Skip to content

Bump mariadb from 3.5.3 to 3.5.4 in /InfoLogger - #3671

Merged
isaachilly merged 2 commits into
devfrom
dependabot/npm_and_yarn/InfoLogger/mariadb-3.5.4
Oct 9, 2026
Merged

isaachilly merged 2 commits into
devfrom
dependabot/npm_and_yarn/InfoLogger/mariadb-3.5.4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 9, 2026

Copy link
Copy Markdown
Contributor

Bumps mariadb from 3.5.3 to 3.5.4.

Release notes

Sourced from mariadb's releases.

MariaDB Connector/Node.js 3.5.4

3.5.4 (Jul 2026)

Full Changelog

Notable changes

  • CONJS-355: Avoid flat-cloning the connection options for every command, relying on a prototype-chain merge instead (#353 thanks to erulabs)
  • CONJS-357: Add JavaScript SAST (CodeQL + eslint-plugin-security) to CI
  • CONJS-365: Enable standard TLS certificate identity validation under Deno
  • CONJS-366: New option maxAllowedColumns (default 65535) bounding the column count announced by the server, a rogue server being otherwise able to have the client allocate metadata for a result-set that will never complete (report by fg0x0)

Issues Fixed

  • CONJS-329: An exception thrown by a callback was reported to that same callback as a database error, instead of propagating like it does from any other node-style callback (report by Assen Totin)
  • CONJS-356: Corrected ed25519 authentication with zero-configuration SSL
  • CONJS-358: Refuse multi-part packet (> 16MB) reassembly before authentication completes, a rogue server being otherwise able to exhaust client memory before any credential is even validated
  • CONJS-359: Corrected the default maxAllowedPacket value when the option is not set
  • CONJS-360: batch() ignored the insertIdAsNumber / supportBigNumbers / bigNumberStrings options for insertId
  • CONJS-361: The connection stopped sending commands after a command ending on the last packet of a network chunk: a prepared statement was never executed, without error nor timeout (report by Assen Totin)
  • CONJS-362: Limit the parsec authentication PBKDF2 iteration factor and move the key derivation off the event loop, a rogue server being otherwise able to freeze the whole process for minutes (report by fg0x0)
  • CONJS-363: typeCast accessors returned corrupted values with prepared statements
  • CONJS-364: Types / TypeNumbers enums threw at runtime (#347, contribution by BrianDouglasIE)
  • CONJS-367: Uninitialized process memory leaked to server via malformed GeoJSON Polygon parameter (report by fg0x0)
  • CONJS-368: Fixed SQL injection in text protocol when session uses NO_BACKSLASH_ESCAPES (report by fg0x0)
  • CONJS-369: Fixed SQL injection through object keys in SET expansion when using permitSetMultiParamEntries (report by fg0x0)
Changelog

Sourced from mariadb's changelog.

3.5.4 (Jul 2026)

Full Changelog

Notable changes

  • CONJS-355: Avoid flat-cloning the connection options for every command, relying on a prototype-chain merge instead (#353 thanks to erulabs)
  • CONJS-357: Add JavaScript SAST (CodeQL + eslint-plugin-security) to CI
  • CONJS-365: Enable standard TLS certificate identity validation under Deno
  • CONJS-366: New option maxAllowedColumns (default 65535) bounding the column count announced by the server, a rogue server being otherwise able to have the client allocate metadata for a result-set that will never complete (report by fg0x0)

Issues Fixed

  • CONJS-329: An exception thrown by a callback was reported to that same callback as a database error, instead of propagating like it does from any other node-style callback (report by Assen Totin)
  • CONJS-356: Corrected ed25519 authentication with zero-configuration SSL
  • CONJS-358: Refuse multi-part packet (> 16MB) reassembly before authentication completes, a rogue server being otherwise able to exhaust client memory before any credential is even validated
  • CONJS-359: Corrected the default maxAllowedPacket value when the option is not set
  • CONJS-360: batch() ignored the insertIdAsNumber / supportBigNumbers / bigNumberStrings options for insertId
  • CONJS-361: The connection stopped sending commands after a command ending on the last packet of a network chunk: a prepared statement was never executed, without error nor timeout (report by Assen Totin)
  • CONJS-362: Limit the parsec authentication PBKDF2 iteration factor and move the key derivation off the event loop, a rogue server being otherwise able to freeze the whole process for minutes (report by fg0x0)
  • CONJS-363: typeCast accessors returned corrupted values with prepared statements
  • CONJS-364: Types / TypeNumbers enums threw at runtime (#347, contribution by BrianDouglasIE)
  • CONJS-367: Uninitialized process memory leaked to server via malformed GeoJSON Polygon parameter (report by fg0x0)
  • CONJS-368: Fixed SQL injection in text protocol when session uses NO_BACKSLASH_ESCAPES (report by fg0x0)
  • CONJS-369: Fixed SQL injection through object keys in SET expansion when using permitSetMultiParamEntries (report by fg0x0)

3.4.7 (Jul 2026)

Full Changelog

Notable changes

  • CONJS-357: Add JavaScript SAST (CodeQL + eslint-plugin-security) to CI

Issues Fixed

  • CONJS-358: Refuse multi-part packet (> 16MB) reassembly before authentication completes, a rogue server being otherwise able to exhaust client memory before any credential is even validated
  • CONJS-363: typeCast accessors returned corrupted values with prepared statements
  • CONJS-367: Uninitialized process memory leaked to server via malformed GeoJSON Polygon parameter (report by fg0x0)
  • CONJS-368: Fixed SQL injection in text protocol when session uses NO_BACKSLASH_ESCAPES (report by fg0x0)
  • CONJS-369: Fixed SQL injection through object keys in SET expansion when using permitSetMultiParamEntries (report by fg0x0)
  • Escape the server-supplied filename before building the LOCAL INFILE validation regular expression

3.3.4 (Jul 2026)

Full Changelog

Notable changes

  • CONJS-357: Add JavaScript SAST (CodeQL + eslint-plugin-security) to CI

Issues Fixed

  • CONJS-358: Refuse multi-part packet (> 16MB) reassembly before authentication completes, a rogue server being otherwise able to exhaust client memory before any credential is even validated
  • CONJS-363: typeCast accessors returned corrupted values with prepared statements
  • CONJS-367: Uninitialized process memory leaked to server via malformed GeoJSON Polygon parameter (report by fg0x0)
  • CONJS-368: Fixed SQL injection in text protocol when session uses NO_BACKSLASH_ESCAPES (report by fg0x0)

... (truncated)

Commits
  • ff43a2c [misc] type definitions: StreamCallback declared as a value it never exports
  • 2044071 Merge pull request #356 from GiHoon1123/fix-sqlerror-instanceof
  • f7009c4 [misc] fix SqlError losing its constructor shape via namespace import
  • 1d9ae05 [misc] command queue: never discard a command that has not started
  • a666b5e [misc] test correction
  • 8efc399 bump 3.5.4 version
  • f050ee7 [misc] callback API: give callbacks to the command layer instead of a promise
  • 1e79cee [misc] test addition
  • 3fdaf48 [CONJS-329] Exception thrown by a callback reported as a database error
  • a0671c2 [CONJS-361] Connection stops sending commands after a command ends on the las...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [mariadb](https://github.com/mariadb-corporation/mariadb-connector-nodejs) from 3.5.3 to 3.5.4.
- [Release notes](https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases)
- [Changelog](https://github.com/mariadb-corporation/mariadb-connector-nodejs/blob/main/CHANGELOG.md)
- [Commits](mariadb-corporation/mariadb-connector-nodejs@3.5.3...3.5.4)

---
updated-dependencies:
- dependency-name: mariadb
  dependency-version: 3.5.4
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file InfoLogger labels Oct 9, 2026
@isaachilly isaachilly self-assigned this Oct 9, 2026
@isaachilly
isaachilly merged commit d1e194e into dev Oct 9, 2026
9 checks passed
@isaachilly
isaachilly deleted the dependabot/npm_and_yarn/InfoLogger/mariadb-3.5.4 branch October 9, 2026 11:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file InfoLogger

Development

Successfully merging this pull request may close these issues.

1 participant