apollographql / apollographql/vscode-graphql

Dependency Dashboard

Open
#115 0 comments 0 reactions 0 assignees View on GitHub
dependencies
Dominant language
TypeScript
Stars
79
Forks
23
PR merge metrics
No merged PRs in 30d

Description

This issue lists Renovate updates and detected dependencies. Read the [Dependency Dashboard](https://docs.renovatebot.com/key-concepts/dashboard/) docs to learn more.

## Repository Problems

Renovate tried to run on this repository, but found these problems.

- ⚠️ WARN: Using npm packages for Renovate presets is now deprecated. Please migrate to repository-based presets instead.

## Deprecations / Replacements
> [!WARNING]
These dependencies are either deprecated or have replacements available:

| Datasource | Package | Replacement PR? |
|------------|------|--------------|
| npm | [npm-run-all](https://redirect.github.com/mysticatea/npm-run-all) | ![Available](https://img.shields.io/badge/available-green?style=flat-square) |

## Rate-Limited

The following updates are currently rate-limited. To force their creation now, click on a checkbox below.

- [ ] chore(deps): replace dependency npm-run-all with npm-run-all2 5.0.0
- [ ] chore(deps): update slackapi/slack-github-action action to v1.27.1
- [ ] fix(deps): update dependency @graphql-tools/schema to v10.1.1
- [ ] fix(deps): update dependency graphql to v16.14.2
- [ ] fix(deps): update dependency graphql-language-service to v5.7.0
- [ ] fix(deps): update dependency zod to v3.25.76
- [ ] fix(deps): update dependency zod-validation-error to v3.5.4
- [ ] chore(deps): update actions/checkout action to v7
- [ ] chore(deps): update actions/setup-node action to v7
- [ ] chore(deps): update actions/upload-artifact action to v7
- [ ] chore(deps): update andstor/file-existence-action action to v3
- [ ] chore(deps): update haaleo/publish-vscode-extension action to v2
- [ ] chore(deps): update node.js to v24
- [ ] chore(deps): update peter-evans/create-or-update-comment action to v5
- [ ] chore(deps): update peter-evans/find-comment action to v4
- [ ] chore(deps): update slackapi/slack-github-action action to v4
- [ ] fix(deps): update dependency @apollo/client to v4
- [ ] fix(deps): update dependency cosmiconfig to v10
- [ ] fix(deps): update dependency dotenv to v17
- [ ] fix(deps): update dependency graphql to v17
- [ ] fix(deps): update dependency vscode-languageclient to v10
- [ ] fix(deps): update dependency vscode-languageserver to v10
- [ ] fix(deps): update dependency which to v7
- [ ] fix(deps): update dependency zod to v4
- [ ] fix(deps): update dependency zod-validation-error to v5
- [ ] πŸ” **Create all rate-limited PRs at once** πŸ”

## Pending Status Checks

The following updates await pending status checks. To force their creation now, click on a checkbox below.

- [ ] [chore(deps): update circleci dependencies (non-major)](../pull/264)
- [ ] chore(deps): update node.js to v24

## Other Branches

The following updates are pending. To force the creation of a PR, click on a checkbox below.

- [ ] chore(deps): lock file maintenance

## Open

The following updates have all been created. To force a retry/rebase of any, click on a checkbox below.

- [ ] [chore(deps): update dependency js-yaml to v4.3.2 [security]](../pull/316)
- [ ] [fix(deps): update dependency glob to v11.1.0 [security]](../pull/301)
- [ ] [fix(deps): update dependency undici to v6.28.0 [security]](../pull/305)
- [ ] [fix(deps): update dependency ws to v8.21.0 [security]](../pull/311)
- [ ] [fix(deps): update dependency @faker-js/faker to v10 [security]](../pull/318)
- [ ] [fix(deps): update all dependencies - patch updates](../pull/260) (`@graphql-codegen/cli`, `@vscode/test-cli`, `cosmiconfig`, `esbuild`, `eslint-config-prettier`, `graphql-tag`, `import-fresh`, `minimatch`, `secops`, `vscode-languageserver-textdocument`)
- [ ] [chore(deps): update all devdependencies](../pull/272) (`@apollo/rover`, `@changesets/changelog-github`, `@changesets/cli`, `@graphql-codegen/typescript-operations`, `@vscode/test-electron`, `eslint-plugin-prettier`, `graphql-http`, `memfs`, `oniguruma-parser`, `patch-package`, `prettier`, `rimraf`, `ts-jest`, `typescript`, `zod-to-json-schema`)
- [ ] [fix(deps): update apollo graphql packages](../pull/289) (`@apollo/client`, `@apollo/client-devtools-vscode`, `@apollo/subgraph`)
- [ ] [fix(deps): update dependency dotenv to v16.6.1](../pull/295)
- [ ] [fix(deps): update dependency semver to v7.8.5](../pull/276)
- [ ] [fix(deps): update dependency vscode-uri to v3.2.0](../pull/277)
- [ ] [chore(deps): update all devdependencies (major)](../pull/273) (`@changesets/changelog-github`, `@changesets/cli`, `@graphql-codegen/cli`, `@graphql-codegen/typescript-operations`, `@types/jest`, `@vscode/test-electron`, `eslint-config-prettier`, `import-fresh`, `jest`, `jest-environment-node`, `typescript`)
- [ ] **Click on this checkbox to rebase all open PRs at once**

## Vulnerabilities

> [!IMPORTANT]
> `20`/`20` CVEs have Renovate fixes.

npm

package.json

glob

- [GHSA-5j98-mcp5-4vw2](https://osv.dev/vulnerability/GHSA-5j98-mcp5-4vw2) (fixed in >= 11.1.0)

undici

- [GHSA-2mjp-6q6p-2qxm](https://osv.dev/vulnerability/GHSA-2mjp-6q6p-2qxm) (fixed in >= 6.24.0)
- [GHSA-35p6-xmwp-9g52](https://osv.dev/vulnerability/GHSA-35p6-xmwp-9g52) (fixed in >= 6.27.0)
- [GHSA-4992-7rv2-5pvq](https://osv.dev/vulnerability/GHSA-4992-7rv2-5pvq) (fixed in >= 6.24.0)
- [GHSA-8xcm-r25x-g524](https://osv.dev/vulnerability/GHSA-8xcm-r25x-g524) (fixed in >= 6.28.0)
- [GHSA-f269-vfmq-vjvj](https://osv.dev/vulnerability/GHSA-f269-vfmq-vjvj) (fixed in >= 6.24.0)
- [GHSA-g8m3-5g58-fq7m](https://osv.dev/vulnerability/GHSA-g8m3-5g58-fq7m) (fixed in >= 6.27.0)
- [GHSA-g9mf-h72j-4rw9](https://osv.dev/vulnerability/GHSA-g9mf-h72j-4rw9) (fixed in >= 6.23.0)
- [GHSA-m8rv-5g2x-5cg5](https://osv.dev/vulnerability/GHSA-m8rv-5g2x-5cg5) (fixed in >= 6.28.0)
- [GHSA-p88m-4jfj-68fv](https://osv.dev/vulnerability/GHSA-p88m-4jfj-68fv) (fixed in >= 6.27.0)
- [GHSA-v3r7-h72x-cjcm](https://osv.dev/vulnerability/GHSA-v3r7-h72x-cjcm) (fixed in >= 6.28.0)
- [GHSA-v9p9-hfj2-hcw8](https://osv.dev/vulnerability/GHSA-v9p9-hfj2-hcw8) (fixed in >= 6.24.0)
- [GHSA-vrm6-8vpv-qv8q](https://osv.dev/vulnerability/GHSA-vrm6-8vpv-qv8q) (fixed in >= 6.24.0)
- [GHSA-vxpw-j846-p89q](https://osv.dev/vulnerability/GHSA-vxpw-j846-p89q) (fixed in >= 6.27.0)

ws

- [GHSA-58qx-3vcg-4xpx](https://osv.dev/vulnerability/GHSA-58qx-3vcg-4xpx) (fixed in >= 8.20.1)
- [GHSA-96hv-2xvq-fx4p](https://osv.dev/vulnerability/GHSA-96hv-2xvq-fx4p) (fixed in >= 8.21.0)

sampleWorkspace/connectors-community/package.json

@faker-js/faker

- [GHSA-qxc2-j82w-r537](https://osv.dev/vulnerability/GHSA-qxc2-j82w-r537) (fixed in >= 10.5.0)

js-yaml

- [GHSA-2883-xcg3-v3hh](https://osv.dev/vulnerability/GHSA-2883-xcg3-v3hh) (fixed in >= 4.3.2)
- [GHSA-52cp-r559-cp3m](https://osv.dev/vulnerability/GHSA-52cp-r559-cp3m) (fixed in >= 4.3.0)
- [GHSA-5p4m-2wfm-xmqj](https://osv.dev/vulnerability/GHSA-5p4m-2wfm-xmqj) (fixed in >= 4.3.1)

## Detected Dependencies

circleci (1)

.circleci/config.yml (3)

- `secops 2.0.7` β†’ [Updates: `2.0.9`]
- `cimg/node 22.12.0` β†’ [Updates: `22.23.2`, `24.21.0`]
- `cimg/node 24.4.0` β†’ [Updates: `24.21.0`]

dockerfile (2)

sampleWorkspace/connectors-community/connectors/.template/Dockerfile (1)

- `ghcr.io/apollographql/router v2.2.0` β†’ [Updates: `v2.17.0`]

sampleWorkspace/connectors-community/connectors/anthropic/Dockerfile (1)

- `ghcr.io/apollographql/router v2.2.0` β†’ [Updates: `v2.17.0`]

github-actions (3)

.github/workflows/build-prs.yml (6)

- `actions/checkout v4` β†’ [Updates: `v7`]
- `actions/setup-node v4` β†’ [Updates: `v7`]
- `actions/upload-artifact v4` β†’ [Updates: `v7`]
- `peter-evans/find-comment v3` β†’ [Updates: `v4`]
- `peter-evans/create-or-update-comment v4` β†’ [Updates: `v5`]
- `node 24`

.github/workflows/E2E.yml (3)

- `actions/checkout v4` β†’ [Updates: `v7`]
- `actions/setup-node v4` β†’ [Updates: `v7`]
- `node 24`

.github/workflows/release.yml (8)

- `actions/checkout v4` β†’ [Updates: `v7`]
- `andstor/file-existence-action v2.0.0` β†’ [Updates: `v3.1.0`]
- `actions/setup-node v3` β†’ [Updates: `v7`]
- `changesets/action v1`
- `HaaLeo/publish-vscode-extension v1` β†’ [Updates: `v2`]
- `HaaLeo/publish-vscode-extension v1` β†’ [Updates: `v2`]
- `slackapi/slack-github-action v1.24.0` β†’ [Updates: `v1.27.1`, `v4.0.0`]
- `node 24.x`

npm (8)

package.json (56)

- `@apollo/client 3.12.3` β†’ [Updates: `3.14.1`, `4.2.12`]
- `@apollo/client-devtools-vscode 4.20.1` β†’ [Updates: `4.26.1`]
- `@apollo/subgraph 2.9.3` β†’ [Updates: `2.15.0`]
- `@graphql-tools/schema 10.0.13` β†’ [Updates: `10.1.1`]
- `@wry/equality 0.5.7`
- `cosmiconfig 9.0.0` β†’ [Updates: `9.0.2`, `10.0.1`]
- `dotenv 16.4.7` β†’ [Updates: `16.6.1`, `17.4.2`]
- `glob 11.0.0` β†’ [Updates: `11.1.0`]
- `graphql 16.12.0` β†’ [Updates: `16.14.2`, `17.0.2`]
- `graphql-language-service 5.5.0` β†’ [Updates: `5.7.0`]
- `graphql-tag 2.12.6` β†’ [Updates: `2.12.7`]
- `jsonc-parser ^3.3.1`
- `lodash.debounce 4.0.8`
- `lz-string 1.5.0`
- `minimatch 10.2.3` β†’ [Updates: `10.2.6`]
- `moment 2.30.1`
- `semver 7.6.3` β†’ [Updates: `7.8.5`]
- `undici 6.21.2` β†’ [Updates: `6.28.0`]
- `vscode-languageclient 9.0.1` β†’ [Updates: `10.1.1`]
- `vscode-languageserver 9.0.1` β†’ [Updates: `10.1.1`]
- `vscode-languageserver-textdocument 1.0.12` β†’ [Updates: `1.0.14`]
- `vscode-uri 3.0.8` β†’ [Updates: `3.2.0`]
- `which 5.0.0` β†’ [Updates: `7.0.0`]
- `ws 8.18.0` β†’ [Updates: `8.21.0`]
- `zod 3.24.1` β†’ [Updates: `3.25.76`, `4.6.2`]
- `zod-validation-error 3.4.0` β†’ [Updates: `3.5.4`, `5.0.0`]
- `@apollo/rover 0.27.0` β†’ [Updates: `0.41.0`]
- `@changesets/changelog-github 0.5.0` β†’ [Updates: `0.7.0`, `1.0.1`]
- `@changesets/cli 2.27.10` β†’ [Updates: `2.31.1`, `3.0.2`]
- `@graphql-codegen/cli 5.0.2` β†’ [Updates: `5.0.7`, `7.4.1`]
- `@graphql-codegen/typescript-operations 4.2.3` β†’ [Updates: `4.6.1`, `6.1.6`]
- `@types/jest 29.5.14` β†’ [Updates: `30.0.0`]
- `@types/lodash.debounce 4.0.9`
- `@types/lodash.merge 4.6.9`
- `@vscode/test-cli 0.0.10` β†’ [Updates: `0.0.15`]
- `@vscode/test-electron 2.4.1` β†’ [Updates: `2.5.2`, `3.1.0`]
- `@wry/trie 0.5.0`
- `esbuild 0.28.1` β†’ [Updates: `0.28.2`]
- `eslint-config-prettier 9.1.0` β†’ [Updates: `9.1.2`, `10.1.8`]
- `eslint-plugin-prettier 5.2.1` β†’ [Updates: `5.5.6`]
- `graphql-http 1.22.1` β†’ [Updates: `1.23.0`]
- `import-fresh 3.3.0` β†’ [Updates: `3.3.1`, `4.0.0`]
- `jest 29.7.0` β†’ [Updates: `30.5.1`]
- `jest-environment-node 29.7.0` β†’ [Updates: `30.5.1`]
- `memfs 4.15.0` β†’ [Updates: `4.75.0`]
- `npm-run-all 4.1.5` β†’ [Updates: `5.0.0`]
- `oniguruma-parser ^0.12.1` β†’ [Updates: `0.12.1`]
- `patch-package ^8.0.1` β†’ [Updates: `8.0.1`]
- `prettier 3.4.2` β†’ [Updates: `3.9.6`]
- `rimraf 6.0.1` β†’ [Updates: `6.1.3`]
- `ts-jest 29.2.5` β†’ [Updates: `29.4.12`]
- `ts-node 10.9.2`
- `typescript 5.5.3` β†’ [Updates: `5.9.3`, `7.0.2`]
- `vscode-tmgrammar-test 0.1.3`
- `zod-to-json-schema 3.23.3` β†’ [Updates: `3.25.2`]
- `vscode ^1.90.0`

sampleWorkspace/configFileTypes/cjsConfig/package.json

sampleWorkspace/configFileTypes/jsConfigWithCJS/package.json

sampleWorkspace/configFileTypes/jsConfigWithESM/package.json

sampleWorkspace/configFileTypes/mjsConfig/package.json

sampleWorkspace/configFileTypes/tsConfigWithCJS/package.json

sampleWorkspace/configFileTypes/tsConfigWithESM/package.json

sampleWorkspace/connectors-community/package.json (6)

- `@faker-js/faker ^9.0.3` β†’ [Updates: `^10.0.0`]
- `dotenv ^16.4.5` β†’ [Updates: `^17.0.0`]
- `graphql ^16.9.0` β†’ [Updates: `^17.0.0`]
- `graphql-request ^7.1.0`
- `js-yaml ^4.1.0` β†’ [Updates: `^4.1.0`]
- `prompts ^2.4.2`

nvm (1)

.nvmrc (1)

- `node 22` β†’ [Updates: `24`]

renovate-config-presets (1)

renovate.json

Contributor guide

No contributing guide indexed for this repository

Research direction

This is an automated Renovate dashboard rather than a scoped change. Start with the linked Renovate dashboard documentation, then inspect package.json, .github/workflows/build-prs.yml, E2E.yml, release.yml, .circleci/config.yml, and the listed Dockerfiles; done would require choosing and validating a specific update, but this issue alone does not define one.

Written by the indexing model from the issue text.

Assessment

Tech stack
dockerfile, github-actions, graphql, typescript
Domain
devops, security, tooling
Issue type
Refactor
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
15/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.