fix(deps): update all minor and patch dependencies#649
Open
renovate[bot] wants to merge 1 commit intomainfrom
Open
fix(deps): update all minor and patch dependencies#649renovate[bot] wants to merge 1 commit intomainfrom
renovate[bot] wants to merge 1 commit intomainfrom
Conversation
Codecov ReportAll modified and coverable lines are covered by tests ✅
Additional details and impacted files@@ Coverage Diff @@
## main #649 +/- ##
========================================
Coverage 22.74% 22.74%
========================================
Files 726 726
Lines 43460 43460
Branches 3428 3417 -11
========================================
Hits 9884 9884
- Misses 33084 33226 +142
+ Partials 492 350 -142 ☔ View full report in Codecov by Sentry. |
63a8cc4 to
7e51ce1
Compare
f91edad to
126f3ad
Compare
1ac6f5a to
d8f7056
Compare
96b1d7b to
01eb04d
Compare
005673c to
e25c7ae
Compare
e25c7ae to
e0d6a18
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
4.11.3→4.13.03.2.4→3.2.719.6.1→19.8.119.6.0→19.8.13.7.0→3.9.23.7.0→3.9.23.7.0→3.9.23.7.0→3.9.23.7.0→3.9.23.7.0→3.9.211.14.0→11.14.19.19.0→9.39.25.0.4→5.0.77.3.1→7.10.13.1.0→3.1.16.4.5→6.6.66.4.5→6.6.66.4.5→6.6.66.4.5→6.6.66.4.5→6.6.64.6.0→4.7.010.4.15→10.4.2210.4.15→10.4.2210.4.15→10.4.2210.4.15→10.4.228.5.2→8.6.148.5.2→8.6.148.5.2→8.6.158.5.2→8.6.158.5.2→8.6.148.5.2→8.6.158.5.2→8.6.158.5.2→8.6.150.6.0→0.7.101.10.12→1.15.115.66.0→5.90.201.99.0→1.158.11.99.0→1.158.11.98.6→1.158.110.4.0→10.4.116.2.0→16.3.21.0.6→1.0.84.17.21→4.17.253.0.2→3.0.48.2.10→8.2.121.4.12→1.4.1320.17.16→20.19.3118.3.18→18.3.2718.3.5→18.3.76.0.2→6.0.35.1.0→5.2.02.2.0→2.2.13.7.2→3.11.02.1.8→2.1.98.14.0→8.15.05.23.3→5.29.34.7.1→4.9.011.25.2→11.29.00.14.1→0.14.31.11.13→1.11.1916.4.7→16.6.11.32.0→1.44.09.19.0→9.39.29.1.0→9.1.22.31.0→2.32.07.37.4→7.37.55.1.0→5.2.00.4.18→0.5.00.11.2→0.12.011.2.0→11.10.013.0.2→13.6.111.3.0→11.3.315.14.0→15.15.016.10.0→16.12.010.1.1→10.2.05.4.2→5.9.22.11.3→2.17.14.2.2→4.5.14.2.0→4.3.24.2.0→4.3.20.52.2→0.55.14.3.0→4.5.09.6.0→9.14.010.4.0→10.5.03.4.2→3.8.16.10.3→6.11.24.4.6→4.5.018.2.10→18.2.1410.4.14→10.5.24.12.3→4.18.14.32.1→4.57.13.5.3→3.6.07.8.1→7.8.21.83.4→1.97.3^0.33.0→^0.34.02.14.0→2.15.18.5.2→8.6.153.35.0→3.35.129.2.5→29.4.69.5.2→9.5.44.33.0→4.41.08.22.0→8.54.04.2.1→4.2.21.1.1→1.1.411.0.5→11.1.05.4.14→5.4.212.1.8→2.1.96.3.4→6.3.54.6.0→4.12.03.24.1→3.25.76Release Notes
apollographql/apollo-server (@apollo/server)
v4.13.0Compare Source
Minor Changes
#8180⚠️ SECURITY
e9d49d1Thanks @github-actions! -@apollo/server/standalone:The default configuration of
startStandaloneServerwas vulnerable to denial of service (DoS) attacks through specially crafted request bodies with exotic character set encodings.In accordance with RFC 7159, we now only accept request bodies encoded in UTF-8, UTF-16 (LE or BE), or UTF-32 (LE or BE).
Any other character set will be rejected with a
415 Unsupported Media Typeerror.Additionally, upstream libraries used by this version of Apollo Server may not support all of these encodings, so some requests may still fail even if they pass this check.
If you were not using
startStandaloneServer, you were not affected by this vulnerability.Generally, please note that we provide
startStandaloneServeras a convenience tool for quickly getting started with Apollo Server.For production deployments, we recommend using Apollo Server with a more fully-featured web server framework such as Express, Koa, or Fastify, where you have more control over security-related configuration options.
Also please note that Apollo Server 4.x is considered EOL as of January 26, 2026, and Apollo no longer commits to providing support or updates for it. Please prioritize migrating to Apollo Server 5.x for continued support and updates.
v4.12.2Compare Source
(No change; there is a change to the
@apollo/server-integration-testsuiteused to test integrations, and the two packages always have matching versions.)v4.12.1Compare Source
Patch Changes
41f98d4Thanks @glasser! - Update README.md to recommend Express v5 integration now that Express v5 is released.v4.12.0Compare Source
Minor Changes
89e3f84Thanks @clenfest! - Adds a new graphql-js validation rule to reject operations that recursively request selections above a specified maximum, which is disabled by default. Use configuration optionmaxRecursiveSelections=trueto enable with a maximum of 10,000,000, ormaxRecursiveSelections=<number>for a custom maximum. Enabling this validation can help avoid performance issues with configured validation rules or plugins.Patch Changes
2550d9fThanks @slagiewka! - Add return after sending 400 response in doubly escaped JSON parser middlewarechromaui/addon-visual-tests (@chromatic-com/storybook)
v3.2.7Compare Source
🐛 Bug Fix
ComparisonResult.SKIPPEDvalue (@ghengeveld)Authors: 1
v3.2.6Compare Source
🐛 Bug Fix
Authors: 1
v3.2.5Compare Source
🐛 Bug Fix
Authors: 3
conventional-changelog/commitlint (@commitlint/cli)
v19.8.1Compare Source
Bug Fixes
v19.8.0Compare Source
Performance Improvements
node:prefix to bypass require.cache call for builtins (#4302) (0cd8f41)19.7.1 (2025-02-02)
Note: Version bump only for package @commitlint/cli
19.6.1 (2024-12-15)
Note: Version bump only for package @commitlint/cli
v19.7.1Compare Source
Note: Version bump only for package @commitlint/cli
conventional-changelog/commitlint (@commitlint/config-conventional)
v19.8.1Compare Source
Note: Version bump only for package @commitlint/config-conventional
v19.8.0Compare Source
Performance Improvements
node:prefix to bypass require.cache call for builtins (#4302) (0cd8f41)19.7.1 (2025-02-02)
Note: Version bump only for package @commitlint/config-conventional
v19.7.1Compare Source
Note: Version bump only for package @commitlint/config-conventional
facebook/docusaurus (@docusaurus/core)
v3.9.2Compare Source
🐛 Bug Fix
docusaurus-plugin-content-docssidebar_keyfront matter attribute (@slorber)docusaurus-cssnano-presetConfiguration
📅 Schedule: Branch creation - Between 12:00 AM and 03:59 AM, only on Monday ( * 0-3 * * 1 ) in timezone Asia/Tokyo, Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.