "^12.11.6",
"@zumer/snapdom": "2.15.0",
"ajv": "^8.17.1",
"better-sqlite3": "^13.0.3",
"cassandra-driver": "^4.9.0",
"class-variance-authority": "^0.7.1",
"clsx": "^2.1.1",
"cmdk": "^1.1.1",
"date-fns": "^4.4.0",
"db2-node": "1.0.22",
"elkjs": "^0.12.0",
"embla-carousel-react": "^8.6.0",
"framer-motion": "^13.2.0",
"geist": "^1.7.2",
"input-otp": "^1.5.0",
"ioredis": "^5.11.1",
"jose": "^6.2.12",
"lucide-react": "^1.41.0",
"monaco-editor": "^0.57.0",
"mongodb": "^7.6.0",
"mssql": "^12.7.0",
"mysql2": "^3.24.3",
"neo4j-driver-lite": "6.2.0",
"next": "^16.3.4",
"next-themes": "^0.4.6",
"openid-client": "^6.8.8",
"oracledb": "^6.10.0",
"pg": "^8.23.0",
"react": "^19.2.8",
"react-dom": "^19.2.8",
"react-hook-form": "^7.87.0",
"react-resizable-panels": "^4.12.4",
"recharts": "^3.10.1",
"sonner": "^2.0.8",
"sql-formatter": "^15.8.2",
"ssh2": "^1.17.0",
"tailwind-merge": "^3.6.0",
"vaul": "^1.1.2",
"yaml": "^2.9.0",
"zod": "^4.5.4"
},
"devDependencies": {
"@ai-sdk/anthropic": "4.0.37",
"@ai-sdk/google": "4.0.40",
"@ai-sdk/openai": "4.0.37",
"@arethetypeswrong/cli": "^0.18.5",
"@biomejs/biome": "^2.5.12",
"@eslint/compat": "^2.1.1",
"@modelcontextprotocol/client": "2.1.0",
"@modelcontextprotocol/server": "2.1.0",
"@peculiar/x509": "^2.1.0",
"@playwright/test": "^1.63.0",
"@tailwindcss/postcss": "^4.3.3",
"@testing-library/react": "^16.3.3",
"@testing-library/user-event": "^14.6.7",
"@types/better-sqlite3": "^9.6.0",
"@types/bun": "latest",
"@types/node": "^26.5.1",
"@types/pg": "^8.23.1",
"@types/react": "^19.2.18",
"@types/react-dom": "^19.2.7",
"@types/ssh2": "^1.15.6",
"@workflow/world-local": "4.2.4",
"@workflow/world-postgres": "4.3.3",
"ai": "7.0.59",
"eslint": "^10.10.0",
"eslint-config-next": "^16.3.4",
"happy-dom": "^20.14.0",
"knip": "^6.34.0",
"oxlint": "^1.81.0",
"protobufjs": "7.6.6",
"tailwindcss": "^4.3.3",
"tsup": "^8.5.1",
"typescript": "^6.0.3",
"typescript-eslint": "^8.70.0",
"workflow": "4.8.1"
}
}