Skip to content

[Snyk] Security upgrade vectordb from 0.4.20 to 0.21.2 - #13325

Open
sestinj wants to merge 1 commit into
mainfrom
snyk-fix-09c6a4c30705b34139597488e73ab2f7
Open

sestinj wants to merge 1 commit into
mainfrom
snyk-fix-09c6a4c30705b34139597488e73ab2f7

Conversation

@sestinj

@sestinj sestinj commented Sep 29, 2026

Copy link
Copy Markdown
Contributor

snyk-top-banner

Snyk has created this PR to fix 8 vulnerabilities in the npm dependencies of this project.

Snyk changed the following file(s):

  • binary/package.json

Vulnerabilities that will be fixed with an upgrade:

Issue Score
high severity Prototype Pollution
SNYK-JS-AXIOS-20245066
  808  
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-AXIOS-20245042
  803  
high severity Improper Validation of Specified Quantity in Input
SNYK-JS-AXIOS-20245044
  803  
high severity Improper Validation of Specified Quantity in Input
SNYK-JS-AXIOS-20245046
  803  
high severity Allocation of Resources Without Limits or Throttling
SNYK-JS-AXIOS-20245062
  803  
high severity Unintended Proxy or Intermediary ('Confused Deputy')
SNYK-JS-AXIOS-20245048
  773  
high severity Unintended Proxy or Intermediary ('Confused Deputy')
SNYK-JS-AXIOS-20245056
  743  
high severity Server-side Request Forgery (SSRF)
SNYK-JS-AXIOS-20245060
  743  

Breaking Change Risk

Merge Risk: High

Notice: This assessment is enhanced by AI.


Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Regular Expression Denial of Service (ReDoS)
🦉 Server-side Request Forgery (SSRF)
🦉 Allocation of Resources Without Limits or Throttling
🦉 More lessons are available in Snyk Learn

@sestinj

sestinj commented Sep 29, 2026

Copy link
Copy Markdown
Contributor Author

Merge Risk: High

The vectordb package has been deprecated and renamed to @lancedb/lancedb. This is a significant breaking change that requires developer action.

Breaking Change:

  • Package Renaming: The package vectordb is no longer maintained. All future development is happening under the new package name @lancedb/lancedb.

Recommendation:
Developers must update their package.json to remove vectordb and add @lancedb/lancedb. All import or require statements in the code, such as require('vectordb'), must be updated to require('@lancedb/lancedb').

Source: NPM Package Page

Notice 🤖: This content was augmented using artificial intelligence. AI-generated content may contain errors and should be reviewed for accuracy before use.

@sestinj
sestinj requested a review from a team as a code owner September 29, 2026 10:21

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants