Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(deps): update all non-major dependencies #1780

Merged
merged 5 commits into from
Dec 6, 2024

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Oct 15, 2024

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
@apollo/server (source) ^4.11.0 -> ^4.11.2 age adoption passing confidence
@babel/cli (source) ^7.25.7 -> ^7.26.4 age adoption passing confidence
@babel/code-frame (source) ^8.0.0-alpha.12 -> ^8.0.0-alpha.14 age adoption passing confidence
@babel/core (source) ^7.25.8 -> ^7.26.0 age adoption passing confidence
@babel/eslint-parser (source) ^7.25.8 -> ^7.25.9 age adoption passing confidence
@babel/plugin-transform-runtime (source) ^7.25.7 -> ^7.25.9 age adoption passing confidence
@babel/preset-env (source) ^7.25.8 -> ^7.26.0 age adoption passing confidence
@babel/preset-react (source) ^7.25.7 -> ^7.26.3 age adoption passing confidence
@babel/preset-typescript (source) ^7.25.7 -> ^7.26.0 age adoption passing confidence
@babel/register (source) ^7.25.7 -> ^7.25.9 age adoption passing confidence
@babel/runtime (source) ^7.25.7 -> ^7.26.0 age adoption passing confidence
@chakra-ui/react (source) ^2.10.2 -> ^2.10.4 age adoption passing confidence
@changesets/cli (source) ^2.27.9 -> ^2.27.10 age adoption passing confidence
@dnd-kit/core (source) ^6.1.0 -> ^6.3.1 age adoption passing confidence
@emotion/react (source) ^11.13.3 -> ^11.13.5 age adoption passing confidence
@emotion/styled (source) ^11.13.0 -> ^11.13.5 age adoption passing confidence
@eslint/compat ^1.2.0 -> ^1.2.4 age adoption passing confidence
@reduxjs/toolkit (source) ^2.2.8 -> ^2.4.0 age adoption passing confidence
@rjsf/core ^5.21.2 -> ^5.23.1 age adoption passing confidence
@rjsf/utils ^5.21.2 -> ^5.23.1 age adoption passing confidence
@rjsf/validator-ajv8 ^5.21.2 -> ^5.23.1 age adoption passing confidence
@storybook/addon-essentials (source) ^8.3.5 -> ^8.4.7 age adoption passing confidence
@storybook/addon-interactions (source) ^8.3.5 -> ^8.4.7 age adoption passing confidence
@storybook/addon-links (source) ^8.3.5 -> ^8.4.7 age adoption passing confidence
@storybook/addon-onboarding (source) ^8.3.5 -> ^8.4.7 age adoption passing confidence
@storybook/blocks (source) ^8.3.5 -> ^8.4.7 age adoption passing confidence
@storybook/react (source) ^8.3.5 -> ^8.4.7 age adoption passing confidence
@storybook/react-webpack5 (source) ^8.3.5 -> ^8.4.7 age adoption passing confidence
@storybook/test (source) ^8.3.5 -> ^8.4.7 age adoption passing confidence
@testing-library/jest-dom ^6.5.0 -> ^6.6.3 age adoption passing confidence
@testing-library/react ^16.0.1 -> ^16.1.0 age adoption passing confidence
@types/chrome (source) ^0.0.278 -> ^0.0.287 age adoption passing confidence
@types/jest (source) ^29.5.13 -> ^29.5.14 age adoption passing confidence
@types/lodash (source) ^4.17.10 -> ^4.17.13 age adoption passing confidence
@types/node (source) ^20.16.11 -> ^20.17.9 age adoption passing confidence
@types/react (source) ^18.3.11 -> ^18.3.14 age adoption passing confidence
@types/react-dom (source) ^18.3.1 -> ^18.3.2 age adoption passing confidence
@types/react-test-renderer (source) ^18.3.0 -> ^18.3.1 age adoption passing confidence
@typescript-eslint/eslint-plugin (source) ^8.9.0 -> ^8.17.0 age adoption passing confidence
@typescript-eslint/parser (source) ^8.9.0 -> ^8.17.0 age adoption passing confidence
electron ^31.7.0 -> ^31.7.6 age adoption passing confidence
eslint-plugin-jest ^28.8.3 -> ^28.9.0 age adoption passing confidence
eslint-plugin-react ^7.37.1 -> ^7.37.2 age adoption passing confidence
express (source) ^4.21.1 -> ^4.21.2 age adoption passing confidence
framer-motion ^11.11.8 -> ^11.13.1 age adoption passing confidence
globals ^15.11.0 -> ^15.13.0 age adoption passing confidence
html-webpack-plugin ^5.6.0 -> ^5.6.3 age adoption passing confidence
nanoid ^5.0.7 -> ^5.0.9 age adoption passing confidence
pnpm (source) 9.12.1 -> 9.15.0 age adoption passing confidence
prettier (source) 3.3.3 -> 3.4.2 age adoption passing confidence
react-bootstrap (source) ^2.10.5 -> ^2.10.6 age adoption passing confidence
react-icons ^5.3.0 -> ^5.4.0 age adoption passing confidence
react-router-dom (source) ^6.27.0 -> ^6.28.0 age adoption passing confidence
react-select (source) ^5.8.1 -> ^5.8.3 age adoption passing confidence
selenium-webdriver (source) ^4.25.0 -> ^4.27.0 age adoption passing confidence
socketcluster-client (source) ^19.2.2 -> ^19.2.3 age adoption passing confidence
socketcluster-server ^19.1.0 -> ^19.1.1 age adoption passing confidence
storybook (source) ^8.3.5 -> ^8.4.7 age adoption passing confidence
stylelint (source) ^16.10.0 -> ^16.11.0 age adoption passing confidence
typescript-eslint (source) ^8.9.0 -> ^8.17.0 age adoption passing confidence
webpack ^5.95.0 -> ^5.97.1 age adoption passing confidence

Release Notes

apollographql/apollo-server (@​apollo/server)

v4.11.2

Compare Source

(No change; there is a change to the @apollo/server-integration-testsuite used to test integrations, and the two packages always have matching versions.)

v4.11.1

Compare Source

Patch Changes
  • #​7952 bb81b2c Thanks @​glasser! - Upgrade dependencies so that automated scans don't detect a vulnerability.

    @apollo/server depends on express which depends on cookie. Versions of express older than v4.21.1 depend on a version of cookie vulnerable to CVE-2024-47764. Users of older express versions who call res.cookie() or res.clearCookie() may be vulnerable to this issue.

    However, Apollo Server does not call this function directly, and it does not expose any object to user code that allows TypeScript users to call this function without an unsafe cast.

    The only way that this direct dependency can cause a vulnerability for users of Apollo Server is if you call startStandaloneServer with a context function that calls Express-specific methods such as res.cookie() or res.clearCookies() on the response object, which is a violation of the TypeScript types provided by startStandaloneServer (which only promise that the response object is a core Node.js http.ServerResponse rather than the Express-specific subclass). So this vulnerability can only affect Apollo Server users who use unsafe JavaScript or unsafe as typecasts in TypeScript.

    However, this upgrade will at least prevent vulnerability scanners from alerting you to this dependency, and we encourage all Express users to upgrade their project's own express dependency to v4.21.1 or newer.

babel/babel (@​babel/cli)

v7.26.4

Compare Source

↩️ Revert
  • babel-traverse

v7.25.9

Compare Source

🐛 Bug Fix
🏠 Internal
🏃‍♀️ Performance
babel/babel (@​babel/code-frame)

v8.0.0-alpha.14

Compare Source

v8.0.0-alpha.13

Compare Source

v8.0.0-alpha.13 (2024-10-25)

In addition to the changelog below, this release includes changes from v7.25.1 to v7.26.0

💥 Breaking Change
  • babel-generator, babel-parser, babel-plugin-transform-typescript, babel-traverse, babel-types
  • babel-generator, babel-parser, babel-plugin-proposal-pipeline-operator, babel-plugin-syntax-pipeline-operator, babel-standalone
  • babel-parser
  • babel-plugin-transform-class-static-block, babel-plugin-transform-destructuring, babel-plugin-transform-spread, babel-traverse
  • babel-generator, babel-parser, babel-plugin-proposal-import-wasm-source, babel-template, babel-types
  • babel-generator, babel-parser, babel-standalone
  • babel-generator, babel-traverse, babel-types
  • `babe

Copy link

changeset-bot bot commented Oct 15, 2024

⚠️ No Changeset found

Latest commit: 6a32cb5

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@renovate renovate bot force-pushed the renovate/all-minor-patch branch from 3be9019 to 5aad580 Compare October 15, 2024 10:51
@renovate renovate bot changed the title chore(deps): update dependency @reduxjs/toolkit to ^2.3.0 chore(deps): update all non-major dependencies Oct 15, 2024
@renovate renovate bot force-pushed the renovate/all-minor-patch branch from 5aad580 to 06fb6ac Compare October 16, 2024 16:43
@renovate renovate bot changed the title chore(deps): update all non-major dependencies fix(deps): update all non-major dependencies Oct 16, 2024
@renovate renovate bot force-pushed the renovate/all-minor-patch branch 11 times, most recently from 72501ea to 4d63525 Compare October 22, 2024 16:21
@renovate renovate bot changed the title fix(deps): update all non-major dependencies chore(deps): update all non-major dependencies Oct 22, 2024
@renovate renovate bot force-pushed the renovate/all-minor-patch branch 13 times, most recently from 92974c3 to 5e4ca18 Compare October 29, 2024 01:31
@renovate renovate bot force-pushed the renovate/all-minor-patch branch 10 times, most recently from 1e18804 to 823bc3f Compare December 3, 2024 10:14
@renovate renovate bot force-pushed the renovate/all-minor-patch branch 11 times, most recently from 9cf3cbf to 8748605 Compare December 6, 2024 16:24
@renovate renovate bot force-pushed the renovate/all-minor-patch branch from 8748605 to 6f2b4e5 Compare December 6, 2024 18:19
Copy link
Contributor Author

renovate bot commented Dec 6, 2024

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

@Methuselah96 Methuselah96 merged commit 90737b7 into main Dec 6, 2024
1 check passed
@Methuselah96 Methuselah96 deleted the renovate/all-minor-patch branch December 6, 2024 22:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant