Skip to content

chore(deps): bump pgsql-parser packages to the literal-escaping release - #1877

Merged
pyramation merged 1 commit into
mainfrom
devin/1791333541-bump-pgsql-deps
Oct 7, 2026
Merged

pyramation merged 1 commit into
mainfrom
devin/1791333541-bump-pgsql-deps

Conversation

@pyramation

Copy link
Copy Markdown
Contributor

Summary

Picks up the pgsql-parser release that includes pgsql-parser#358. In that release the TS deparser escapes quotes in string literals (bit strings, transaction gids, option values, role password/VALID UNTIL, XMLTABLE paths, …) and rejects invalid numeric fval/ival values when deparsing hand-built ASTs.

Generated with makage deps ../pgsql-parser --install. It changed 21 ranges across 10 packages:

package bumps
pgpm/core, csv-to-pg, graphile-sql-expression-validator pgsql-deparser ^18.3.10, pgsql-parser ^18.2.10 (+ @pgsql/utils ^18.2.12 in csv-to-pg)
pgpm/cli, pg-ast, @constructive-io/query-builder pgsql-deparser ^18.3.10
node-type-registry pgsql-deparser ^18.3.10, @pgsql/utils ^18.2.12
safegres @pgsql/lint ^18.2.10, @pgsql/traverse ^18.7.12, pgsql-deparser ^18.3.10, pgsql-parser ^18.2.10
@pgpmjs/transform @pgsql/scripts ^18.4.10, @pgsql/semantics ^18.1.11, @pgsql/transform ^18.17.10, plpgsql-parser ^18.5.12
@pgpmjs/slice plpgsql-parser ^18.5.12

pnpm-lock.yaml was re-run through prettier so it keeps the repo's formatting. The lockfile diff only touches the pgsql/plpgsql/@pgsql entries, and pnpm install --frozen-lockfile is clean.

Tests run locally against pg 18: pg-ast, query-builder (including db tests), node-type-registry, csv-to-pg, pgpm/transform, pgpm/slice, graphile-sql-expression-validator and safegres all pass.

Link to Devin session: https://app.devin.ai/sessions/a1e43e1e9fb2494fa571e6ecb93e1067
Open in Devin Desktop: https://app.devin.ai/desktop/session/a1e43e1e9fb2494fa571e6ecb93e1067?variant=devin
Requested by: @pyramation

…l-parser 18.2.10, plpgsql-parser 18.5.12, @pgsql/* )
@devin-ai-integration

Copy link
Copy Markdown
Contributor

I'll fix CI failures and address comments from users with write access. I'll skip comments containing "(aside)".

  • Disable automatic comment, CI, and merge conflict monitoring

@tenki-reviewer

tenki-reviewer Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Review complete. No issues found — approved ✅.


A routine dependency refresh moving the PostgreSQL parser toolchain to the latest patch releases of the 18.x line across all consuming packages. Every bump uses caret ranges so resolution stays within the compatible release train, and the versions align with what is published to the lockfile — no manifest/lockfile drift was detected.

Files Change
graphile/graphile-sql-expression-validator, packages/csv-to-pg, packages/node-type-registry, packages/safegres Bump pgsql-deparser (and pgsql-parser where present) to the latest 18.x patch releases.
pgpm/cli, pgpm/core, pgpm/slice, pgpm/transform Bump pgsql-parser, @pgsql/utils, and @pgsql/traverse dependencies.
postgres/pg-ast, postgres/query-builder Bump @pgsql/scripts, @pgsql/semantics, @pgsql/transform, and plpgsql-parser dependencies.

Reviewed commit: 04198b3

@socket-security

Copy link
Copy Markdown

@pyramation
pyramation merged commit 2ae69ae into main Oct 7, 2026
5 checks passed
@pyramation
pyramation deleted the devin/1791333541-bump-pgsql-deps branch October 7, 2026 00:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant