Bump the npm_and_yarn group across 11 directories with 12 updates#12477
Bump the npm_and_yarn group across 11 directories with 12 updates#12477dependabot[bot] wants to merge 1 commit intomasterfrom
Conversation
Bumps the npm_and_yarn group with 3 updates in the / directory: [tar](https://github.com/isaacs/node-tar), [@apollo/server](https://github.com/apollographql/apollo-server/tree/HEAD/packages/server) and [dompurify](https://github.com/cure53/DOMPurify). Bumps the npm_and_yarn group with 2 updates in the /cypress directory: [lodash](https://github.com/lodash/lodash) and [brace-expansion](https://github.com/juliangruber/brace-expansion). Bumps the npm_and_yarn group with 7 updates in the /microsite directory: | Package | From | To | | --- | --- | --- | | [tar](https://github.com/isaacs/node-tar) | `6.1.13` | `6.2.1` | | [yaml](https://github.com/eemeli/yaml) | `1.10.2` | `1.10.3` | | [brace-expansion](https://github.com/juliangruber/brace-expansion) | `1.1.11` | `1.1.13` | | [immutable](https://github.com/immutable-js/immutable-js) | `4.2.2` | `4.3.8` | | [picomatch](https://github.com/micromatch/picomatch) | `2.3.1` | `2.3.2` | | [serialize-javascript](https://github.com/yahoo/serialize-javascript) | `6.0.1` | `6.0.2` | | [svgo](https://github.com/svg/svgo) | `2.8.0` | `2.8.2` | Bumps the npm_and_yarn group with 1 update in the /packages/backend-common directory: [tar](https://github.com/isaacs/node-tar). Bumps the npm_and_yarn group with 1 update in the /packages/cli directory: [tar](https://github.com/isaacs/node-tar). Bumps the npm_and_yarn group with 1 update in the /plugins/catalog-graphql directory: [@apollo/server](https://github.com/apollographql/apollo-server/tree/HEAD/packages/server). Bumps the npm_and_yarn group with 1 update in the /plugins/gcalendar directory: [dompurify](https://github.com/cure53/DOMPurify). Bumps the npm_and_yarn group with 1 update in the /plugins/graphql-backend directory: [@apollo/server](https://github.com/apollographql/apollo-server/tree/HEAD/packages/server). Bumps the npm_and_yarn group with 1 update in the /plugins/microsoft-calendar directory: [dompurify](https://github.com/cure53/DOMPurify). Bumps the npm_and_yarn group with 1 update in the /plugins/techdocs directory: [dompurify](https://github.com/cure53/DOMPurify). Bumps the npm_and_yarn group with 7 updates in the /storybook directory: | Package | From | To | | --- | --- | --- | | [lodash](https://github.com/lodash/lodash) | `4.17.21` | `4.18.1` | | [tar](https://github.com/isaacs/node-tar) | `6.1.11` | `6.2.1` | | [yaml](https://github.com/eemeli/yaml) | `1.10.2` | `1.10.3` | | [handlebars](https://github.com/handlebars-lang/handlebars.js) | `4.7.7` | `4.7.9` | | [brace-expansion](https://github.com/juliangruber/brace-expansion) | `1.1.11` | `1.1.13` | | [flatted](https://github.com/WebReflection/flatted) | `3.2.6` | `3.4.2` | | [picomatch](https://github.com/micromatch/picomatch) | `2.3.1` | `2.3.2` | Updates `tar` from 6.1.15 to 7.5.11 - [Release notes](https://github.com/isaacs/node-tar/releases) - [Changelog](https://github.com/isaacs/node-tar/blob/main/CHANGELOG.md) - [Commits](isaacs/node-tar@v6.1.15...v7.5.11) Updates `@apollo/server` from 4.8.1 to 5.5.0 - [Release notes](https://github.com/apollographql/apollo-server/releases) - [Changelog](https://github.com/apollographql/apollo-server/blob/main/packages/server/CHANGELOG.md) - [Commits](https://github.com/apollographql/apollo-server/commits/@apollo/server@5.5.0/packages/server) Updates `dompurify` from 2.4.5 to 3.3.2 - [Release notes](https://github.com/cure53/DOMPurify/releases) - [Commits](cure53/DOMPurify@2.4.5...3.3.2) Updates `lodash` from 