chore(deps): update apollo graphql packages to v5#241
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
Contributor
Author
|
ccc9cb1 to
1ae7fed
Compare
1ae7fed to
af2b179
Compare
af2b179 to
039b2a2
Compare
039b2a2 to
34dfe55
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
4.11.3→5.5.1Release Notes
apollographql/apollo-server (@apollo/server-integration-testsuite)
v5.5.1Compare Source
Patch Changes
3f46c51]:v5.5.0Compare Source
Minor Changes
#8191⚠️ SECURITY
ada1200-@apollo/server/standalone:Apollo Server now rejects GraphQL
GETrequests which contain aContent-Typeheader other thanapplication/json(with optional parameters such as; charset=utf-8). Any other value is now rejected with a 415 status code.(GraphQL
GETrequests without aContent-Typeheader are still allowed, though they do still need to contain a non-emptyX-Apollo-Operation-NameorApollo-Require-Preflightheader to be processed if the default CSRF prevention feature is enabled.)This improvement makes Apollo Server's CSRF more resistant to browsers which implement CORS in non-spec-compliant ways. Apollo is aware of one browser which as of March 2026 has a bug which allows an attacker to circumvent Apollo Server's CSRF prevention feature to carry out read-only XS-Search-style CSRF attacks. The browser vendor is in the process of patching this vulnerability; upgrading Apollo Server to v5.5.0 mitigates this vulnerability.
If your server uses cookies (or HTTP Basic Auth) for authentication, Apollo encourages you to upgrade to v5.5.0.
This is technically a backwards-incompatible change. Apollo is not aware of any GraphQL clients which provide non-empty
Content-Typeheaders withGETrequests with types other thanapplication/json. If your use case requires such requests, please file an issue and we may add more configurability in a follow-up release.See advisory GHSA-9q82-xgwf-vj6h for more details.
Patch Changes
ada1200]:v5.4.0Compare Source
Patch Changes
d25a5bd]:v5.3.0Compare Source
Patch Changes
8e54e58,26320bc]:v5.2.0Compare Source
Patch Changes
51acbeb]:v5.1.0Compare Source
Patch Changes
80a1a1a]:v5.0.0Compare Source
Major Changes
Drop support for Node.JS v14, v16, and v20.
The integration test suite no longer uses
lib: ["dom"]to tell TypeScript to assume DOM-related symbols are in the global namespace. If your integration library's test suite relied on this behavior, you may need to addlib: ["dom"]to thecompilerOptionssection of your test suite'stsconfig.json.Patch Changes
#8078
dabe7baThanks @renovate! - Support Jest v30 as well as Jest v29.Updated dependencies [
5b26558,100233a,100233a,100233a,100233a]:v4.13.0Compare Source
Patch Changes
e9d49d1]:v4.12.2Compare Source
Patch Changes
#8070
0dee3c9Thanks @glasser! - Provide dual-build CJS and ESM for@apollo/server-integration-testsuite.We previously provided only a CJS build of this package, unlike
@apollo/serveritself and the other helper packages that come with it. We may make all of
Apollo Server ESM-only in AS5; this is a step in that direction. Specifically,
only providing this package for CJS makes it challenging to run the tests in
ts-jestin some ESM-only setups, because the copy of@apollo/serverfetcheddirectly in your ESM-based test may differ from the copy fetched indirectly via
@apollo/server-integration-testsuite, causing the "lockstep versioning" testto fail.
Updated dependencies:
v4.12.1Compare Source
Patch Changes
41f98d4]:v4.12.0Compare Source
Patch Changes
89e3f84,2550d9f]:Configuration
📅 Schedule: (in timezone America/Los_Angeles)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.