apollographql / apollographql/next-apollo-example
Dependency Dashboard
- Dominant language
- JavaScript
- Stars
- 14
- Forks
- 8
- PR merge metrics
- No merged PRs in 30d
Description
This issue lists Renovate updates and detected dependencies. Read the [Dependency Dashboard](https://docs.renovatebot.com/key-concepts/dashboard/) docs to learn more.
## Rate-Limited
The following updates are currently rate-limited. To force their creation now, click on a checkbox below.
- [ ] chore(deps): lock file maintenance
## Open
The following updates have all been created. To force a retry/rebase of any, click on a checkbox below.
- [ ] [fix(deps): update dependency lodash to v4.18.1 [security]](../pull/10)
- [ ] [fix(deps): update dependency next to v15 [security]](../pull/8)
- [ ] [fix(deps): update dependency @apollo/client to v3.14.1](../pull/11)
- [ ] [fix(deps): update dependency graphql to v16.14.2](../pull/12)
- [ ] [fix(deps): update dependency react to v18.3.1](../pull/16)
- [ ] [fix(deps): update dependency react-dom to v18.3.1](../pull/17)
- [ ] [fix(deps): update dependency @apollo/client to v4](../pull/14)
- [ ] [fix(deps): update dependency graphql to v17](../pull/15)
- [ ] [fix(deps): update dependency react to v19](../pull/18)
- [ ] [fix(deps): update dependency react-dom to v19](../pull/19)
- [ ] **Click on this checkbox to rebase all open PRs at once**
## Vulnerabilities
> [!IMPORTANT]
> `32`/`32` CVEs have Renovate fixes.
npm
package.json
lodash
- [GHSA-f23m-r3pf-42rh](https://osv.dev/vulnerability/GHSA-f23m-r3pf-42rh) (fixed in >= 4.18.0)
- [GHSA-r5fr-rjxr-66jc](https://osv.dev/vulnerability/GHSA-r5fr-rjxr-66jc) (fixed in >= 4.18.0)
- [GHSA-xxjr-mmjv-4gpg](https://osv.dev/vulnerability/GHSA-xxjr-mmjv-4gpg) (fixed in >= 4.17.23)next
- [GHSA-2xp9-vwfh-vxw4](https://osv.dev/vulnerability/GHSA-2xp9-vwfh-vxw4) (fixed in >= 15.5.24)
- [GHSA-36qx-fr4f-26g5](https://osv.dev/vulnerability/GHSA-36qx-fr4f-26g5) (fixed in >= 15.5.16)
- [GHSA-3g8h-86w9-wvmq](https://osv.dev/vulnerability/GHSA-3g8h-86w9-wvmq) (fixed in >= 15.5.16)
- [GHSA-3x4c-7xq6-9pq8](https://osv.dev/vulnerability/GHSA-3x4c-7xq6-9pq8) (fixed in >= 15.5.14)
- [GHSA-4342-x723-ch2f](https://osv.dev/vulnerability/GHSA-4342-x723-ch2f) (fixed in >= 14.2.32)
- [GHSA-4633-3j49-mh5q](https://osv.dev/vulnerability/GHSA-4633-3j49-mh5q) (fixed in >= 15.5.21)
- [GHSA-4c39-4ccg-62r3](https://osv.dev/vulnerability/GHSA-4c39-4ccg-62r3) (fixed in >= 15.5.21)
- [GHSA-5j59-xgg2-r9c4](https://osv.dev/vulnerability/GHSA-5j59-xgg2-r9c4) (fixed in >= 14.2.35)
- [GHSA-68g3-v927-f742](https://osv.dev/vulnerability/GHSA-68g3-v927-f742) (fixed in >= 15.5.21)
- [GHSA-7gfc-8cq8-jh5f](https://osv.dev/vulnerability/GHSA-7gfc-8cq8-jh5f) (fixed in >= 14.2.15)
- [GHSA-7m27-7ghc-44w9](https://osv.dev/vulnerability/GHSA-7m27-7ghc-44w9) (fixed in >= 13.5.8)
- [GHSA-8h8q-6873-q5fj](https://osv.dev/vulnerability/GHSA-8h8q-6873-q5fj) (fixed in >= 15.5.16)
- [GHSA-955p-x3mx-jcvp](https://osv.dev/vulnerability/GHSA-955p-x3mx-jcvp) (fixed in >= 15.5.21)
- [GHSA-9g9p-9gw9-jx7f](https://osv.dev/vulnerability/GHSA-9g9p-9gw9-jx7f) (fixed in >= 15.5.10)
- [GHSA-c59h-r6p8-q9wc](https://osv.dev/vulnerability/GHSA-c59h-r6p8-q9wc) (fixed in >= 13.4.20-canary.13)
- [GHSA-f82v-jwr5-mffw](https://osv.dev/vulnerability/GHSA-f82v-jwr5-mffw) (fixed in >= 13.5.9)
- [GHSA-fq54-2j52-jc42](https://osv.dev/vulnerability/GHSA-fq54-2j52-jc42) (fixed in >= 13.5.0)
- [GHSA-g5qg-72qw-gw5v](https://osv.dev/vulnerability/GHSA-g5qg-72qw-gw5v) (fixed in >= 14.2.31)
- [GHSA-g77x-44xx-532m](https://osv.dev/vulnerability/GHSA-g77x-44xx-532m) (fixed in >= 14.2.7)
- [GHSA-ggv3-7p47-pfv8](https://osv.dev/vulnerability/GHSA-ggv3-7p47-pfv8) (fixed in >= 15.5.13)
- [GHSA-gx5p-jg67-6x7h](https://osv.dev/vulnerability/GHSA-gx5p-jg67-6x7h) (fixed in >= 15.5.16)
- [GHSA-h25m-26qc-wcjf](https://osv.dev/vulnerability/GHSA-h25m-26qc-wcjf) (fixed in >= 15.0.8)
- [GHSA-h64f-5h5j-jqjh](https://osv.dev/vulnerability/GHSA-h64f-5h5j-jqjh) (fixed in >= 15.5.16)
- [GHSA-m99w-x7hq-7vfj](https://osv.dev/vulnerability/GHSA-m99w-x7hq-7vfj) (fixed in >= 15.5.21)
- [GHSA-mwv6-3258-q52c](https://osv.dev/vulnerability/GHSA-mwv6-3258-q52c) (fixed in >= 14.2.34)
- [GHSA-p9j2-gv94-2wf4](https://osv.dev/vulnerability/GHSA-p9j2-gv94-2wf4) (fixed in >= 15.5.21)
- [GHSA-q4gf-8mx6-v5v3](https://osv.dev/vulnerability/GHSA-q4gf-8mx6-v5v3) (fixed in >= 15.5.15)
- [GHSA-qpjv-v59x-3qc4](https://osv.dev/vulnerability/GHSA-qpjv-v59x-3qc4) (fixed in >= 14.2.24)
- [GHSA-xv57-4mr9-wg8v](https://osv.dev/vulnerability/GHSA-xv57-4mr9-wg8v) (fixed in >= 14.2.31)
## Detected Dependencies
npm (1)
package.json (7)
- `@apollo/client 3.7.12` → [Updates: `3.14.1`, `4.2.12`]
- `deepmerge 4.3.1`
- `graphql 16.8.1` → [Updates: `16.14.2`, `17.0.2`]
- `lodash 4.17.21` → [Updates: `4.18.1`]
- `next 13.3.1` → [Updates: `15.5.24`]
- `react 18.2.0` → [Updates: `18.3.1`, `19.3.0`]
- `react-dom 18.2.0` → [Updates: `18.3.1`, `19.3.0`]
Contributor guide
No contributing guide indexed for this repository
Research direction
Start with the Renovate Dependency Dashboard documentation and the detected dependencies in package.json. Review the linked pull requests for the listed lodash, Next.js, Apollo Client, GraphQL, React, and react-dom updates before deciding what remains. Done means the selected dependency updates are handled and the dashboard no longer lists them as open or vulnerable.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- graphql, javascript, nextjs, react
- Domain
- security, tooling
- Issue type
- Refactor
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 15/100