fix(deps): update minor-and-patch (lts) #6382
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
2.10.2
->2.11.0
2.10.2
->2.11.0
5.1.0
->5.1.1
1.19.5
->1.19.6
2.8.18
->2.8.19
20.17.57
->20.19.0
4.4.2
->4.4.3
28.12.0
->28.13.0
4.9.1
->4.9.2
Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
apollographql/federation (@apollo/gateway)
v2.11.0
Compare Source
Minor Changes
Patch Changes
Corrects a set of denial-of-service (DOS) vulnerabilities that made it possible for an attacker to render gateway inoperable with certain simple query patterns due to uncontrolled resource consumption. All prior-released versions and configurations are vulnerable. (#3238)
See the associated GitHub Advisories GHSA-q2f9-x4p4-7xmh and GHSA-p2q6-pwh5-m6jr for more information.
Updated dependencies [
1462c91879d41884c0a7e60551d8dd0d67c832d3
,9614b26e5a17cbf1f6aaf08f6fcb1c95eb12592d
,9614b26e5a17cbf1f6aaf08f6fcb1c95eb12592d
]:apollographql/federation (@apollo/subgraph)
v2.11.0
Compare Source
Minor Changes
Patch Changes
1462c91879d41884c0a7e60551d8dd0d67c832d3
,9614b26e5a17cbf1f6aaf08f6fcb1c95eb12592d
]:dotansimha/graphql-code-generator (@graphql-codegen/plugin-helpers)
v5.1.1
Compare Source
Patch Changes
e324382
Thanks @ArminWiebigke! - Allow functions to be passed as valid values forUrlSchemaOptions.customFetch
. This was already possible, but the type definitions did not reflect that correctly.import-js/eslint-import-resolver-typescript (eslint-import-resolver-typescript)
v4.4.3
Compare Source
Patch Changes
43575e7
Thanks @JounQin! - chore: migratestable-hash
tostable-hash-x
jest-community/eslint-plugin-jest (eslint-plugin-jest)
v28.13.0
Compare Source
Features
prefer-ending-with-an-expect
rule (#1742) (fe1349b)yarnpkg/berry (yarn)
v4.9.2
Compare Source
Configuration
📅 Schedule: Branch creation - "after 10pm every weekday,before 5am every weekday,every weekend" in timezone Europe/London, Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.