apollographql / apollographql/graphql-testing-library

Dependency Dashboard

Open
#6 0 comments 0 reactions 0 assignees View on GitHub
dependencies
Dominant language
TypeScript
Stars
61
Forks
2
PR merge metrics
No merged PRs in 30d

Description

This issue lists Renovate updates and detected dependencies. Read the [Dependency Dashboard](https://docs.renovatebot.com/key-concepts/dashboard/) docs to learn more.

## Config Migration Needed

See Config Migration PR: #132.

## Repository Problems

Renovate tried to run on this repository, but found these problems.

- ⚠️ WARN: Using npm packages for Renovate presets is now deprecated. Please migrate to repository-based presets instead.

## Deprecations / Replacements
> [!WARNING]
These dependencies are either deprecated or have replacements available:

| Datasource | Package | Replacement PR? |
|------------|------|--------------|
| npm | [tailwind](https://redirect.github.com/thenativeweb/tailwind) | ![Unavailable](https://img.shields.io/badge/unavailable-orange?style=flat-square) |

## Rate-Limited

The following updates are currently rate-limited. To force their creation now, click on a checkbox below.

- [ ] chore(deps): update andstor/file-existence-action action to v3.1.0
- [ ] chore(deps): update schneegans/dynamic-badges-action action to v1.8.0
- [ ] fix(deps): update dependency sharp to v0.34.5
- [ ] chore(deps): update actions/cache action to v5
- [ ] chore(deps): update actions/checkout action to v6
- [ ] chore(deps): update actions/setup-node action to v6
- [ ] chore(deps): update dependency node to v24
- [ ] chore(deps): update dependency pnpm to v10
- [ ] chore(deps): update peter-evans/create-or-update-comment action to v5
- [ ] chore(deps): update pnpm/action-setup action to v5
- [ ] chore(deps): update slackapi/slack-github-action action to v3
- [ ] fix(deps): update dependency body-parser to v2
- [ ] fix(deps): update dependency express to v5
- [ ] fix(deps): update dependency typescript to v6
- [ ] πŸ” **Create all rate-limited PRs at once** πŸ”

## PR Edited (Blocked)

The following updates have been manually edited so Renovate will no longer make changes. To discard all commits and start over, click on a checkbox below.

- [ ] fix(deps): update all dependencies - patch updates (`@astrojs/check`, `@graphql-codegen/cli`, `@graphql-codegen/typescript`, `@graphql-tools/jest-transform`, `@testing-library/dom`, `@tsconfig/recommended`, `@types/cors`, `@types/jest`, `@types/node`, `@types/react`, `@types/react-dom`, `bitovi/github-actions-storybook-to-github-pages`, `graphql-ws`, `msw-storybook-addon`, `slackapi/slack-github-action`, `tailwindcss`, `wait-on`)
- [ ] chore(deps): update all devdependencies (`@apollo/client`, `@changesets/changelog-github`, `@changesets/cli`, `@graphql-codegen/typescript-resolvers`, `@playwright/test`, `@storybook/addon-docs`, `@storybook/addon-essentials`, `@storybook/addon-interactions`, `@storybook/addon-links`, `@storybook/blocks`, `@storybook/react`, `@storybook/react-vite`, `@storybook/test`, `@storybook/test-runner`, `@testing-library/jest-dom`, `@testing-library/react`, `@types/node`, `@types/ws`, `@typescript-eslint/eslint-plugin`, `@typescript-eslint/parser`, `eslint-plugin-storybook`, `graphql`, `msw`, `postcss`, `prettier`, `ts-jest`, `typescript`, `vite-plugin-svgr`)
- [ ] fix(deps): update dependency @astrojs/starlight to v0.38.3
- [ ] fix(deps): update dependency typescript to v5.9.3
- [ ] chore(deps): update all devdependencies (major) (`@apollo/client`, `@graphql-codegen/cli`, `@graphql-codegen/typescript`, `@graphql-codegen/typescript-resolvers`, `@storybook/addon-docs`, `@storybook/addon-links`, `@storybook/react`, `@storybook/react-vite`, `@types/jest`, `@types/node`, `@types/react`, `@types/react-dom`, `@types/react-relay`, `@types/relay-runtime`, `babel-plugin-relay`, `concurrently`, `eslint-plugin-storybook`, `graphql-ws`, `jest`, `jest-environment-jsdom`, `jsdom`, `react`, `react-relay`, `relay-compiler`, `relay-runtime`, `tailwindcss`, `typescript`, `vite-plugin-graphql-loader`, `vite-plugin-svgr`, `wait-on`)
- [ ] fix(deps): update dependency graphql-ws to v6
- [ ] chore(deps): lock file maintenance

## Open

The following updates have all been created. To force a retry/rebase of any, click on a checkbox below.