4.17.21 to 4.18.1 - [Release notes](https://github.com/lodash/lodash/releases) - [Commits](lodash/lodash@4.17.21...4.18.1) Updates `brace-expansion` from 1.1.11 to 1.1.13 - [Release notes](https://github.com/juliangruber/brace-expansion/releases) - [Commits](juliangruber/brace-expansion@1.1.11...v1.1.13) Updates `tar` from 6.1.13 to 6.2.1 - [Release notes](https://github.com/isaacs/node-tar/releases) - [Changelog](https://github.com/isaacs/node-tar/blob/main/CHANGELOG.md) - [Commits](isaacs/node-tar@v6.1.15...v7.5.11) Updates `yaml` from 1.10.2 to 1.10.3 - [Release notes](https://github.com/eemeli/yaml/releases) - [Commits](eemeli/yaml@v1.10.2...v1.10.3) Updates `brace-expansion` from 1.1.11 to 1.1.13 - [Release notes](https://github.com/juliangruber/brace-expansion/releases) - [Commits](juliangruber/brace-expansion@1.1.11...v1.1.13) Updates `immutable` from 4.2.2 to 4.3.8 - [Release notes](https://github.com/immutable-js/immutable-js/releases) - [Changelog](https://github.com/immutable-js/immutable-js/blob/main/CHANGELOG.md) - [Commits](immutable-js/immutable-js@v4.2.2...v4.3.8) Updates `picomatch` from 2.3.1 to 2.3.2 - [Release notes](https://github.com/micromatch/picomatch/releases) - [Changelog](https://github.com/micromatch/picomatch/blob/master/CHANGELOG.md) - [Commits](micromatch/picomatch@2.3.1...2.3.2) Updates `serialize-javascript` from 6.0.1 to 6.0.2 - [Release notes](https://github.com/yahoo/serialize-javascript/releases) - [Commits](yahoo/serialize-javascript@v6.0.1...v6.0.2) Updates `svgo` from 2.8.0 to 2.8.2 - [Release notes](https://github.com/svg/svgo/releases) - [Commits](svg/svgo@v2.8.0...v2.8.2) Updates `tar` from 6.2.1 to 7.5.13 - [Release notes](https://github.com/isaacs/node-tar/releases) - [Changelog](https://github.com/isaacs/node-tar/blob/main/CHANGELOG.md) - [Commits](isaacs/node-tar@v6.1.15...v7.5.11) Updates `tar` from 6.2.1 to 7.5.13 - [Release notes](https://github.com/isaacs/node-tar/releases) - [Changelog](https://github.com/isaacs/node-tar/blob/main/CHANGELOG.md) - [Commits](isaacs/node-tar@v6.1.15...v7.5.11) Updates `@apollo/server` from 4.13.0 to 5.5.0 - [Release notes](https://github.com/apollographql/apollo-server/releases) - [Changelog](https://github.com/apollographql/apollo-server/blob/main/packages/server/CHANGELOG.md) - [Commits](https://github.com/apollographql/apollo-server/commits/@apollo/server@5.5.0/packages/server) Updates `dompurify` from 2.5.9 to 3.3.3 - [Release notes](https://github.com/cure53/DOMPurify/releases) - [Commits](cure53/DOMPurify@2.4.5...3.3.2) Updates `@apollo/server` from 4.13.0 to 5.5.0 - [Release notes](https://github.com/apollographql/apollo-server/releases) - [Changelog](https://github.com/apollographql/apollo-server/blob/main/packages/server/CHANGELOG.md) - [Commits](https://github.com/apollographql/apollo-server/commits/@apollo/server@5.5.0/packages/server) Updates `dompurify` from 2.5.9 to 3.3.3 - [Release notes](https://github.com/cure53/DOMPurify/releases) - [Commits](cure53/DOMPurify@2.4.5...3.3.2) Updates `dompurify` from 2.5.9 to 3.3.3 - [Release notes](https://github.com/cure53/DOMPurify/releases) - [Commits](cure53/DOMPurify@2.4.5...3.3.2) Updates `lodash` from 4.17.21 to 4.18.1 - [Release notes](https://github.com/lodash/lodash/releases) - [Commits](lodash/lodash@4.17.21...4.18.1) Updates `tar` from 6.1.11 to 6.2.1 - [Release notes](https://github.com/isaacs/node-tar/releases) - [Changelog](https://github.com/isaacs/node-tar/blob/main/CHANGELOG.md) - [Commits](isaacs/node-tar@v6.1.15...v7.5.11) Updates `yaml` from 1.10.2 to 1.10.3 - [Release notes](https://github.com/eemeli/yaml/releases) - [Commits](eemeli/yaml@v1.10.2...v1.10.3) Updates `handlebars` from 4.7.7 to 4.7.9 - [Release notes](https://github.com/handlebars-lang/handlebars.js/releases) - [Changelog](https://github.com/handlebars-lang/handlebars.js/blob/v4.7.9/release-notes.md) - [Commits](handlebars-lang/handlebars.js@v4.7.7...v4.7.9) Updates `brace-expansion` from 1.1.11 to 1.1.13 - [Release notes](https://github.com/juliangruber/brace-expansion/releases) - [Commits](juliangruber/brace-expansion@1.1.11...v1.1.13) Updates `flatted` from 3.2.6 to 3.4.2 - [Commits](WebReflection/flatted@v3.2.6...v3.4.2) Updates `picomatch` from 2.3.1 to 2.3.2 - [Release notes](https://github.com/micromatch/picomatch/releases) - [Changelog](https://github.com/micromatch/picomatch/blob/master/CHANGELOG.md) - [Commits](micromatch/picomatch@2.3.1...2.3.2) --- updated-dependencies: - dependency-name: tar dependency-version: 7.5.11 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: "@apollo/server" dependency-version: 5.5.0 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: dompurify dependency-version: 3.3.2 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: lodash dependency-version: 4.18.1 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: brace-expansion dependency-version: 1.1.13 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: tar dependency-version: 6.2.1 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: yaml dependency-version: 1.10.3 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: brace-expansion dependency-version: 1.1.13 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: immutable dependency-version: 4.3.8 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: picomatch dependency-version: 2.3.2 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: serialize-javascript dependency-version: 6.0.2 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: svgo dependency-version: 2.8.2 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: tar dependency-version: 7.5.13 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: tar dependency-version: 7.5.13 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: "@apollo/server" dependency-version: 5.5.0 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: dompurify dependency-version: 3.3.3 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: "@apollo/server" dependency-version: 5.5.0 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: dompurify dependency-version: 3.3.3 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: dompurify dependency-version: 3.3.3 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: lodash dependency-version: 4.18.1 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: tar dependency-version: 6.2.1 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: yaml dependency-version: 1.10.3 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: handlebars dependency-version: 4.7.9 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: brace-expansion dependency-version: 1.1.13 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: flatted dependency-version: 3.4.2 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: picomatch dependency-version: 2.3.2 dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com>
Review or Edit in CodeSandboxOpen the branch in Web Editor • VS Code • Insiders |
EntelligenceAI PR SummaryBroad dependency upgrade across the monorepo targeting security patches and major version updates for several packages.
Confidence Score: 2/5 - Changes NeededNot safe to merge — while this PR makes valuable security improvements (tar v6→v7, dompurify v2→v3), the Key Findings:
Files requiring special attention
|
There was a problem hiding this comment.
Walkthrough
This PR performs a broad dependency upgrade sweep across the monorepo, bumping several packages to newer major versions: tar (v6→v7), @apollo/server (v4→v5), dompurify (v2→v3), and various transitive dependencies (brace-expansion, lodash, immutable, minipass, picomatch, serialize-javascript, svgo, yaml, handlebars, flatted). Lock files across all workspaces are updated accordingly to reflect the new resolved versions and integrity hashes.
Changes
| File(s) | Summary |
|---|---|
packages/backend-common/package.json |
|
packages/cli/package.json |
Bumps tar dependency from ^6.1.12 to ^7.5.13. |
plugins/catalog-graphql/package.json |
|
plugins/graphql-backend/package.json |
Bumps @apollo/server dependency from ^4.0.0 to ^5.5.0. |
plugins/gcalendar/package.json |
|
plugins/microsoft-calendar/package.json |
|
plugins/techdocs/package.json |
Bumps dompurify dependency from ^2.x to ^3.3.3. |
yarn.lock |
Updates resolved versions for @apollo/server (v4→v5.5.0) with cascading updates to @apollo/utils.*, @apollo/server-gateway-interface, @graphql-tools/schema, and transitive replacements (finalhandler, body-parser@2.x, negotiator, uuid@11); upgrades tar to v7.5.11 and dompurify to v3.3.2; adds numerous new transitive dependencies; pins legacy Backstage packages for plugin-gitops-profiles. |
cypress/yarn.lock |
Bumps brace-expansion (1.1.11→1.1.13) and lodash (4.17.21→4.18.1) with updated integrity hashes. |
microsite/yarn.lock |
Bumps brace-expansion (→1.1.13), immutable (→4.3.8), minipass (→5.0.0), picomatch (→2.3.2), serialize-javascript (→6.0.2), svgo (→2.8.2), tar (→6.2.1), and yaml (→1.10.3); replaces @trysound/sax@0.2.0 with sax@1.6.0. |
storybook/yarn.lock |
Bumps brace-expansion (→1.1.13), flatted (→3.4.2), handlebars (→4.7.9), lodash (→4.18.1), picomatch (→2.3.2), tar (→6.2.1), and yaml (→1.10.3); adds minipass@^5.0.0 entry; removes neo-async@^2.6.0 resolution alias. |
Sequence Diagram
This diagram shows the interactions between components:
sequenceDiagram
title Dependency Architecture Changes: Apollo Server v5 & tar v7 Upgrades
participant App as Backstage App
participant GraphQLBackend as graphql-backend plugin
participant CatalogGraphQL as catalog-graphql plugin
participant ApolloV5 as "@apollo/server v5"
participant ApolloV4 as "@apollo/server v4 (removed)"
participant FinalHandler as "finalhandler v2"
participant BodyParserV2 as "body-parser v2"
participant ExpressV4 as "express v4 (removed)"
participant BackendCommon as "backend-common"
participant CLI as "packages/cli"
participant TarV7 as "tar v7"
participant TarV6 as "tar v6"
participant MinipassV7 as "minipass v7"
participant FSMinipass as "@isaacs/fs-minipass v4"
Note over App, ExpressV4: BEFORE: Apollo Server v4 used Express as HTTP layer
App->>GraphQLBackend: initialize GraphQL server
GraphQLBackend->>ApolloV4: create ApolloServer
ApolloV4->>ExpressV4: mount middleware
ApolloV4->>ApolloV4: use node-fetch, lru-cache v7
ApolloV4->>ApolloV4: use @josephg/resolvable, node-abort-controller
Note over App, FSMinipass: AFTER: Apollo Server v5 uses standalone HTTP handler
App->>GraphQLBackend: initialize GraphQL server
GraphQLBackend->>ApolloV5: create ApolloServer (^5.5.0)
activate ApolloV5
ApolloV5->>FinalHandler: handle HTTP lifecycle
ApolloV5->>BodyParserV2: parse request bodies
ApolloV5->>ApolloV5: use lru-cache v11, uuid v11
ApolloV5->>ApolloV5: use negotiator v1, whatwg-mimetype v4
ApolloV5->>ApolloV5: use @graphql-tools/schema v10
ApolloV5-->>GraphQLBackend: server ready (no Express dependency)
deactivate ApolloV5
App->>CatalogGraphQL: initialize catalog GraphQL
CatalogGraphQL->>ApolloV5: create ApolloServer (^5.5.0)
Note over BackendCommon, FSMinipass: tar v6 -> v7 upgrade chain
App->>BackendCommon: extract archive
BackendCommon->>TarV6: tar ^6.1.12 (old)
Note over TarV6: uses minipass v4, yallist v4, chownr v2
App->>BackendCommon: extract archive
activate BackendCommon
BackendCommon->>TarV7: tar ^7.5.13 (new)
activate TarV7
TarV7->>FSMinipass: @isaacs/fs-minipass v4
TarV7->>MinipassV7: minipass v7.1.2
TarV7->>TarV7: yallist v5, chownr v3, minizlib v3
TarV7-->>BackendCommon: archive extracted
deactivate TarV7
deactivate BackendCommon
App->>CLI: build/package commands
CLI->>TarV7: tar ^7.5.13 (upgraded from v6)
Note over App, FSMinipass: Security-motivated plugin version pinning
participant GitOpsPlugin as "gitops-profiles plugin"
participant CorePluginAPI as "core-plugin-api (workspace)"
App->>GitOpsPlugin: load plugin
GitOpsPlugin->>GitOpsPlugin: pinned @backstage/config@0.1.1
GitOpsPlugin->>GitOpsPlugin: pinned @backstage/core-components@0.1.0
GitOpsPlugin->>GitOpsPlugin: pinned @backstage/core-plugin-api@0.1.0
GitOpsPlugin->>GitOpsPlugin: pinned @backstage/theme@0.1.1
App->>CorePluginAPI: load core-plugin-api
CorePluginAPI->>CorePluginAPI: pinned @backstage/config@0.1.1
CorePluginAPI->>CorePluginAPI: pinned @backstage/version-bridge@0.1.0
Note over App, FSMinipass: dompurify v2 -> v3 across plugins
participant TechDocs as "techdocs plugin"
participant GCalendar as "gcalendar plugin"
participant MSCalendar as "microsoft-calendar plugin"
participant DomPurifyV3 as "dompurify v3.3.3"
TechDocs->>DomPurifyV3: sanitize HTML (upgraded from ^2.2.9)
GCalendar->>DomPurifyV3: sanitize HTML (upgraded from ^2.3.6)
MSCalendar->>DomPurifyV3: sanitize HTML (upgraded from ^2.3.6)
Note over DomPurifyV3: Now requires @types/trusted-types v2
🔗 Cross-Repository Impact Analysis
Enable automatic detection of breaking changes across your dependent repositories. → Set up now
Learn more about Cross-Repository Analysis
What It Does
- Automatically identifies repositories that depend on this code
- Analyzes potential breaking changes across your entire codebase
- Provides risk assessment before merging to prevent cross-repo issues
How to Enable
- Visit Settings → Code Management
- Configure repository dependencies
- Future PRs will automatically include cross-repo impact analysis!
Benefits
- 🛡️ Prevent breaking changes across repositories
- 🔍 Catch integration issues before they reach production
- 📊 Better visibility into your multi-repo architecture
| @@ -33,7 +33,7 @@ | |||
| "clean": "backstage-cli package clean" | |||
There was a problem hiding this comment.
Correctness: Bumping @apollo/server from ^4.0.0 to ^5.5.0 is a major version upgrade with breaking API changes (e.g., expressMiddleware signature, context function shape, plugin API), but no source files in this PR are updated to reflect those changes, which will likely cause build or runtime failures.
🤖 AI Agent Prompt for Cursor/Windsurf
📋 Copy this prompt to your AI coding assistant (Cursor, Windsurf, etc.) to get help fixing this issue
In plugins/graphql-backend/package.json line 33, the @apollo/server dependency is being bumped from ^4.0.0 to ^5.5.0. Apollo Server v5 introduced breaking changes compared to v4, including changes to expressMiddleware, context function signatures, and the plugin API. No TypeScript source files in plugins/graphql-backend/src/ are being updated in this PR to accommodate these breaking changes. Please review the Apollo Server v5 migration guide (https://www.apollographql.com/docs/apollo-server/migration/) and update all usages of Apollo Server APIs in the plugin source code accordingly before merging this dependency bump.
| @@ -33,7 +33,7 @@ | |||
| "clean": "backstage-cli package clean" | |||
There was a problem hiding this comment.
Correctness: Bumping @apollo/server from ^4.0.0 to ^5.5.0 is a major version upgrade with breaking API changes (e.g., expressMiddleware signature, context function shape, plugin API), but no source files in this PR are updated to reflect those changes, which will likely cause build or runtime failures.
Affected Locations:
- plugins/graphql-backend/package.json:33-33
- plugins/catalog-graphql/package.json:38-38
🤖 AI Agent Prompt for Cursor/Windsurf
📋 Copy this prompt to your AI coding assistant (Cursor, Windsurf, etc.) to get help fixing this issue
In plugins/graphql-backend/package.json line 33, the @apollo/server dependency is being bumped from ^4.0.0 to ^5.5.0. Apollo Server v5 introduced breaking changes compared to v4, including changes to expressMiddleware, context function signatures, and the plugin API. No TypeScript source files in plugins/graphql-backend/src/ are being updated in this PR to accommodate these breaking changes. Please review the Apollo Server v5 migration guide (https://www.apollographql.com/docs/apollo-server/migration/) and update all usages of Apollo Server APIs in the plugin source code accordingly before merging this dependency bump.
🤖 Augment PR SummarySummary: This PR updates a set of npm/yarn dependencies across multiple workspaces (root, plugins, and packages), primarily as a dependency/security maintenance bump. Changes:
Technical Notes:
🤖 Was this summary useful? React with 👍 or 👎 |
| "selfsigned": "^2.0.0", | ||
| "stoppable": "^1.1.0", | ||
| "tar": "^6.1.12", | ||
| "tar": "^7.5.13", |
There was a problem hiding this comment.
tar@7 declares engines: { node: ">=18" }, but this repo’s root package.json currently allows Node 16 || 18; this upgrade can break installs/runs for Node 16 users/CI. Other locations where this applies: packages/cli/package.json:130.
Severity: high
Other Locations
packages/cli/package.json:130
🤖 Was this useful? React with 👍 or 👎, or 🚀 if it prevented an incident/outage.
| @@ -33,7 +33,7 @@ | |||
| "clean": "backstage-cli package clean" | |||
| }, | |||
There was a problem hiding this comment.
@apollo/server@5 drops Node 16/18 support (Node 20+ only per upstream) and also removes the built-in Express v4 integration import (@apollo/server/express4), which is currently used in plugins/graphql-backend/src/service/router.ts. This dependency bump is therefore very likely to break both runtime Node compatibility and the Express middleware wiring. Other locations where this applies: plugins/catalog-graphql/package.json:36.
Severity: high
Other Locations
plugins/catalog-graphql/package.json:36
🤖 Was this useful? React with 👍 or 👎, or 🚀 if it prevented an incident/outage.
|
This PR has been automatically marked as stale because it has not had recent activity from the author. It will be closed if no further activity occurs. If the PR was closed and you want it re-opened, let us know and we'll re-open the PR so that you can continue the contribution! |
|
This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests. To ignore these dependencies, configure ignore rules in dependabot.yml |
Bumps the npm_and_yarn group with 3 updates in the / directory: tar, @apollo/server and dompurify.
Bumps the npm_and_yarn group with 2 updates in the /cypress directory: lodash and brace-expansion.
Bumps the npm_and_yarn group with 7 updates in the /microsite directory:
6.1.136.2.11.10.21.10.31.1.111.1.134.2.24.3.82.3.12.3.26.0.16.0.22.8.02.8.2Bumps the npm_and_yarn group with 1 update in the /packages/backend-common directory: tar.
Bumps the npm_and_yarn group with 1 update in the /packages/cli directory: tar.
Bumps the npm_and_yarn group with 1 update in the /plugins/catalog-graphql directory: @apollo/server.
Bumps the npm_and_yarn group with 1 update in the /plugins/gcalendar directory: dompurify.
Bumps the npm_and_yarn group with 1 update in the /plugins/graphql-backend directory: @apollo/server.
Bumps the npm_and_yarn group with 1 update in the /plugins/microsoft-calendar directory: dompurify.
Bumps the npm_and_yarn group with 1 update in the /plugins/techdocs directory: dompurify.
Bumps the npm_and_yarn group with 7 updates in the /storybook directory:
4.17.214.18.16.1.116.2.11.10.21.10.34.7.74.7.91.1.111.1.133.2.63.4.22.3.12.3.2Updates
tarfrom 6.1.15 to 7.5.11Changelog
Sourced from tar's changelog.
... (truncated)
Commits
bf776f67.5.11f48b5faprevent escaping symlinks with drive-relative paths97cff15docs: more security info2b72abc7.5.107bc755dparse root off paths before sanitizing .. partsc8cb846update deps1f0c2c97.5.9fbb0851build minified version as default export6b8eba07.5.82cb1120fix(unpack): improve UnpackSync symlink error "into" path accuracyMaintainer changes
This version was pushed to npm by isaacs, a new releaser for tar since your current version.
Install script changes
This version adds
preparescript that runs during installation. Review the package contents before updating.Updates
@apollo/serverfrom 4.8.1 to 5.5.0Release notes
Sourced from
@apollo/server's releases.... (truncated)
Changelog
Sourced from
@apollo/server's changelog.... (truncated)
Commits
64c0e1bVersion Packages (#8192)ada1200Reject GET requests with a Content-Type other than application/json (#8191)ad45d15Version Packages (#8179)d25a5bdMerge commit from fork443e547fix repository urls28d6d47Version Packages (#8172)26320bcfeat: Allow configuration of graphql validation options #8014f2c16a7bump dependency8e54e58feat: Allow configuration of graphql execution options(maxCoercionErrors)7be3686Version Packages (#8163)Maintainer changes
This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for
@apollo/serversince your current version.Updates
dompurifyfrom 2.4.5 to 3.3.2Release notes
Sourced from dompurify's releases.
... (truncated)
Commits
5e56114Getting 3.x branch ready for 3.3.2 release (#1208)e8c95f4fix: Fixed the broken package-lock.json9636037Update package-lock.json5cad4ceGetting 3.x branch ready for 3.3.2 releas (#1205)6fc446aMerge pull request #1175 from cure53/main3b3bf91Merge branch 'main' of github.com:cure53/DOMPurify9863f41chore: Preparing 3.3.1 releaseb4e0295chore: Preparing 3.3.0 release077746bbuild(deps-dev): bump js-yaml from 4.1.0 to 4.1.1 (#1170)4de68bbbuild(deps): bump actions/checkout from 5 to 6 (#1171)Updates
lodashfrom 4.17.21 to 4.18.1Release notes
Sourced from lodash's releases.
Commits
cb0b9b9release(patch): bump main to 4.18.1 (#6177)75535f5chore: prune stale advisory refs (#6170)62e91bcdocs: remove n_ Node.js < 6 REPL note from README (#6165)59be2derelease(minor): bump to 4.18.0 (#6161)af63457fix: broken tests for _.template 879aaa91073a76fix: linting issues879aaa9fix: validate imports keys in _.templatefe8d32efix: block prototype pollution in baseUnset via constructor/prototype traversal18ba0a3refactor(fromPairs): use baseAssignValue for consistent assignment (#6153)b819080ci: add dist sync validation workflow (#6137)Updates
brace-expansionfrom 1.1.11 to 1.1.13Release notes
Sourced from brace-expansion's releases.
Commits
6c353ca1.1.137fd684fBackport fix for GHSA-f886-m6hf-6m8v (#95)44f33b41.1.12c460dbdpkg: publish on tag 1.xccb8ac6fmtc3c73c8Fix potential ReDoS Vulnerability or Inefficient Regular Expression (#65)Updates
tarfrom 6.1.13 to 6.2.1Changelog
Sourced from tar's changelog.
... (truncated)
Commits
bf776f67.5.11f48b5faprevent escaping symlinks with drive-relative paths97cff15docs: more security info2b72abc7.5.107bc755dparse root off paths before sanitizing .. partsc8cb846update deps1f0c2c97.5.9fbb0851build minified version as default export6b8eba07.5.82cb1120fix(unpack): improve UnpackSync symlink error "into" path accuracyMaintainer changes
This version was pushed to npm by isaacs, a new releaser for tar since your current version.
Install script changes
This version adds
preparescript that runs during installation. Review the package contents before updating.Updates
yamlfrom 1.10.2 to 1.10.3Commits
cfe8f041.10.37abcf45fix: Catch stack overflow during CST compositiona0252f8chore: Add rules avoiding processing of tests/json-test-suitea5e83b0style: Apply updates Prettier rulesb8ddca0chore: Refresh lockfile395f892ci: Use a different (working) submodule checkout6fd2720test-events: Add {} and [] indicators to flow maps & sequencesUpdates
brace-expansionfrom 1.1.11 to 1.1.13Release notes
Sourced from brace-expansion's releases.
Commits
6c353ca1.1.137fd684fBackport fix for GHSA-f886-m6hf-6m8v (#95)44f33b41.1.12c460dbdpkg: publish on tag 1.xccb8ac6fmtc3c73c8Fix potential ReDoS Vulnerability or Inefficient Regular Expression (#65)Updates
immutablefrom 4.2.2 to 4.3.8Release notes
Sourced from immutable's releases.
... (truncated)
Changelog
Sourced from immutable's changelog.
... (truncated)
Commits
485cbe04.3.86ed4eb6Merge commit from fork94bcd3cfix new proto key injectionfaeb58bfix Prototype Pollution in mergeDeep, toJS, etc.37ca417release 4.3.7 (#2007)23daf26Fix issue with slice negative of filtered sequence (#2006)493afbarelease 4.3.6 (#1997)be3cb9aFix Repeat(<value>).equals(undefined) incorrectly returning true (#1994)d7664bfgenerate sitemap in path that will be deployedf8327b1upgrade next sitemap (#1978)Maintainer changes
This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for immutable since your current version.
Updates
picomatchfrom 2.3.1 to 2.3.2Release notes
Sourced from picomatch's releases.
Changelog
Sourced from picomatch's changelog.
... (truncated)
Commits
81cba8dPublish 2.3.2fc1f6b6Merge commit from forkeec17aeMerge commit from fork78f8ca4Merge pull request #156 from micromatch/backport-1443f4f10eMerge pull request #144 from Jason3S/jdent-object-propertiesUpdates
serialize-javascriptfrom 6.0.1 to 6.0.2Release notes
Sourced from serialize-javascript's releases.
Commits
b71ec236.0.2f27d65dfix: serialize URL string contents to prevent XSS (#173)02499c0Bump@babel/traversefrom 7.10.1 to 7.23.7 (#171)0d88527docs: update readme with URL support (#146)e2a3a91chore: update node version and lock file5a1fa64fix typo (#164)Updates
svgofrom 2.8.0 to 2.8.2Release notes
Sourced from svgo's releases.