Open
Conversation
1c11fdb to
9f41f68
Compare
c9cb0d9 to
b1eff80
Compare
b4d316b to
42fd35a
Compare
30b8555 to
3446370
Compare
3446370 to
5daf10f
Compare
5daf10f to
feb0147
Compare
feb0147 to
af17ceb
Compare
66a83be to
4adf963
Compare
c994896 to
9017f61
Compare
9017f61 to
4c90bee
Compare
4c90bee to
6209724
Compare
34ddfdb to
7ec89dd
Compare
7ec89dd to
ea8f921
Compare
e5ea4b0 to
0d4106d
Compare
8216021 to
fbdddfb
Compare
fbdddfb to
27ae7aa
Compare
27ae7aa to
731e4e5
Compare
40521f4 to
47031eb
Compare
47031eb to
51dd026
Compare
5a1e048 to
1b201d7
Compare
3d26522 to
2068a07
Compare
2068a07 to
49ddbe9
Compare
49ddbe9 to
3ec1ee0
Compare
8729894 to
e92959e
Compare
e92959e to
11b6c09
Compare
11b6c09 to
3337db5
Compare
3337db5 to
5695d23
Compare
5695d23 to
94ae8a8
Compare
a73a02c to
00c744e
Compare
4e3fecf to
4f14e9b
Compare
b1824a8 to
89cf992
Compare
89cf992 to
b983b9b
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
2.10.1→2.13.13.9.0→3.13.03.9.0→3.13.03.6.1→3.8.2Release Notes
apollographql/federation (@apollo/gateway)
v2.13.1Compare Source
Patch Changes
Allow bumping
make-fetch-happendependency to v15. (#3374)This change allows users to upgrade
make-fetch-happento v15, which in turn will allow updating thecacachedependency from v17 to v20, dropping thetarv6 dependency that is marked as vulnerable.The only breaking changes in
make-fetch-happenfrom v11 to v15 are removals of support for old end-of-life Node.js versions.There is only one note from the 12.0.0 release of
make-fetch-happenthat might be of interest when considering the upgrade:As a result, it should be possible for most users to upgrade from v11 to v15 without any issues.
We still keep the dependency to v11 as an alternative for people that cannot upgrade to v15 for some reason. This will be removed in a future version of
@apollo/gateway.Even for users that stay on v11, there should not be any immediate danger. While
cacachehadtarv6 as a dependency, it actually never used it. It seems that that dependency had become unused at some point but was never removed. So users onmake-fetch-happenv11 are not actually affected by the vulnerability intarv6.The dependency might hold the
tarpackage required by other packages back, though. In case an update from v11 to v15 is not possible, users should consider to use the resolution override feature of their package manager to force the dependency fromcacachetotarto either be removed or updated to a newer version. Ascacachedoes not actually usetar, this should not cause any issues.Updated dependencies []:
v2.13.0Compare Source
Minor Changes
Patch Changes
f4d2f4a1f50a92be37ea7179eddb3681f36d9d15,523b13b715e75033f0bdbc176416e59ac01de8f0,ecbe182423313b3a94c185dee6b659573435b141,4c64006b1604471940e20aa1aa46a0f75a6396df,873577a2b7ae8ce507e0ca4377aed049e1a15075]:v2.12.2Compare Source
Patch Changes
238d9d71e831e4f3e8d8e334ad6952cc19c073b1]:v2.12.1Compare Source
Patch Changes
b19431e4a92206703e29aba859a5fc7574b9ef8b,09e596e6a0c753071ca822e84f525d73ada395cf,ac1ed2946c48e0fef4b413b192d8c5fbdb2370ae]:v2.12.0Compare Source
Minor Changes
Patch Changes
3e2b0a8569a9fe46726182887ed0b4bfc0b52468,bb4614d338ae03bac51a5fc2439590f172c4e54d,99f2da21de88f9ad9a32ee7ed64b2d4a92887b40,468f27842608f4e390cfc88bc7e6b4b0945f95ff,3fd5157b309f1d3439b2d87c67b0601fb246d04c,b734ea04d118db09cf6077fdd968c8f04a96327a,4bda3a498eba36e187dfd9ae673eca12d3f3502c,e7e67579908d5cd2fa6fe558228dffe4808cd98d,f3ab499eaf62b1a1c0f08b838d2cbde5accb303a,faea2d1174d80593264f2227cfde9a2ba1a59b96,0dbc7cc72ffacf324231e9ccb2de4189f6bf3289,97b9d2edfcfeed99124f9e115f992cbef3804682,f6af504f1ba8283fd00af0d6e3c9c1a665d62736,bc07e979b9fd24c9b94740b170f11023fe99ba1e,a595235d3cf8f67611efd8395332b64d067b5f1f,9cbdcb53f859c877a476e2725faa4cb205506f57]:v2.11.5Compare Source
Patch Changes
5ee4d966487e714ae6bc6445bf53d75ccbbaf6ae,e1c58611c3c996b4fff98a54e49f00549ff2115d,3e2d1fd315db54a089fedf131cfaa27792bdd049]:v2.11.4Compare Source
Patch Changes
d221ac04c3ee00a3c7a671d9d56e2cfa36943b49,7730c03e128be6754b9e40c086d5cb5c4685ac66,4bda3a498eba36e187dfd9ae673eca12d3f3502c,f3ab499eaf62b1a1c0f08b838d2cbde5accb303a,6adbf7e86927de969aedab665b6a3a8dbf3a6095,2a20dc38dfc40e0b618d5cc826f18a19ddb91aff]:v2.11.3Compare Source
Patch Changes
4faa114215200daf7ad7518be8e50071fcde783c,8c7a2cd655ad3060e9f5c3b106cfbdb59251701c]:v2.11.2Compare Source
Patch Changes
28c08bef6e691aefc6ed07c0e7057f9cd803b317,28c08bef6e691aefc6ed07c0e7057f9cd803b317]:v2.11.1Compare Source
Patch Changes
7799ad1717becf15fb0e82f89619f2ec8a24b4d4,b26794c5724ef23d1f0fd45a40aee3d301557489,51bed5be49d8e87adae59f568315c9e3488a91e0]:v2.11.0Compare Source
Minor Changes
Patch Changes
Corrects a set of denial-of-service (DOS) vulnerabilities that made it possible for an attacker to render gateway inoperable with certain simple query patterns due to uncontrolled resource consumption. All prior-released versions and configurations are vulnerable. (#3238)
See the associated GitHub Advisories GHSA-q2f9-x4p4-7xmh and GHSA-p2q6-pwh5-m6jr for more information.
Updated dependencies [
1462c91879d41884c0a7e60551d8dd0d67c832d3,9614b26e5a17cbf1f6aaf08f6fcb1c95eb12592d,9614b26e5a17cbf1f6aaf08f6fcb1c95eb12592d]:v2.10.4Compare Source
Patch Changes
8377f039b4c888ecdda2a2b0b0ca181a343cb81a,20c75d1d60a48fc289d88c8d29652f1afc7553e4]:v2.10.3Compare Source
Patch Changes
2b88aec38d5bacb6ec815d885fdac47ef415124a,18a9cfaf533602bb37fdf22962539ce0eae948c8,9c0aaa0874c98ae8ce0cc38cad7f6f25d2c29635,f94e7b35c43ed64c67ff25c7aeb86ec0dd73370a]:v2.10.2Compare Source
Patch Changes
0e457586002f5fd06eacfd00954ef1e285fd52d6]:apollographql/apollo-server (apollo-server)
v3.13.0Compare Source
v3.12.1Compare Source
v3.12.0Compare Source
v3.11.1Compare Source
v3.11.0Compare Source
v3.10.4Compare Source
v3.10.3Compare Source
v3.10.2Compare Source
v3.10.1Compare Source
v3.10.0Compare Source
apollographql/apollo-server (apollo-server-express)
v3.13.0Compare Source
v3.12.1Compare Source
v3.12.0Compare Source
v3.11.1Compare Source
v3.11.0Compare Source
v3.10.4Compare Source
v3.10.3Compare Source
v3.10.2Compare Source
v3.10.1Compare Source
v3.10.0Compare Source
apollographql/apollo-server (apollo-server-plugin-response-cache)
v3.8.2Compare Source
v3.8.1Compare Source
v3.8.0Compare Source
v3.7.1Compare Source
v3.7.0Compare Source
Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.