- [ ] [chore(deps): update dependency tsup to v8.3.5 [security]](../pull/159)
- [ ] [chore(deps): update dependency vitest to v2.1.9 [security]](../pull/171)
- [ ] [chore(deps): update dependency playwright to v1.55.1 [security]](../pull/166)
- [ ] [chore(deps): update dependency storybook to v8.6.17 [security]](../pull/172)
- [ ] [chore(deps): update dependency undici to v6.24.0 [security]](../pull/173)
- [ ] [chore(deps): update dependency vite to v6 [security]](../pull/170)
- [ ] [fix(deps): update dependency @apollo/server to v5 [security]](../pull/169)
- [ ] [fix(deps): update dependency astro to v6 [security]](../pull/146)
- [ ] [fix(deps): update dependency graphql-subscriptions to v3](../pull/150)
- [ ] [fix(deps): update graphql-tools monorepo (major)](../pull/140) (`@graphql-tools/schema`, `@graphql-tools/utils`)
- [ ] **Click on this checkbox to rebase all open PRs at once**

## Vulnerabilities

> [!IMPORTANT]
> `121`/`121` CVEs have Renovate fixes.

github-actions

.github/workflows/deploy-storybook.yml

pnpm

- [GHSA-2phv-j68v-wwqx](https://osv.dev/vulnerability/GHSA-2phv-j68v-wwqx) (fixed in >= 10.27.0)
- [GHSA-6pfh-p556-v868](https://osv.dev/vulnerability/GHSA-6pfh-p556-v868) (fixed in >= 10.28.1)
- [GHSA-6x96-7vc8-cm3p](https://osv.dev/vulnerability/GHSA-6x96-7vc8-cm3p) (fixed in >= 10.28.1)
- [GHSA-7vhp-vf5g-r2fw](https://osv.dev/vulnerability/GHSA-7vhp-vf5g-r2fw) (fixed in >= 10.26.0)
- [GHSA-8cc4-rfj6-fhg4](https://osv.dev/vulnerability/GHSA-8cc4-rfj6-fhg4) (fixed in >= 10.0.0)
- [GHSA-m733-5w8f-5ggw](https://osv.dev/vulnerability/GHSA-m733-5w8f-5ggw) (fixed in >= 10.28.2)
- [GHSA-v253-rj99-jwpq](https://osv.dev/vulnerability/GHSA-v253-rj99-jwpq) (fixed in >= 10.28.2)
- [GHSA-xpqm-wm3m-f34h](https://osv.dev/vulnerability/GHSA-xpqm-wm3m-f34h) (fixed in >= 10.28.1)

.github/workflows/release.yml

pnpm

- [GHSA-2phv-j68v-wwqx](https://osv.dev/vulnerability/GHSA-2phv-j68v-wwqx) (fixed in >= 10.27.0)
- [GHSA-6pfh-p556-v868](https://osv.dev/vulnerability/GHSA-6pfh-p556-v868) (fixed in >= 10.28.1)
- [GHSA-6x96-7vc8-cm3p](https://osv.dev/vulnerability/GHSA-6x96-7vc8-cm3p) (fixed in >= 10.28.1)
- [GHSA-7vhp-vf5g-r2fw](https://osv.dev/vulnerability/GHSA-7vhp-vf5g-r2fw) (fixed in >= 10.26.0)
- [GHSA-8cc4-rfj6-fhg4](https://osv.dev/vulnerability/GHSA-8cc4-rfj6-fhg4) (fixed in >= 10.0.0)
- [GHSA-m733-5w8f-5ggw](https://osv.dev/vulnerability/GHSA-m733-5w8f-5ggw) (fixed in >= 10.28.2)
- [GHSA-v253-rj99-jwpq](https://osv.dev/vulnerability/GHSA-v253-rj99-jwpq) (fixed in >= 10.28.2)
- [GHSA-xpqm-wm3m-f34h](https://osv.dev/vulnerability/GHSA-xpqm-wm3m-f34h) (fixed in >= 10.28.1)

.github/workflows/snapshot-release.yml

pnpm

- [GHSA-2phv-j68v-wwqx](https://osv.dev/vulnerability/GHSA-2phv-j68v-wwqx) (fixed in >= 10.27.0)
- [GHSA-6pfh-p556-v868](https://osv.dev/vulnerability/GHSA-6pfh-p556-v868) (fixed in >= 10.28.1)
- [GHSA-6x96-7vc8-cm3p](https://osv.dev/vulnerability/GHSA-6x96-7vc8-cm3p) (fixed in >= 10.28.1)
- [GHSA-7vhp-vf5g-r2fw](https://osv.dev/vulnerability/GHSA-7vhp-vf5g-r2fw) (fixed in >= 10.26.0)
- [GHSA-8cc4-rfj6-fhg4](https://osv.dev/vulnerability/GHSA-8cc4-rfj6-fhg4) (fixed in >= 10.0.0)
- [GHSA-m733-5w8f-5ggw](https://osv.dev/vulnerability/GHSA-m733-5w8f-5ggw) (fixed in >= 10.28.2)
- [GHSA-v253-rj99-jwpq](https://osv.dev/vulnerability/GHSA-v253-rj99-jwpq) (fixed in >= 10.28.2)
- [GHSA-xpqm-wm3m-f34h](https://osv.dev/vulnerability/GHSA-xpqm-wm3m-f34h) (fixed in >= 10.28.1)

.github/workflows/test.yml

pnpm

- [GHSA-2phv-j68v-wwqx](https://osv.dev/vulnerability/GHSA-2phv-j68v-wwqx) (fixed in >= 10.27.0)
- [GHSA-6pfh-p556-v868](https://osv.dev/vulnerability/GHSA-6pfh-p556-v868) (fixed in >= 10.28.1)
- [GHSA-6x96-7vc8-cm3p](https://osv.dev/vulnerability/GHSA-6x96-7vc8-cm3p) (fixed in >= 10.28.1)
- [GHSA-7vhp-vf5g-r2fw](https://osv.dev/vulnerability/GHSA-7vhp-vf5g-r2fw) (fixed in >= 10.26.0)
- [GHSA-8cc4-rfj6-fhg4](https://osv.dev/vulnerability/GHSA-8cc4-rfj6-fhg4) (fixed in >= 10.0.0)
- [GHSA-m733-5w8f-5ggw](https://osv.dev/vulnerability/GHSA-m733-5w8f-5ggw) (fixed in >= 10.28.2)
- [GHSA-v253-rj99-jwpq](https://osv.dev/vulnerability/GHSA-v253-rj99-jwpq) (fixed in >= 10.28.2)
- [GHSA-xpqm-wm3m-f34h](https://osv.dev/vulnerability/GHSA-xpqm-wm3m-f34h) (fixed in >= 10.28.1)
- [GHSA-2phv-j68v-wwqx](https://osv.dev/vulnerability/GHSA-2phv-j68v-wwqx) (fixed in >= 10.27.0)
- [GHSA-6pfh-p556-v868](https://osv.dev/vulnerability/GHSA-6pfh-p556-v868) (fixed in >= 10.28.1)
- [GHSA-6x96-7vc8-cm3p](https://osv.dev/vulnerability/GHSA-6x96-7vc8-cm3p) (fixed in >= 10.28.1)
- [GHSA-7vhp-vf5g-r2fw](https://osv.dev/vulnerability/GHSA-7vhp-vf5g-r2fw) (fixed in >= 10.26.0)
- [GHSA-8cc4-rfj6-fhg4](https://osv.dev/vulnerability/GHSA-8cc4-rfj6-fhg4) (fixed in >= 10.0.0)
- [GHSA-m733-5w8f-5ggw](https://osv.dev/vulnerability/GHSA-m733-5w8f-5ggw) (fixed in >= 10.28.2)
- [GHSA-v253-rj99-jwpq](https://osv.dev/vulnerability/GHSA-v253-rj99-jwpq) (fixed in >= 10.28.2)
- [GHSA-xpqm-wm3m-f34h](https://osv.dev/vulnerability/GHSA-xpqm-wm3m-f34h) (fixed in >= 10.28.1)
- [GHSA-2phv-j68v-wwqx](https://osv.dev/vulnerability/GHSA-2phv-j68v-wwqx) (fixed in >= 10.27.0)
- [GHSA-6pfh-p556-v868](https://osv.dev/vulnerability/GHSA-6pfh-p556-v868) (fixed in >= 10.28.1)
- [GHSA-6x96-7vc8-cm3p](https://osv.dev/vulnerability/GHSA-6x96-7vc8-cm3p) (fixed in >= 10.28.1)
- [GHSA-7vhp-vf5g-r2fw](https://osv.dev/vulnerability/GHSA-7vhp-vf5g-r2fw) (fixed in >= 10.26.0)
- [GHSA-8cc4-rfj6-fhg4](https://osv.dev/vulnerability/GHSA-8cc4-rfj6-fhg4) (fixed in >= 10.0.0)
- [GHSA-m733-5w8f-5ggw](https://osv.dev/vulnerability/GHSA-m733-5w8f-5ggw) (fixed in >= 10.28.2)
- [GHSA-v253-rj99-jwpq](https://osv.dev/vulnerability/GHSA-v253-rj99-jwpq) (fixed in >= 10.28.2)
- [GHSA-xpqm-wm3m-f34h](https://osv.dev/vulnerability/GHSA-xpqm-wm3m-f34h) (fixed in >= 10.28.1)
- [GHSA-2phv-j68v-wwqx](https://osv.dev/vulnerability/GHSA-2phv-j68v-wwqx) (fixed in >= 10.27.0)
- [GHSA-6pfh-p556-v868](https://osv.dev/vulnerability/GHSA-6pfh-p556-v868) (fixed in >= 10.28.1)
- [GHSA-6x96-7vc8-cm3p](https://osv.dev/vulnerability/GHSA-6x96-7vc8-cm3p) (fixed in >= 10.28.1)
- [GHSA-7vhp-vf5g-r2fw](https://osv.dev/vulnerability/GHSA-7vhp-vf5g-r2fw) (fixed in >= 10.26.0)
- [GHSA-8cc4-rfj6-fhg4](https://osv.dev/vulnerability/GHSA-8cc4-rfj6-fhg4) (fixed in >= 10.0.0)
- [GHSA-m733-5w8f-5ggw](https://osv.dev/vulnerability/GHSA-m733-5w8f-5ggw) (fixed in >= 10.28.2)
- [GHSA-v253-rj99-jwpq](https://osv.dev/vulnerability/GHSA-v253-rj99-jwpq) (fixed in >= 10.28.2)
- [GHSA-xpqm-wm3m-f34h](https://osv.dev/vulnerability/GHSA-xpqm-wm3m-f34h) (fixed in >= 10.28.1)
- [GHSA-2phv-j68v-wwqx](https://osv.dev/vulnerability/GHSA-2phv-j68v-wwqx) (fixed in >= 10.27.0)
- [GHSA-6pfh-p556-v868](https://osv.dev/vulnerability/GHSA-6pfh-p556-v868) (fixed in >= 10.28.1)
- [GHSA-6x96-7vc8-cm3p](https://osv.dev/vulnerability/GHSA-6x96-7vc8-cm3p) (fixed in >= 10.28.1)
- [GHSA-7vhp-vf5g-r2fw](https://osv.dev/vulnerability/GHSA-7vhp-vf5g-r2fw) (fixed in >= 10.26.0)
- [GHSA-8cc4-rfj6-fhg4](https://osv.dev/vulnerability/GHSA-8cc4-rfj6-fhg4) (fixed in >= 10.0.0)
- [GHSA-m733-5w8f-5ggw](https://osv.dev/vulnerability/GHSA-m733-5w8f-5ggw) (fixed in >= 10.28.2)
- [GHSA-v253-rj99-jwpq](https://osv.dev/vulnerability/GHSA-v253-rj99-jwpq) (fixed in >= 10.28.2)
- [GHSA-xpqm-wm3m-f34h](https://osv.dev/vulnerability/GHSA-xpqm-wm3m-f34h) (fixed in >= 10.28.1)
- [GHSA-2phv-j68v-wwqx](https://osv.dev/vulnerability/GHSA-2phv-j68v-wwqx) (fixed in >= 10.27.0)
- [GHSA-6pfh-p556-v868](https://osv.dev/vulnerability/GHSA-6pfh-p556-v868) (fixed in >= 10.28.1)
- [GHSA-6x96-7vc8-cm3p](https://osv.dev/vulnerability/GHSA-6x96-7vc8-cm3p) (fixed in >= 10.28.1)
- [GHSA-7vhp-vf5g-r2fw](https://osv.dev/vulnerability/GHSA-7vhp-vf5g-r2fw) (fixed in >= 10.26.0)
- [GHSA-8cc4-rfj6-fhg4](https://osv.dev/vulnerability/GHSA-8cc4-rfj6-fhg4) (fixed in >= 10.0.0)
- [GHSA-m733-5w8f-5ggw](https://osv.dev/vulnerability/GHSA-m733-5w8f-5ggw) (fixed in >= 10.28.2)
- [GHSA-v253-rj99-jwpq](https://osv.dev/vulnerability/GHSA-v253-rj99-jwpq) (fixed in >= 10.28.2)
- [GHSA-xpqm-wm3m-f34h](https://osv.dev/vulnerability/GHSA-xpqm-wm3m-f34h) (fixed in >= 10.28.1)
- [GHSA-2phv-j68v-wwqx](https://osv.dev/vulnerability/GHSA-2phv-j68v-wwqx) (fixed in >= 10.27.0)
- [GHSA-6pfh-p556-v868](https://osv.dev/vulnerability/GHSA-6pfh-p556-v868) (fixed in >= 10.28.1)
- [GHSA-6x96-7vc8-cm3p](https://osv.dev/vulnerability/GHSA-6x96-7vc8-cm3p) (fixed in >= 10.28.1)
- [GHSA-7vhp-vf5g-r2fw](https://osv.dev/vulnerability/GHSA-7vhp-vf5g-r2fw) (fixed in >= 10.26.0)
- [GHSA-8cc4-rfj6-fhg4](https://osv.dev/vulnerability/GHSA-8cc4-rfj6-fhg4) (fixed in >= 10.0.0)
- [GHSA-m733-5w8f-5ggw](https://osv.dev/vulnerability/GHSA-m733-5w8f-5ggw) (fixed in >= 10.28.2)
- [GHSA-v253-rj99-jwpq](https://osv.dev/vulnerability/GHSA-v253-rj99-jwpq) (fixed in >= 10.28.2)
- [GHSA-xpqm-wm3m-f34h](https://osv.dev/vulnerability/GHSA-xpqm-wm3m-f34h) (fixed in >= 10.28.1)

npm

demo/server/package.json

@apollo/server

- [GHSA-9q82-xgwf-vj6h](https://osv.dev/vulnerability/GHSA-9q82-xgwf-vj6h) (fixed in >= 5.5.0)
- [GHSA-mp6q-xf9x-fwf7](https://osv.dev/vulnerability/GHSA-mp6q-xf9x-fwf7) (fixed in >= 4.13.0)

docs/package.json

astro

- [GHSA-49w6-73cw-chjr](https://osv.dev/vulnerability/GHSA-49w6-73cw-chjr) (fixed in >= 4.16.18)
- [GHSA-5ff5-9fcw-vg88](https://osv.dev/vulnerability/GHSA-5ff5-9fcw-vg88) (fixed in >= 5.14.3)
- [GHSA-c4pw-33h3-35xw](https://osv.dev/vulnerability/GHSA-c4pw-33h3-35xw) (fixed in >= 4.16.17)
- [GHSA-fvmw-cj7j-j39q](https://osv.dev/vulnerability/GHSA-fvmw-cj7j-j39q) (fixed in >= 5.15.9)
- [GHSA-g735-7g2w-hh3f](https://osv.dev/vulnerability/GHSA-g735-7g2w-hh3f) (fixed in >= 5.18.1)
- [GHSA-ggxq-hp9w-j794](https://osv.dev/vulnerability/GHSA-ggxq-hp9w-j794) (fixed in >= 5.15.8)
- [GHSA-hr2q-hp5q-x767](https://osv.dev/vulnerability/GHSA-hr2q-hp5q-x767) (fixed in >= 5.15.5)
- [GHSA-j687-52p2-xcff](https://osv.dev/vulnerability/GHSA-j687-52p2-xcff) (fixed in >= 6.1.6)
- [GHSA-m85w-3h95-hcf9](https://osv.dev/vulnerability/GHSA-m85w-3h95-hcf9) (fixed in >= 4.16.1)
- [GHSA-whqg-ppgf-wp8c](https://osv.dev/vulnerability/GHSA-whqg-ppgf-wp8c) (fixed in >= 5.15.8)
- [GHSA-wrwg-2hg8-v723](https://osv.dev/vulnerability/GHSA-wrwg-2hg8-v723) (fixed in >= 5.15.8)
- [GHSA-x3h8-62x9-952g](https://osv.dev/vulnerability/GHSA-x3h8-62x9-952g) (fixed in >= 5.14.3)
- [GHSA-xf8x-j4p2-f749](https://osv.dev/vulnerability/GHSA-xf8x-j4p2-f749) (fixed in >= 4.16.19)

package.json

playwright

- [GHSA-7mvr-c777-76hp](https://osv.dev/vulnerability/GHSA-7mvr-c777-76hp) (fixed in >= 1.55.1)

storybook

- [GHSA-8452-54wp-rmv6](https://osv.dev/vulnerability/GHSA-8452-54wp-rmv6) (fixed in >= 8.6.15)
- [GHSA-mjf5-7g4m-gx5w](https://osv.dev/vulnerability/GHSA-mjf5-7g4m-gx5w) (fixed in >= 8.6.17)

tsup

- [GHSA-3mv9-4h5g-vhg3](https://osv.dev/vulnerability/GHSA-3mv9-4h5g-vhg3) (fixed in > 8.3.4)

undici

- [GHSA-2mjp-6q6p-2qxm](https://osv.dev/vulnerability/GHSA-2mjp-6q6p-2qxm) (fixed in >= 6.24.0)
- [GHSA-4992-7rv2-5pvq](https://osv.dev/vulnerability/GHSA-4992-7rv2-5pvq) (fixed in >= 6.24.0)
- [GHSA-c76h-2ccp-4975](https://osv.dev/vulnerability/GHSA-c76h-2ccp-4975) (fixed in >= 6.21.1)
- [GHSA-cxrh-j4jr-qwg3](https://osv.dev/vulnerability/GHSA-cxrh-j4jr-qwg3) (fixed in >= 6.21.2)
- [GHSA-f269-vfmq-vjvj](https://osv.dev/vulnerability/GHSA-f269-vfmq-vjvj) (fixed in >= 6.24.0)
- [GHSA-g9mf-h72j-4rw9](https://osv.dev/vulnerability/GHSA-g9mf-h72j-4rw9) (fixed in >= 6.23.0)
- [GHSA-v9p9-hfj2-hcw8](https://osv.dev/vulnerability/GHSA-v9p9-hfj2-hcw8) (fixed in >= 6.24.0)
- [GHSA-vrm6-8vpv-qv8q](https://osv.dev/vulnerability/GHSA-vrm6-8vpv-qv8q) (fixed in >= 6.24.0)

vite

- [GHSA-356w-63v5-8wf4](https://osv.dev/vulnerability/GHSA-356w-63v5-8wf4) (fixed in >= 5.4.18)
- [GHSA-4r4m-qw57-chr8](https://osv.dev/vulnerability/GHSA-4r4m-qw57-chr8) (fixed in >= 5.4.16)
- [GHSA-4w7w-66w2-5vf9](https://osv.dev/vulnerability/GHSA-4w7w-66w2-5vf9) (fixed in >= 6.4.2)
- [GHSA-859w-5945-r5v3](https://osv.dev/vulnerability/GHSA-859w-5945-r5v3) (fixed in >= 5.4.19)
- [GHSA-93m4-6634-74q7](https://osv.dev/vulnerability/GHSA-93m4-6634-74q7) (fixed in >= 5.4.21)
- [GHSA-93m4-6634-74q7](https://osv.dev/vulnerability/GHSA-93m4-6634-74q7) (fixed in >= 5.4.21)
- [GHSA-93m4-6634-74q7](https://osv.dev/vulnerability/GHSA-93m4-6634-74q7) (fixed in >= 5.4.21)
- [GHSA-93m4-6634-74q7](https://osv.dev/vulnerability/GHSA-93m4-6634-74q7) (fixed in >= 5.4.21)
- [GHSA-g4jq-h2w9-997c](https://osv.dev/vulnerability/GHSA-g4jq-h2w9-997c) (fixed in >= 5.4.20)
- [GHSA-jqfw-vq24-v9c3](https://osv.dev/vulnerability/GHSA-jqfw-vq24-v9c3) (fixed in >= 5.4.20)
- [GHSA-vg6x-rcgg-rjx6](https://osv.dev/vulnerability/GHSA-vg6x-rcgg-rjx6) (fixed in >= 5.4.12)
- [GHSA-x574-m823-4x7w](https://osv.dev/vulnerability/GHSA-x574-m823-4x7w) (fixed in >= 5.4.15)
- [GHSA-xcj6-pq6g-qj4x](https://osv.dev/vulnerability/GHSA-xcj6-pq6g-qj4x) (fixed in >= 5.4.17)

vitest

- [GHSA-9crc-q9x8-hgqq](https://osv.dev/vulnerability/GHSA-9crc-q9x8-hgqq) (fixed in >= 2.1.9)

## Detected Dependencies

github-actions (4)

.github/workflows/deploy-storybook.yml (6)

- `actions/checkout v4` β†’ [Updates: `v6`]
- `pnpm/action-setup v4` β†’ [Updates: `v5`]
- `actions/setup-node v4` β†’ [Updates: `v6`]
- `bitovi/github-actions-storybook-to-github-pages v1.0.3` β†’ [Updates: `v1.0.4`]
- `pnpm 9` β†’ [Updates: `10`]
- `node 20` β†’ [Updates: `24`]

.github/workflows/release.yml (8)

- `actions/checkout v4` β†’ [Updates: `v6`]
- `andstor/file-existence-action v3.0.0` β†’ [Updates: `v3.1.0`]
- `actions/setup-node v4` β†’ [Updates: `v6`]
- `pnpm/action-setup v4` β†’ [Updates: `v5`]
- `changesets/action v1`
- `slackapi/slack-github-action v1.27.0` β†’ [Updates: `v1.27.1`, `v3.0.1`]
- `node 20.x` β†’ [Updates: `24.x`]
- `pnpm 9` β†’ [Updates: `10`]

.github/workflows/snapshot-release.yml (10)

- `alessbell/pull-request-comment-branch v2.1.0`
- `peter-evans/create-or-update-comment v4.0.0` β†’ [Updates: `v5.0.0`]
- `actions/checkout v4` β†’ [Updates: `v6`]
- `actions/setup-node v4` β†’ [Updates: `v6`]
- `pnpm/action-setup v4` β†’ [Updates: `v5`]
- `andstor/file-existence-action v3.0.0` β†’ [Updates: `v3.1.0`]
- `peter-evans/create-or-update-comment v4.0.0` β†’ [Updates: `v5.0.0`]
- `peter-evans/create-or-update-comment v4.0.0` β†’ [Updates: `v5.0.0`]
- `node 20.x` β†’ [Updates: `24.x`]
- `pnpm 9` β†’ [Updates: `10`]

.github/workflows/test.yml (39)

- `actions/checkout v4` β†’ [Updates: `v6`]
- `pnpm/action-setup v4` β†’ [Updates: `v5`]
- `actions/setup-node v4` β†’ [Updates: `v6`]
- `actions/cache v4` β†’ [Updates: `v5`]
- `actions/checkout v4` β†’ [Updates: `v6`]
- `pnpm/action-setup v4` β†’ [Updates: `v5`]
- `actions/setup-node v4` β†’ [Updates: `v6`]
- `actions/checkout v4` β†’ [Updates: `v6`]
- `pnpm/action-setup v4` β†’ [Updates: `v5`]
- `actions/setup-node v4` β†’ [Updates: `v6`]
- `MishaKav/jest-coverage-comment main`
- `schneegans/dynamic-badges-action v1.7.0` β†’ [Updates: `v1.8.0`]
- `actions/checkout v4` β†’ [Updates: `v6`]
- `pnpm/action-setup v4` β†’ [Updates: `v5`]
- `actions/setup-node v4` β†’ [Updates: `v6`]
- `actions/cache v4` β†’ [Updates: `v5`]
- `actions/checkout v4` β†’ [Updates: `v6`]
- `pnpm/action-setup v4` β†’ [Updates: `v5`]
- `actions/setup-node v4` β†’ [Updates: `v6`]
- `actions/checkout v4` β†’ [Updates: `v6`]
- `pnpm/action-setup v4` β†’ [Updates: `v5`]
- `actions/setup-node v4` β†’ [Updates: `v6`]
- `actions/checkout v4` β†’ [Updates: `v6`]
- `pnpm/action-setup v4` β†’ [Updates: `v5`]
- `actions/setup-node v4` β†’ [Updates: `v6`]
- `pnpm 9` β†’ [Updates: `10`]
- `node 20` β†’ [Updates: `24`]
- `pnpm 9` β†’ [Updates: `10`]
- `node 20` β†’ [Updates: `24`]
- `pnpm 9` β†’ [Updates: `10`]
- `node 20` β†’ [Updates: `24`]
- `pnpm 9` β†’ [Updates: `10`]
- `node 20` β†’ [Updates: `24`]
- `pnpm 9` β†’ [Updates: `10`]
- `node 20` β†’ [Updates: `24`]
- `pnpm 9` β†’ [Updates: `10`]
- `node 20` β†’ [Updates: `24`]
- `pnpm 9` β†’ [Updates: `10`]
- `node 20` β†’ [Updates: `24`]

npm (3)

demo/server/package.json (13)

- `@apollo/server ^4.0.0` β†’ [Updates: `^5.0.0`]
- `@graphql-tools/schema ^9.0.13` β†’ [Updates: `^10.0.0`]
- `body-parser ^1.20.2` β†’ [Updates: `^2.0.0`]
- `cors ^2.8.5`
- `express ^4.17.1` β†’ [Updates: `^5.0.0`]
- `graphql ^16.6.0`
- `graphql-subscriptions ^1.2.1` β†’ [Updates: `^3.0.0`]
- `graphql-ws ^5.5.5` β†’ [Updates: `^6.0.0`]
- `typescript ^4.7.4` β†’ [Updates: `^6.0.0`]
- `ws ^8.4.2`
- `@types/cors 2.8.17` β†’ [Updates: `2.8.19`]
- `@types/node 18.19.54` β†’ [Updates: `18.19.130`, `24.12.2`]
- `@types/ws 8.5.12` β†’ [Updates: `8.18.1`]

docs/package.json (6)

- `@apollo/tailwind-preset 0.2.0`
- `@astrojs/check 0.9.3` β†’ [Updates: `0.9.8`]
- `@astrojs/starlight 0.28.2` β†’ [Updates: `0.38.3`]
- `astro 4.15.9` β†’ [Updates: `6.1.6`]
- `sharp 0.33.5` β†’ [Updates: `0.34.5`]
- `typescript 5.5.4` β†’ [Updates: `5.9.3`, `6.0.3`]

package.json (78)

- `@bundled-es-modules/statuses ^1.0.1`
- `@graphql-tools/executor ^1.2.7`
- `@graphql-tools/merge ^9.0.4`
- `@graphql-tools/mock ^9.0.4`
- `@graphql-tools/schema ^10.0.4`
- `@graphql-tools/utils ^10.3.2` β†’ [Updates: `^11.0.0`]
- `@types/statuses ^2.0.5`
- `graphql-tag ^2.12.6`
- `is-node-process ^1.2.0`
- `outvariant ^1.4.3`
- `@apollo/client 3.12.4` β†’ [Updates: `3.14.1`, `4.1.7`]
- `@apollo/tailwind-preset 0.2.0`
- `@changesets/changelog-github 0.5.0` β†’ [Updates: `0.6.0`]
- `@changesets/cli 2.27.8` β†’ [Updates: `2.31.0`]
- `@graphql-codegen/cli 5.0.2` β†’ [Updates: `5.0.7`, `6.3.1`]
- `@graphql-codegen/typescript 4.1.2` β†’ [Updates: `4.1.6`, `5.0.10`]
- `@graphql-codegen/typescript-resolvers 4.4.1` β†’ [Updates: `4.5.2`, `5.1.8`]
- `@graphql-tools/jest-transform 2.0.0` β†’ [Updates: `2.0.1`]
- `@playwright/test 1.49.1` β†’ [Updates: `1.59.1`]
- `@storybook/addon-docs 8.4.7` β†’ [Updates: `8.6.18`, `10.3.5`]
- `@storybook/addon-essentials 8.4.7` β†’ [Updates: `8.6.14`]
- `@storybook/addon-interactions 8.4.7` β†’ [Updates: `8.6.14`]
- `@storybook/addon-links 8.4.7` β†’ [Updates: `8.6.18`, `10.3.5`]
- `@storybook/blocks 8.4.7` β†’ [Updates: `8.6.14`]
- `@storybook/react 8.4.7` β†’ [Updates: `8.6.18`, `10.3.5`]
- `@storybook/react-vite 8.4.7` β†’ [Updates: `8.6.18`, `10.3.5`]
- `@storybook/test 8.4.7` β†’ [Updates: `8.6.15`]
- `@storybook/test-runner 0.20.1` β†’ [Updates: `0.24.3`]
- `@svgr/plugin-jsx 8.1.0`
- `@svgr/plugin-svgo 8.1.0`
- `@tailwindcss/aspect-ratio 0.4.2`
- `@testing-library/dom 10.4.0` β†’ [Updates: `10.4.1`]
- `@testing-library/jest-dom 6.6.3` β†’ [Updates: `6.9.1`]
- `@testing-library/react 16.1.0` β†’ [Updates: `16.3.2`]
- `@tsconfig/recommended 1.0.7` β†’ [Updates: `1.0.13`]
- `@types/jest 29.5.13` β†’ [Updates: `29.5.14`, `30.0.0`]
- `@types/node 22.10.2` β†’ [Updates: `22.19.17`, `24.12.2`]
- `@types/react 18.3.10` β†’ [Updates: `18.3.28`, `19.2.14`]
- `@types/react-dom 18.3.0` β†’ [Updates: `18.3.7`, `19.2.3`]
- `@types/react-relay 16.0.6` β†’ [Updates: `18.2.1`]
- `@types/relay-runtime 17.0.4` β†’ [Updates: `20.1.1`]
- `@typescript-eslint/eslint-plugin 8.18.1` β†’ [Updates: `8.58.2`]
- `@typescript-eslint/parser 8.18.1` β†’ [Updates: `8.58.2`]
- `babel-plugin-relay 17.0.0` β†’ [Updates: `20.1.1`]
- `concurrently 8.2.2` β†’ [Updates: `9.2.1`]
- `eslint-plugin-storybook 0.11.1` β†’ [Updates: `0.12.0`, `10.3.5`]
- `graphql 16.10.0` β†’ [Updates: `16.13.2`]
- `graphql-ws 5.16.0` β†’ [Updates: `5.16.2`, `6.0.8`]
- `http-server 14.1.1`
- `jest 29.7.0` β†’ [Updates: `30.3.0`]
- `jest-environment-jsdom 29.7.0` β†’ [Updates: `30.3.0`]
- `jsdom 25.0.1` β†’ [Updates: `29.0.2`]
- `msw 2.7.0` β†’ [Updates: `2.13.4`]
- `msw-storybook-addon 2.0.3` β†’ [Updates: `2.0.7`]
- `playwright 1.49.1` β†’ [Updates: `1.55.1`]
- `postcss 8.4.47` β†’ [Updates: `8.5.10`]
- `prettier 3.4.2` β†’ [Updates: `3.8.3`]
- `react 18.3.1` β†’ [Updates: `19.2.5`]
- `react-relay 17.0.0` β†’ [Updates: `20.1.1`]
- `relay-compiler 17.0.0` β†’ [Updates: `20.1.1`]
- `relay-runtime 17.0.0` β†’ [Updates: `20.1.1`]
- `storybook 8.4.7` β†’ [Updates: `8.6.17`]
- `tailwind 4.0.0`
- `tailwindcss 3.4.13` β†’ [Updates: `3.4.19`, `4.2.2`]
- `ts-jest 29.2.5` β†’ [Updates: `29.4.9`]
- `ts-jest-resolver 2.0.1`
- `tsup 8.3.0` β†’ [Updates: `8.3.5`]
- `tw-colors 3.3.2`
- `typescript 5.7.2` β†’ [Updates: `5.9.3`, `6.0.3`]
- `undici 6.21.0` β†’ [Updates: `6.24.0`]
- `vite 5.4.8` β†’ [Updates: `6.4.2`]
- `vite-plugin-graphql-loader 4.0.4` β†’ [Updates: `5.0.1`]
- `vite-plugin-relay 2.1.0`
- `vite-plugin-svgr 4.3.0` β†’ [Updates: `4.5.0`, `5.2.0`]
- `vitest 2.1.1` β†’ [Updates: `2.1.9`]
- `wait-on 8.0.1` β†’ [Updates: `8.0.5`, `9.0.5`]
- `graphql ^15.0.0 || ^16.0.0`
- `msw ^2.0.0`

renovate-config-presets (1)

renovate.json

Contributor guide

No contributing guide indexed for this repository

Research direction

Start with the linked Dependency Dashboard documentation and config migration reference, including PR #132, then inspect the repository warning about npm-based Renovate presets. Review the listed .github/workflows files and linked Renovate PRs; the issue does not define a single completion condition or a newcomer-sized change.

Written by the indexing model from the issue text.

Assessment

Tech stack
express, github-actions, graphql, node.js, playwright, storybook, tailwindcss, typescript, vite
Domain
ci-cd, devops, security, tooling
Issue type
Refactor
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
15/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.