Skip to content

build(deps): bump github.com/pocketbase/pocketbase from 0.35.0 to 0.37.5#1112

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/github.com/pocketbase/pocketbase-0.37.5
Closed

build(deps): bump github.com/pocketbase/pocketbase from 0.35.0 to 0.37.5#1112
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/github.com/pocketbase/pocketbase-0.37.5

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github May 4, 2026

Bumps github.com/pocketbase/pocketbase from 0.35.0 to 0.37.5.

Release notes

Sourced from github.com/pocketbase/pocketbase's releases.

v0.37.5 Release

To update the prebuilt executable you can run ./pocketbase update.

  • Fixed password fields not being detected as changed (#7670).

  • Added the local time zone name next to the date field label.

  • Reload trusted proxy info UI after settings save.

  • Other minor improvements (skips the duplicated record ids from the IN expand list, reordered confirm-email-change error checks to minimize enumeration attacks, etc.).

v0.37.4 Release

To update the prebuilt executable you can run ./pocketbase update.

[!IMPORTANT] This release include a security fix related to #7662.

  • Added backups list scroll container (#7655).

  • Optimized record upsert and preview modals data loading to minimize layout jumps.

  • Fixed SMTP IPv6 network address format (#7659).

  • Fixed autocomplete selection not properly updating the underlying input value (#7664).

  • Added ghupdate.BaseURL config option (#7665).

  • Added dummy bcrypt password check for the failure auth path to minimize enumeration timing attacks when registrations are disabled.

  • Adjusted Bitbucket, GitHub, GitLab and Gitea/Forgejo OAuth2 providers to better reflect recent API updates and doc references. In case the userinfo data is not sufficient, some of the providers now send a separate list emails request in order to minimize eventual linking security issues caused by custom onpremise setups (e.g. Gitea/Forgejo allows skipping the email verification if an ENV variable is configured).

  • ⚠️ Fixed a pre-hijacking OAuth2 linking vulnerability (#7662; thanks @​Alardiians for reporting it privately).

  • Bumped Go and npm dependencies.

v0.37.3 Release

To update the prebuilt executable you can run ./pocketbase update.

  • Fixed total count load on page back/forward navigation.

  • Fixed editor floating dialogs position when scrolling (#7653).

  • Enabled text wrapping for the API rule fields.

  • Added view query sample loading indicator.

  • Other minor light UI contrast and styles improvements.

v0.37.2 Release

... (truncated)

Changelog

Sourced from github.com/pocketbase/pocketbase's changelog.

v0.37.5

  • Fixed password fields not being detected as changed (#7670).

  • Added the local time zone name next to the date field label.

  • Reload trusted proxy info UI after settings save.

  • Other minor improvements (skips the duplicated record ids from the IN expand list, reordered confirm-email-change error checks to minimize enumeration attacks, etc.).

v0.37.4

  • Added backups list scroll container (#7655).

  • Optimized record upsert and preview modals data loading to minimize layout jumps.

  • Fixed SMTP IPv6 network address format (#7659).

  • Fixed autocomplete selection not properly updating the underlying input value (#7664).

  • Added ghupdate.BaseURL config option (#7665).

  • Added dummy bcrypt password check for the failure auth path to minimize enumeration timing attacks when registrations are disabled.

  • Adjusted Bitbucket, GitHub, GitLab and Gitea/Forgejo OAuth2 providers to better reflect recent API updates and doc references. In case the userinfo data is not sufficient, some of the providers now send a separate list emails request in order to minimize eventual linking security issues caused by custom onpremise setups (e.g. Gitea/Forgejo allows skipping the email verification if an ENV variable is configured).

  • ⚠️ Fixed a pre-hijacking OAuth2 linking vulnerability (#7662; thanks @​Alardiians for reporting it privately).

  • Bumped Go and npm dependencies.

v0.37.3

  • Fixed total count load on page back/forward navigation.

  • Fixed editor floating dialogs position when scrolling (#7653).

  • Enabled text wrapping for the API rule fields.

  • Added view query sample loading indicator.

  • Other minor light UI contrast and styles improvements.

v0.37.2

  • Fixed autoexpandable input in Firefox (#7648).

... (truncated)

Commits
  • 0cf34c4 updated changelog
  • 547ee71 slightly adjusted the dark text color
  • 4850da6 adjusted flaky test
  • 53ac0d2 reordered change email validations to make enumerations slightly harder
  • d90aaed skip duplicated records ids from the IN expand
  • 74defc4 fixed editor keydown propagation outside of form
  • 9205b11 bumped app version
  • 8d0881d reload trusted proxy info UI after settings save
  • dbcd95e updated the security policy
  • 905256b added the local time zone name next to the date field label
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github.com/pocketbase/pocketbase](https://github.com/pocketbase/pocketbase) from 0.35.0 to 0.37.5.
- [Release notes](https://github.com/pocketbase/pocketbase/releases)
- [Changelog](https://github.com/pocketbase/pocketbase/blob/master/CHANGELOG.md)
- [Commits](pocketbase/pocketbase@v0.35.0...v0.37.5)

---
updated-dependencies:
- dependency-name: github.com/pocketbase/pocketbase
  dependency-version: 0.37.5
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels May 4, 2026
@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot Bot commented on behalf of github May 11, 2026

Superseded by #1125.

@dependabot dependabot Bot closed this May 11, 2026
@dependabot dependabot Bot deleted the dependabot/go_modules/github.com/pocketbase/pocketbase-0.37.5 branch May 11, 2026 00:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants