Skip to content

Comments

Security/update trpc 10.45.3#38

Merged
Droniu merged 2 commits intomainfrom
security/update-trpc-10.45.3
Dec 17, 2025
Merged

Security/update trpc 10.45.3#38
Droniu merged 2 commits intomainfrom
security/update-trpc-10.45.3

Conversation

@Droniu
Copy link
Member

@Droniu Droniu commented Dec 17, 2025

No description provided.

Updates all @trpc packages to address security vulnerability in @trpc/server.

Affected versions: >= 10.27.0, < 10.45.3
Patched version: 10.45.3

Updated projects:
- example-app-taxjar (10.43.1 → 10.45.3)
- example-app-sequra (10.38.2 → 10.45.3)
- example-app-sendgrid (10.43.1 → 10.45.3)
- example-app-klarna (10.38.2 → 10.45.3)
- example-app-invoices (10.43.1 → 10.45.3)
- example-app-crm (10.43.1 → 10.45.3)
- example-app-authorize.net (10.37.1 → 10.45.3)

All @trpc packages updated: @trpc/server, @trpc/client, @trpc/next, @trpc/react-query
@Droniu Droniu requested a review from a team as a code owner December 17, 2025 10:05
@github-actions
Copy link

Differences Found

✅ No packages or licenses were added.

Summary

Expand
License Name Package Count Packages
0BSD 1
Packages
  • tslib
AFL-2.1 1
Packages
  • json-schema
Apache 2.0 1
Packages
  • @mailchimp/mailchimp_marketing
CC-BY-3.0 1
Packages
  • spdx-exceptions
MIT (http://mootools.net/license.txt) 1
Packages
  • slick
MIT-0 1
Packages
  • nodemailer
Public Domain 1
Packages
  • jsonify
Python-2.0 1
Packages
  • argparse
SEE LICENSE IN LICENSE 1
Packages
  • spawndamnit
WTFPL 1
Packages
  • utf8-byte-length
CC-BY-4.0 2
Packages
  • @saleor/macaw-ui
  • caniuse-lite
CC0-1.0 3
Packages
  • language-subtag-registry
  • spdx-license-ids
  • type-fest
Unlicense 3
Packages
  • @zxing/text-encoding
  • big-integer
  • tweetnacl
<<missing>> 5
Packages
  • busboy
  • cycle
  • example-nextjs-sequra
  • eyes
  • streamsearch
BlueOak-1.0.0 5
Packages
  • chownr
  • jackspeak
  • package-json-from-dist
  • path-scurry
  • yallist
LGPL-3.0-or-later 11
Packages
  • @img/sharp-libvips-darwin-arm64
  • @img/sharp-libvips-darwin-x64
  • @img/sharp-libvips-linux-arm
  • @img/sharp-libvips-linux-arm64
  • @img/sharp-libvips-linux-s390x
  • @img/sharp-libvips-linux-x64
  • @img/sharp-libvips-linuxmusl-arm64
  • @img/sharp-libvips-linuxmusl-x64
  • @img/sharp-wasm32
  • @img/sharp-win32-ia32
  • @img/sharp-win32-x64
MPL-2.0 12
Packages
  • axe-core
  • lightningcss
  • lightningcss-darwin-arm64
  • lightningcss-darwin-x64
  • lightningcss-freebsd-x64
  • lightningcss-linux-arm-gnueabihf
  • lightningcss-linux-arm64-gnu
  • lightningcss-linux-arm64-musl
  • lightningcss-linux-x64-gnu
  • lightningcss-linux-x64-musl
  • lightningcss-win32-arm64-msvc
  • lightningcss-win32-x64-msvc
BSD-2-Clause 25
Packages
  • @typescript-eslint/parser
  • @typescript-eslint/typescript-estree
  • cheerio-select
  • css-select
  • css-what
  • damerau-levenshtein
  • domelementtype
  • domhandler
  • domutils
  • dotenv
  • entities
  • escodegen
  • eslint-scope
  • espree
  • esprima
  • esrecurse
  • estraverse
  • esutils
  • glob-to-regexp
  • normalize-package-data
  • And 5 more...
BSD-3-Clause 30
Packages
  • @humanwhocodes/object-schema
  • @saleor/app-sdk
  • @saleor/auth-sdk
  • @saleor/eslint-plugin-saleor-app
  • @sentry/cli
  • @xtuc/ieee754
  • abab
  • asn1js
  • bcrypt-pbkdf
  • diff
  • esquery
  • exenv
  • hoist-non-react-statics
  • hyphenate-style-name
  • ieee754
  • immutable
  • istanbul-lib-coverage
  • istanbul-lib-report
  • istanbul-lib-source-maps
  • istanbul-reports
  • And 10 more...
ISC 71
Packages
  • @isaacs/cliui
  • @isaacs/fs-minipass
  • @saleor/app-sdk
  • @saleor/json-schema-compiler
  • @ungap/structured-clone
  • abbrev
  • anymatch
  • ast-types-flow
  • authorizenet
  • boolbase
  • cli-color
  • cli-width
  • cliui
  • d
  • electron-to-chromium
  • es5-ext
  • es6-symbol
  • es6-weak-map
  • eslint-import-resolver-typescript
  • ext
  • And 51 more...
Apache-2.0 76
Packages
  • @ampproject/remapping
  • @humanwhocodes/config-array
  • @humanwhocodes/module-importer
  • @img/sharp-darwin-arm64
  • @img/sharp-darwin-x64
  • @img/sharp-linux-arm
  • @img/sharp-linux-arm64
  • @img/sharp-linux-s390x
  • @img/sharp-linux-x64
  • @img/sharp-linuxmusl-arm64
  • @img/sharp-linuxmusl-x64
  • @img/sharp-wasm32
  • @img/sharp-win32-ia32
  • @img/sharp-win32-x64
  • @opentelemetry/api
  • @opentelemetry/semantic-conventions
  • @pollyjs/adapter
  • @pollyjs/adapter-fetch
  • @pollyjs/adapter-node-http
  • @pollyjs/core
  • And 56 more...
MIT 1440
Packages
  • @0no-co/graphql.web
  • @aashutoshrathi/word-wrap
  • @adobe/css-tools
  • @alloc/quick-lru
  • @apidevtools/json-schema-ref-parser
  • @apollo/client
  • @ardatan/relay-compiler
  • @ardatan/sync-fetch
  • @babel/code-frame
  • @babel/compat-data
  • @babel/core
  • @babel/generator
  • @babel/helper-annotate-as-pure
  • @babel/helper-compilation-targets
  • @babel/helper-create-class-features-plugin
  • @babel/helper-environment-visitor
  • @babel/helper-function-name
  • @babel/helper-globals
  • @babel/helper-hoist-variables
  • @babel/helper-member-expression-to-functions
  • And 1420 more...

@Droniu Droniu enabled auto-merge (squash) December 17, 2025 10:10
@Droniu Droniu merged commit c2c3b48 into main Dec 17, 2025
9 checks passed
@Droniu Droniu deleted the security/update-trpc-10.45.3 branch December 17, 2025 10:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants