Skip to content

chore(deps): @prisma/management-api-sdk 1.69.0 -> 1.79.0 - #290

Merged
wmadden-electric merged 2 commits into
mainfrom
claude/management-api-sdk-bump-09f51c
Sep 27, 2026
Merged

wmadden-electric merged 2 commits into
mainfrom
claude/management-api-sdk-bump-09f51c

Conversation

@wmadden-electric

@wmadden-electric wmadden-electric commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

Moves @prisma/management-api-sdk from 1.69.0 to 1.79.0, the version npm's latest tag points to. No release and no other dependency changes.

Changes

  • Three pins move together: packages/cli-engine (devDependencies), packages/cli and packages/prisma (dependencies). The engine's types refer to the SDK's types. If the engine and the CLI pin different versions, pnpm installs both and the CLI fails to typecheck against the engine.
  • The engine's version stays at 0.6.1: only its devDependencies changed, and npm does not publish those. Its peer range ^1.55.0 already admits 1.79.0. node scripts/check-engine-version.mjs origin/main reports the version as consistent.
  • AuthCredential.type is now string in packages/cli/src/types/auth.ts. The SDK changed credential.type in the GET /v1/me response from "oauth" | "service_token" | "management_token" to string. Nothing in the CLI or the engine branches on its value; packages/cli/src/auth/operations.ts passes the credential through unchanged.

Every other SDK type change between the two versions is an addition: new endpoints and new optional fields.

Notes

  • The lockfile holds one SDK version. @prisma/composer@0.23.0 declares the SDK as ^1.76.0, and the lockfile had kept that older resolution. pnpm dedupe moved it to 1.79.0. The same run merged duplicate copies of semver and string-width.
  • Verified locally: build, typecheck, lint, engine tests (39 files), CLI tests (64 files), prisma tests, grammar and conformance checks. The end-to-end suite did not run locally, because no PRISMA_E2E_SERVICE_TOKEN was set. CI runs it.

🤖 Generated with Claude Code

The engine, @prisma/cli and prisma pins move together, because the engine's types refer to the SDK's types and two copies fail to typecheck against each other. The engine's version stays at 0.6.1: only its devDependencies changed, and npm does not publish those.

The SDK now types credential.type in the GET /v1/me response as string, so AuthCredential.type becomes string. Nothing in the CLI branches on its value.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Signed-off-by: willbot <w.a.madden+machine@gmail.com>
Signed-off-by: Will Madden <madden@prisma.io>
@coderabbitai

coderabbitai Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 726817e7-8503-45a7-9d2a-92a5ce8da40c

📥 Commits

Reviewing files that changed from the base of the PR and between a00dae7 and d4730fc.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (4)
  • packages/cli-engine/package.json
  • packages/cli/package.json
  • packages/cli/src/types/auth.ts
  • packages/prisma/package.json

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


Summary by CodeRabbit

  • Compatibility
    • The CLI now accepts a wider range of authentication credential types, improving compatibility with newer authentication options.

Walkthrough

The management API SDK dependency was upgraded from version 1.69.0 to 1.79.0 in three package manifests. The AuthCredential.type declaration now accepts any string instead of only "oauth", "service_token", or "management_token".

Priority: ⬇️ Low

Merge Risk: ⚪ Minimal · up to d4730

The SDK update resolves consistently, and the credential type matches the updated API. No concrete behavior regression is established; the change appears ready to merge with normal checks.

Security Architecture Review

Security architecture risk: 🔵 Low · up to d4730

The credential type now accepts more values, but the inspected authentication flow does not use that value to grant access. Upstream response validation and all downstream consumers remain unverified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The demonstrated effect is on CLI authentication metadata returned from the Management API, not on the token used to authorize requests. A broader effect through uninspected consumers is not ruled out.

Trust Boundaries and Controls

  • observed — The CLI checks the /v1/me response for 401 and requires principal and credential presence, but copies a present credential without local response-shape validation. The inspected client obtains request authority from a service or stored token rather than credential.type.

Hardening Proposals

  • proposed — If consumers later use credential.type for an authority decision, establish its server-side provenance and validate the expected value at that decision boundary. This is not an observed regression in the inspected flow.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 1…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title clearly and concisely identifies the main change: upgrading @prisma/management-api-sdk from 1.69.0 to 1.79.0.
Description check ✅ Passed The description directly explains the SDK upgrade, synchronized dependency pins, AuthCredential.type change, validation performed, and the end-to-end test limitation.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
✨ Simplify code
  • Commit to this branch
  • Create a new PR

Comment @coderabbitai help to get the list of available commands.

@pkg-pr-new

pkg-pr-new Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Open in StackBlitz

npx https://pkg.pr.new/@prisma/cli@290
npx https://pkg.pr.new/@prisma/cli-engine@290

commit: 4717d5b

@prisma/composer declares the SDK as ^1.76.0, and the lockfile had kept its older resolution, 1.76.0, next to the CLI's 1.79.0. pnpm dedupe moves Composer's copy to 1.79.0, so the lockfile holds one SDK version. The same run merged duplicate copies of semver and string-width.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Signed-off-by: willbot <w.a.madden+machine@gmail.com>
Signed-off-by: Will Madden <madden@prisma.io>
@wmadden-electric
wmadden-electric merged commit cbacdc1 into main Sep 27, 2026
16 checks passed
@wmadden-electric
wmadden-electric deleted the claude/management-api-sdk-bump-09f51c branch September 27, 2026 09:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant