Skip to content

build(deps): bump dexie from 4.4.4 to 4.4.5 - #1472

Merged
rubenvdlinde merged 1 commit into
developmentfrom
dependabot/npm_and_yarn/development/dexie-4.4.5
Aug 30, 2026
Merged

build(deps): bump dexie from 4.4.4 to 4.4.5#1472
rubenvdlinde merged 1 commit into
developmentfrom
dependabot/npm_and_yarn/development/dexie-4.4.5

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 30, 2026

Copy link
Copy Markdown
Contributor

Bumps dexie from 4.4.4 to 4.4.5.

Release notes

Sourced from dexie's releases.

Dexie v4.4.5

This is a maintenance release that fixes an issue with indexes named after inherited Object properties and improves authentication recovery in dexie-cloud-addon.

Related Package Releases

Package Version
dexie 4.4.5
dexie-cloud-addon 4.4.14
dexie-react-hooks 4.4.0 (no change)
y-dexie 4.4.0 (no change)
dexie-export-import 4.4.0 (no change)

Bug Fixes

dexie@4.4.5

  • fix: don't crash when an index is named constructor — Tables with a primary key or index named constructor could cause db.open() to fail with TypeError: indexList.push is not a function. The internal index lookup now uses an object without a prototype, avoiding collisions with inherited Object.prototype properties such as constructor, toString, and valueOf. (#2325, fixes #1920). Contributed by @​tarann26.

dexie-cloud-addon@4.4.14

  • fix: recover from failed refresh-token renewal — When a locally unexpired refresh token is rejected by the server, login() now falls back to the regular fetchTokens authentication path instead of propagating the refresh error. This allows custom authentication integrations to silently obtain new tokens when possible, or trigger their normal login flow when required. OAuth redirect errors continue to propagate normally. (#2326). Fixed by @​liz709 and @​dfahlander.
Commits
  • 22bdff1 dexie@4.4.5
  • 6a7b452 fix(dbcore): don't crash when an index is named 'constructor' (#2325)
  • dbaf960 dexie-cloud-addon@4.4.14
  • 3fd4745 fix(dexie-cloud-addon): fall back to fetchTokens when refresh fails
  • 962052f updated pnpm lockfile
  • 12038d1 Updated deps of dexie-cloud-todo-app
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [dexie](https://github.com/dexie/Dexie.js) from 4.4.4 to 4.4.5.
- [Release notes](https://github.com/dexie/Dexie.js/releases)
- [Commits](dexie/Dexie.js@v4.4.4...v4.4.5)

---
updated-dependencies:
- dependency-name: dexie
  dependency-version: 4.4.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code patch Patch version bump labels Aug 30, 2026
@dependabot
dependabot Bot requested review from SudoThijn and remko48 as code owners August 30, 2026 07:00
@dependabot dependabot Bot added patch Patch version bump dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 30, 2026
@rubenvdlinde
rubenvdlinde merged commit 643a0af into development Aug 30, 2026
46 checks passed
@rubenvdlinde
rubenvdlinde deleted the dependabot/npm_and_yarn/development/dexie-4.4.5 branch August 30, 2026 08:01
@github-actions

Copy link
Copy Markdown
Contributor

Quality Report — ConductionNL/dossiq @ 4938ade

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
build
check-manifest
check-vue3-compile
test-l10n
format
check-schema-l10n
check-l10n-js
composer ✅ 106/106
npm ✅ 552/552
app:check-code ⏭️
info.xml
REUSE
PHPUnit
Newman ⏭️
Playwright 🚨 NO VERDICT — enabled but never ran
Hydra gates

Quality workflow — 2026-08-30 08:31 UTC

Download the full PDF report from the workflow artifacts.

rubenvdlinde added a commit that referenced this pull request Sep 1, 2026
…k set (#1636)

Dexie throws "Two different versions of Dexie loaded in the same app" at
module init when two copies at different versions meet in one page, and the
SPA never mounts. The 2026-09-01 acceptance run on a clean rig hit exactly
that: dossiq-main.js at 4.4.5 beside a shared nc-vue chunk at 4.4.4, and
the Cases page rendered as bare chrome.

The version alignment landed in #1472 and in nextcloud-vue#825, which
stopped the library vendoring its own dexie. Nothing guarded it: the next
dexie bump on either side reintroduces the throw with every instrument
green. This adds scripts/check-single-dexie.js as a postbuild step, so it
runs wherever npm run build runs, including the shared release workflow. It
fails when two built chunks embed different Dexie versions, or when the
embedded version is not the one package-lock.json resolves.

Verified against a fresh production build (one version, 4.4.5, matching the
lockfile, exit 0) and against a planted 4.4.4 chunk (exit 1).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code patch Patch version bump

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant