chore(deps): update dependency @apollo/server-integration-testsuite to v5#226
Open
renovate[bot] wants to merge 1 commit intomainfrom
Open
chore(deps): update dependency @apollo/server-integration-testsuite to v5#226renovate[bot] wants to merge 1 commit intomainfrom
renovate[bot] wants to merge 1 commit intomainfrom
Conversation
1f1c903 to
0d82924
Compare
b267250 to
5f808fe
Compare
c1e2602 to
4cff8e0
Compare
3270ae3 to
e9226f0
Compare
715a71b to
4b5a39d
Compare
4ee58d4 to
8951840
Compare
8951840 to
adad063
Compare
adad063 to
89b122f
Compare
845f2c0 to
f8b1afe
Compare
09491e0 to
91ef55e
Compare
bd0e6d4 to
59bdc25
Compare
677333f to
448c5ad
Compare
79e73a6 to
ace5782
Compare
e1e5476 to
fc25436
Compare
ced7250 to
db61f79
Compare
90a85ea to
2a7b8f6
Compare
2a7b8f6 to
b753708
Compare
4a23efe to
680bc7c
Compare
b499f70 to
b4930f6
Compare
0bc1b06 to
4c86652
Compare
4c86652 to
0dff049
Compare
831aee3 to
190d7f7
Compare
190d7f7 to
2f97644
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
4.13.0→5.5.0Release Notes
apollographql/apollo-server (@apollo/server-integration-testsuite)
v5.5.0Compare Source
Minor Changes
#8191⚠️ SECURITY
ada1200-@apollo/server/standalone:Apollo Server now rejects GraphQL
GETrequests which contain aContent-Typeheader other thanapplication/json(with optional parameters such as; charset=utf-8). Any other value is now rejected with a 415 status code.(GraphQL
GETrequests without aContent-Typeheader are still allowed, though they do still need to contain a non-emptyX-Apollo-Operation-NameorApollo-Require-Preflightheader to be processed if the default CSRF prevention feature is enabled.)This improvement makes Apollo Server's CSRF more resistant to browsers which implement CORS in non-spec-compliant ways. Apollo is aware of one browser which as of March 2026 has a bug which allows an attacker to circumvent Apollo Server's CSRF prevention feature to carry out read-only XS-Search-style CSRF attacks. The browser vendor is in the process of patching this vulnerability; upgrading Apollo Server to v5.5.0 mitigates this vulnerability.
If your server uses cookies (or HTTP Basic Auth) for authentication, Apollo encourages you to upgrade to v5.5.0.
This is technically a backwards-incompatible change. Apollo is not aware of any GraphQL clients which provide non-empty
Content-Typeheaders withGETrequests with types other thanapplication/json. If your use case requires such requests, please file an issue and we may add more configurability in a follow-up release.See advisory GHSA-9q82-xgwf-vj6h for more details.
Patch Changes
ada1200]:v5.4.0Compare Source
Patch Changes
d25a5bd]:v5.3.0Compare Source
Patch Changes
8e54e58,26320bc]:v5.2.0Compare Source
Patch Changes
51acbeb]:v5.1.0Compare Source
Patch Changes
80a1a1a]:v5.0.0Compare Source
Major Changes
Drop support for Node.JS v14, v16, and v20.
The integration test suite no longer uses
lib: ["dom"]to tell TypeScript to assume DOM-related symbols are in the global namespace. If your integration library's test suite relied on this behavior, you may need to addlib: ["dom"]to thecompilerOptionssection of your test suite'stsconfig.json.Patch Changes
#8078
dabe7baThanks @renovate! - Support Jest v30 as well as Jest v29.Updated dependencies [
5b26558,100233a,100233a,100233a,100233a]:Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.