refactor: Bump graphql from 16.13.2 to 16.14.2 - #10703
Conversation
|
🚀 Thanks for opening this pull request! We appreciate your effort in improving the project. Please let us know once your pull request is ready for review. Tip
Note Please respond to review comments from AI agents just like you would to comments from a human reviewer. Let the reviewer resolve their own comments, unless they have reviewed and accepted your commit, or agreed with your explanation for why the feedback was incorrect. Caution Pull requests must be written using an AI agent with human supervision. Pull requests written entirely by a human will likely be rejected, because of lower code quality, higher review effort and the higher risk of introducing bugs. Please note that AI review comments on this pull request alone do not satisfy this requirement. Our CI and AI review are safeguards, not development tools. If many issues are flagged, rethink your development approach. Invest more effort in planning and design rather than using review cycles to fix low-quality code. |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Essentials Run ID: 📒 Files selected for processing (2)
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review. 📝 WalkthroughWalkthroughThe GraphQL dependency is upgraded from 16.13.2 to 16.14.2. The lockfile records the new version, tarball URLs, and integrity hashes. ChangesGraphQL dependency update
Priority: ⬇️ Low Estimated code review effort: 1 (Trivial) | ~5 minutes Merge Risk: ⚪ Minimal · up to This change only updates a dependency version and its lockfile entries with no code modifications, so it carries minimal merge risk. 🚥 Pre-merge checks | ✅ 7✅ Passed checks (7 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## alpha #10703 +/- ##
=======================================
Coverage 93.84% 93.84%
=======================================
Files 192 192
Lines 16937 16937
Branches 257 257
=======================================
+ Hits 15894 15895 +1
+ Misses 1021 1020 -1
Partials 22 22 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
|
🎉 This change has been released in version 9.10.2-alpha.5 |
Pull Request
Issue
Routine upgrade of the production dependency
graphqlfrom 16.13.2 to 16.14.2, the latest release in the v16 line. There is no open security alert forgraphql.The Dependabot PR for graphql 17 (#10691) is blocked and not addressed here: graphql 17 requires Node 22+ (the
engines.noderange of Parse Server includes Node 20), and@apollo/serverdeclares a peer dependency ongraphql@^16.11.0.Approach
Pin
graphqlto the exact version 16.14.2 independenciesand update the lock file.graphqlis deduped across@apollo/server,@graphql-tools/*,graphql-relayandgraphql-upload; all of their declaredgraphqlranges accept 16.14.2, so the lock file diff is limited tographql. Theengines.noderange of graphql 16.14.2 (^12.22.0 || ^14.16.0 || ^16.0.0 || >=17.0.0) is compatible.Changes
ofTypeintrospection depth via a newtypeDepthoption ofgetIntrospectionQuery(Allow configuration of theofTypeintrospection depth graphql/graphql-js#4317). The default stays at 9, so the generated introspection query is unchanged.experimentalDirectivesOnDirectiveDefinitionsoption. The introspection schema gains additive meta-fields for directive deprecation (__Directive.isDeprecated,__Directive.deprecationReason, anincludeDeprecatedargument on__Schema.directivesthat defaults tofalse), theDIRECTIVE_DEFINITIONvalue of__DirectiveLocation, andDIRECTIVE_DEFINITIONas an allowed location of the built-in@deprecateddirective. Parse Server does not deprecate any directive, so the directives it returns in introspection are unchanged apart from the additional location on@deprecated.valueFromASTto only resolve variables that are own properties of the variables object, so inheritedObject.prototypeproperties are no longer treated as provided variables (Fix valueFromAST variable own-property checks graphql/graphql-js#4652).Lock file entries:
node_modules/graphql: 16.13.2 → 16.14.2Breaking Changes
None
Code Changes Required
None — the upgrade is a drop-in replacement.
Tasks
No tasks apply (dependency update of manifest and lock file only). Existing GraphQL specs (
ParseGraphQLServer,ParseGraphQLSchema,ParseGraphQLController,defaultGraphQLTypes,GraphQLQueryComplexity) cover the usedgraphqlAPIs, including custom type definitions with schema directives, introspection control and variables.Summary by CodeRabbit