Skip to content

refactor: Bump graphql from 16.13.2 to 16.14.2 - #10703

Merged
mtrezza merged 1 commit into
parse-community:alphafrom
mtrezza:refactor/graphql-16.14.2
Sep 26, 2026
Merged

mtrezza merged 1 commit into
parse-community:alphafrom
mtrezza:refactor/graphql-16.14.2

Conversation

@mtrezza

@mtrezza mtrezza commented Sep 26, 2026 •

Copy link
Copy Markdown
Member

Pull Request

Issue

Routine upgrade of the production dependency graphql from 16.13.2 to 16.14.2, the latest release in the v16 line. There is no open security alert for graphql.

The Dependabot PR for graphql 17 (#10691) is blocked and not addressed here: graphql 17 requires Node 22+ (the engines.node range of Parse Server includes Node 20), and @apollo/server declares a peer dependency on graphql@^16.11.0.

Approach

Pin graphql to the exact version 16.14.2 in dependencies and update the lock file. graphql is deduped across @apollo/server, @graphql-tools/*, graphql-relay and graphql-upload; all of their declared graphql ranges accept 16.14.2, so the lock file diff is limited to graphql. The engines.node range of graphql 16.14.2 (^12.22.0 || ^14.16.0 || ^16.0.0 || >=17.0.0) is compatible.

Changes

  • 16.14.0: Allow configuration of the ofType introspection depth via a new typeDepth option of getIntrospectionQuery (Allow configuration of the ofType introspection depth graphql/graphql-js#4317). The default stays at 9, so the generated introspection query is unchanged.
  • 16.14.0: Add experimental support for directives on directive definitions (Add experimental support for directives on directive definitions graphql/graphql-js#4521). The parser and schema support is opt-in via the experimentalDirectivesOnDirectiveDefinitions option. The introspection schema gains additive meta-fields for directive deprecation (__Directive.isDeprecated, __Directive.deprecationReason, an includeDeprecated argument on __Schema.directives that defaults to false), the DIRECTIVE_DEFINITION value of __DirectiveLocation, and DIRECTIVE_DEFINITION as an allowed location of the built-in @deprecated directive. Parse Server does not deprecate any directive, so the directives it returns in introspection are unchanged apart from the additional location on @deprecated.
  • 16.14.0: Fix valueFromAST to only resolve variables that are own properties of the variables object, so inherited Object.prototype properties are no longer treated as provided variables (Fix valueFromAST variable own-property checks graphql/graphql-js#4652).
  • 16.14.1, 16.14.2: Documentation and internal changes only.

Lock file entries:

  • node_modules/graphql: 16.13.2 → 16.14.2

Breaking Changes

None

Code Changes Required

None — the upgrade is a drop-in replacement.

Tasks

No tasks apply (dependency update of manifest and lock file only). Existing GraphQL specs (ParseGraphQLServer, ParseGraphQLSchema, ParseGraphQLController, defaultGraphQLTypes, GraphQLQueryComplexity) cover the used graphql APIs, including custom type definitions with schema directives, introspection control and variables.

Summary by CodeRabbit

  • Maintenance
    • Updated an underlying component to a newer version. No user-facing changes are included in this update.

@parse-github-assistant

Copy link
Copy Markdown

🚀 Thanks for opening this pull request! We appreciate your effort in improving the project. Please let us know once your pull request is ready for review.

Tip

  • Keep pull requests small. Large PRs will be rejected. Break complex features into smaller, incremental PRs.
  • Use Test Driven Development. Write failing tests before implementing functionality. Ensure tests pass.
  • Group code into logical blocks. Add a short comment before each block to explain its purpose.
  • We offer conceptual guidance. Coding is up to you. PRs must be merge-ready for human review.
  • Our review focuses on concept, not quality. PRs with code issues will be rejected. Use an AI agent.
  • Human review time is precious. Avoid review ping-pong. Inspect and test your AI-generated code.

Note

Please respond to review comments from AI agents just like you would to comments from a human reviewer. Let the reviewer resolve their own comments, unless they have reviewed and accepted your commit, or agreed with your explanation for why the feedback was incorrect.

Caution

Pull requests must be written using an AI agent with human supervision. Pull requests written entirely by a human will likely be rejected, because of lower code quality, higher review effort and the higher risk of introducing bugs. Please note that AI review comments on this pull request alone do not satisfy this requirement. Our CI and AI review are safeguards, not development tools. If many issues are flagged, rethink your development approach. Invest more effort in planning and design rather than using review cycles to fix low-quality code.

@coderabbitai

coderabbitai Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Essentials

Run ID: 0e45dede-5dc5-405e-b949-446f24e5698d

📥 Commits

Reviewing files that changed from the base of the PR and between 4f230bf and d58a2e1.

📒 Files selected for processing (2)
  • package-lock.json
  • package.json

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review.


📝 Walkthrough

Walkthrough

The GraphQL dependency is upgraded from 16.13.2 to 16.14.2. The lockfile records the new version, tarball URLs, and integrity hashes.

Changes

GraphQL dependency update

Layer / File(s) Summary
Update GraphQL version
package.json, package-lock.json
The manifest and lockfile now specify GraphQL 16.14.2. The lockfile also contains updated tarball URLs and integrity hashes.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~5 minutes

Merge Risk: ⚪ Minimal · up to d58a2

This change only updates a dependency version and its lockfile entries with no code modifications, so it carries minimal merge risk.

🚥 Pre-merge checks | ✅ 7
✅ Passed checks (7 passed)
Check name Status Explanation
Title check ✅ Passed The title uses the valid refactor: prefix, capitalizes the subject, and clearly describes the GraphQL dependency upgrade.
Description check ✅ Passed The description includes the required Pull Request, Issue, Approach, and Tasks sections. It clearly explains the dependency upgrade, compatibility, scope, and testing coverage.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Security Check ✅ Passed PASS. The PR changes only package.json and package-lock.json to update graphql from 16.13.2 to 16.14.2. GitHub advisory GHSA-9pv7-vfvm-6vr7 affects GraphQL versions before 16.8.1, so neither ver…
Engage In Review Feedback ✅ Passed PASS: The current review produced zero actionable findings, and no CodeRabbit review threads were returned. Therefore, there was no review feedback requiring engagement, implementation, or discussion.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR

Comment @coderabbitai help to get the list of available commands.

@codecov

codecov Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 93.84%. Comparing base (4f230bf) to head (d58a2e1).

Additional details and impacted files
@@           Coverage Diff           @@
##            alpha   #10703   +/-   ##
=======================================
  Coverage   93.84%   93.84%           
=======================================
  Files         192      192           
  Lines       16937    16937           
  Branches      257      257           
=======================================
+ Hits        15894    15895    +1     
+ Misses       1021     1020    -1     
  Partials       22       22           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@mtrezza
mtrezza merged commit 7a01a5b into parse-community:alpha Sep 26, 2026
25 checks passed
@mtrezza
mtrezza deleted the refactor/graphql-16.14.2 branch September 26, 2026 17:56
@parseplatformorg

Copy link
Copy Markdown
Contributor

🎉 This change has been released in version 9.10.2-alpha.5

@parseplatformorg parseplatformorg added the state:released-alpha Released as alpha version label Sep 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

state:released-alpha Released as alpha version

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants