Skip to content

fix(deps): update apollo graphql packages#8266

Open
renovate[bot] wants to merge 1 commit intolatestfrom
renovate/apollo-graphql-packages
Open

fix(deps): update apollo graphql packages#8266
renovate[bot] wants to merge 1 commit intolatestfrom
renovate/apollo-graphql-packages

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Aug 6, 2025

This PR contains the following updates:

Package Change Age Confidence
@apollo/client (source) 3.13.83.14.0 age confidence
@apollo/server (source) 4.12.24.13.0 age confidence

Release Notes

apollographql/apollo-client (@​apollo/client)

v3.14.0

Compare Source

Minor Changes
Patch Changes

v3.13.9

Compare Source

Patch Changes
  • #​12804 32c9aa9 Thanks @​phryneas! - Fix a possible race condition on queries that were reobserved before they were subscribed to the first time.
apollographql/apollo-server (@​apollo/server)

v4.13.0

Compare Source

Minor Changes
  • #​8180 e9d49d1 Thanks @​github-actions! - ⚠️ SECURITY @apollo/server/standalone:

    The default configuration of startStandaloneServer was vulnerable to denial of service (DoS) attacks through specially crafted request bodies with exotic character set encodings.

    In accordance with RFC 7159, we now only accept request bodies encoded in UTF-8, UTF-16 (LE or BE), or UTF-32 (LE or BE).
    Any other character set will be rejected with a 415 Unsupported Media Type error.
    Additionally, upstream libraries used by this version of Apollo Server may not support all of these encodings, so some requests may still fail even if they pass this check.

    If you were not using startStandaloneServer, you were not affected by this vulnerability.

    Generally, please note that we provide startStandaloneServer as a convenience tool for quickly getting started with Apollo Server.
    For production deployments, we recommend using Apollo Server with a more fully-featured web server framework such as Express, Koa, or Fastify, where you have more control over security-related configuration options.

    Also please note that Apollo Server 4.x is considered EOL as of January 26, 2026, and Apollo no longer commits to providing support or updates for it. Please prioritize migrating to Apollo Server 5.x for continued support and updates.


Configuration

📅 Schedule: Branch creation - "before 8am every weekday,every weekend" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot force-pushed the renovate/apollo-graphql-packages branch from 8002de4 to 93eab9a Compare August 11, 2025 20:16
@coderabbitai
Copy link

coderabbitai bot commented Aug 11, 2025

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.


Comment @coderabbitai help to get the list of available commands and usage tips.

@renovate renovate bot changed the title fix(deps): update dependency @apollo/client to v3.13.9 fix(deps): update dependency @apollo/client to v3.14.0 Aug 22, 2025
@renovate renovate bot force-pushed the renovate/apollo-graphql-packages branch from 93eab9a to 06d83d6 Compare August 22, 2025 12:46
@renovate renovate bot force-pushed the renovate/apollo-graphql-packages branch from 06d83d6 to d0cd20d Compare December 3, 2025 15:02
@renovate renovate bot force-pushed the renovate/apollo-graphql-packages branch from d0cd20d to 39c276b Compare December 31, 2025 15:17
@renovate renovate bot force-pushed the renovate/apollo-graphql-packages branch from 39c276b to 0c16d90 Compare January 19, 2026 15:59
@renovate renovate bot force-pushed the renovate/apollo-graphql-packages branch from 0c16d90 to bc85e04 Compare February 4, 2026 12:40
@renovate renovate bot changed the title fix(deps): update dependency @apollo/client to v3.14.0 fix(deps): update apollo graphql packages Feb 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants