Skip to content

build(deps): bump github.com/pocketbase/pocketbase from 0.35.0 to 0.37.4#1113

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/github.com/pocketbase/pocketbase-0.37.4
Open

build(deps): bump github.com/pocketbase/pocketbase from 0.35.0 to 0.37.4#1113
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/github.com/pocketbase/pocketbase-0.37.4

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github May 8, 2026

Bumps github.com/pocketbase/pocketbase from 0.35.0 to 0.37.4.

Release notes

Sourced from github.com/pocketbase/pocketbase's releases.

v0.37.4 Release

To update the prebuilt executable you can run ./pocketbase update.

[!IMPORTANT] This release include a security fix related to #7662.

  • Added backups list scroll container (#7655).

  • Optimized record upsert and preview modals data loading to minimize layout jumps.

  • Fixed SMTP IPv6 network address format (#7659).

  • Fixed autocomplete selection not properly updating the underlying input value (#7664).

  • Added ghupdate.BaseURL config option (#7665).

  • Added dummy bcrypt password check for the failure auth path to minimize enumeration timing attacks when registrations are disabled.

  • Adjusted Bitbucket, GitHub, GitLab and Gitea/Forgejo OAuth2 providers to better reflect recent API updates and doc references. In case the userinfo data is not sufficient, some of the providers now send a separate list emails request in order to minimize eventual linking security issues caused by custom onpremise setups (e.g. Gitea/Forgejo allows skipping the email verification if an ENV variable is configured).

  • ⚠️ Fixed a pre-hijacking OAuth2 linking vulnerability (#7662; thanks @​Alardiians for reporting it privately).

  • Bumped Go and npm dependencies.

v0.37.3 Release

To update the prebuilt executable you can run ./pocketbase update.

  • Fixed total count load on page back/forward navigation.

  • Fixed editor floating dialogs position when scrolling (#7653).

  • Enabled text wrapping for the API rule fields.

  • Added view query sample loading indicator.

  • Other minor light UI contrast and styles improvements.

v0.37.2 Release

To update the prebuilt executable you can run ./pocketbase update.

  • Fixed autoexpandable input in Firefox (#7648).

  • Slightly adjusted the dark theme colors for better readability (#7648).

  • Removed unnecessary tags stripping from the displayed log attributes (#7649).

  • Workarounded Safari freeze caused by a buggy CSS popover property (#7650).

v0.37.1 Release

... (truncated)

Changelog

Sourced from github.com/pocketbase/pocketbase's changelog.

v0.37.4

  • Added backups list scroll container (#7655).

  • Optimized record upsert and preview modals data loading to minimize layout jumps.

  • Fixed SMTP IPv6 network address format (#7659).

  • Fixed autocomplete selection not properly updating the underlying input value (#7664).

  • Added ghupdate.BaseURL config option (#7665).

  • Added dummy bcrypt password check for the failure auth path to minimize enumeration timing attacks when registrations are disabled.

  • Adjusted Bitbucket, GitHub, GitLab and Gitea/Forgejo OAuth2 providers to better reflect recent API updates and doc references. In case the userinfo data is not sufficient, some of the providers now send a separate list emails request in order to minimize eventual linking security issues caused by custom onpremise setups (e.g. Gitea/Forgejo allows skipping the email verification if an ENV variable is configured).

  • ⚠️ Fixed a pre-hijacking OAuth2 linking vulnerability (#7662; thanks @​Alardiians for reporting it privately).

  • Bumped Go and npm dependencies.

v0.37.3

  • Fixed total count load on page back/forward navigation.

  • Fixed editor floating dialogs position when scrolling (#7653).

  • Enabled text wrapping for the API rule fields.

  • Added view query sample loading indicator.

  • Other minor light UI contrast and styles improvements.

v0.37.2

  • Fixed autoexpandable input in Firefox (#7648).

  • Slightly adjusted the dark theme colors for better readability (#7648).

  • Removed unnecessary tags stripping from the displayed log attributes (#7649).

  • Workarounded Safari freeze caused by a buggy CSS popover property (#7650).

v0.37.1

  • Minor UI bugfixes:
    • Fixed number field input values normalization (#7646).

... (truncated)

Commits
  • 44bf550 updated changelogs
  • 338d672 updated ui/dist
  • 5bd9d87 reorder editor buttons to avoid dropdowns text wrapping
  • 6ba78d5 updated gitlab userinfo doc reference
  • 260bd59 updated jstypes
  • 0065664 added explicit gitlab confirmed_at check
  • 419f335 various minor ui fixes
  • 326f150 added more tests for internal record hooks
  • 1c86add #7665 added BaseURL to the ghupdate plugin configuration
  • 494f47e bumped go deps
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels May 8, 2026
Bumps [github.com/pocketbase/pocketbase](https://github.com/pocketbase/pocketbase) from 0.35.0 to 0.37.4.
- [Release notes](https://github.com/pocketbase/pocketbase/releases)
- [Changelog](https://github.com/pocketbase/pocketbase/blob/master/CHANGELOG.md)
- [Commits](pocketbase/pocketbase@v0.35.0...v0.37.4)

---
updated-dependencies:
- dependency-name: github.com/pocketbase/pocketbase
  dependency-version: 0.37.4
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/go_modules/github.com/pocketbase/pocketbase-0.37.4 branch from 8f9e6df to 324845c Compare May 14, 2026 21:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants