refactor: Bump parse-server to 9.10.1, npm to 11.20.0, tar to 7.5.22, fast-xml-parser to 5.11.1, uuid to 11.1.1 and @tootallnate/once to 2.0.1 - #617
Conversation
…o 11.20.0, tar from 7.5.16 to 7.5.22, fast-xml-parser from 5.5.8 to 5.11.1, uuid from 11.1.0 to 11.1.1 and @tootallnate/once from 2.0.0 to 2.0.1
|
🚀 Thanks for opening this pull request! We appreciate your effort in improving the project. Please let us know once your pull request is ready for review. Tip
Note Please respond to review comments from AI agents just like you would to comments from a human reviewer. Let the reviewer resolve their own comments, unless they have reviewed and accepted your commit, or agreed with your explanation for why the feedback was incorrect. Caution Pull requests must be written using an AI agent with human supervision. Pull requests written entirely by a human will likely be rejected, because of lower code quality, higher review effort and the higher risk of introducing bugs. Please note that AI review comments on this pull request alone do not satisfy this requirement. Our CI and AI review are safeguards, not development tools. If many issues are flagged, rethink your development approach. Invest more effort in planning and design rather than using review cycles to fix low-quality code. |
|
Warning Review limit reached
Reviews can continue after your included limit without a manual trigger. An admin must approve usage-based billing. Next included review available in 25 minutes. View limit detailsLimit details: You’ve used the included review currently available. Your 65 included PR review attempts over the past 7 days set your current allowance at 1 review per hour. The included review limit has been reached and this organization has disabled usage-based review continuation. Wait for reviews to reset or ask a billing admin to change After included review limits. Review configuration: ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Essentials Run ID: 📒 Files selected for processing (2)
Comment |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #617 +/- ##
=======================================
Coverage 97.77% 97.77%
=======================================
Files 2 2
Lines 225 225
=======================================
Hits 220 220
Misses 5 5 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
Issue
Fixes 16 open Dependabot security alerts. All affected packages are development-only dependencies, so the published package is not affected.
express-rate-limit8.7.0 (via parse-server) → ip-address 10.7.2; bundled in npm → 10.5.0Not fixed by this PR:
decompress(alerts 363, 378, 396): no patched version exists.uuid(alert 315): the top-level copy is updated to 11.1.1, but other copies stay on 8.x / 9.x becausegaxios,google-gax,teeny-requestandistanbul-lib-processinfopin^8/^9.Approach
Upgrades the
parse-serverdevDependency from 9.10.0 to 9.10.1 (exact pin), and updates the transitive dependenciesnpm(11.17.0 → 11.20.0),tar(7.5.16 → 7.5.22),fast-xml-parser(5.5.8 → 5.11.1),uuid(11.1.0 → 11.1.1) and@tootallnate/once(2.0.0 → 2.0.1) within their existing parent ranges. Nooverrideswere added.The parse-server upgrade also moves
@parse/push-adapter(8.4.0 → 8.5.5),parse(8.5.0 → 8.6.2),ws(→ 8.21.3),express-rate-limit(8.3.1 → 8.7.0),follow-redirects(1.15.11 → 1.16.0) and their subtrees (e.g.firebase-admin13.9.0,@google-cloud/storage7.22.0,google-auth-library10.9.1). The lock file diff is limited to these packages and their dependencies.CI installs
parse-server@8/parse-server@9at job time, so the Parse Server 9 jobs already test against 9.10.1.Changes
@parse/push-adapter,express-rate-limit,follow-redirects,parseandws(see fix: Bump @parse/push-adapter from 8.4.0 to 8.5.3 parse-server#10676, fix: Bump express-rate-limit from 8.3.1 to 8.7.0 parse-server#10672, fix: Bump follow-redirects from 1.15.11 to 1.16.0 parse-server#10577, fix: Bump parse from 8.6.0 to 8.6.2, @parse/push-adapter from 8.5.3 to 8.5.5 and ws from 8.21.0 to 8.21.3 parse-server#10688)stage/install-scriptsfeatures, the linked install strategy graduates to stable, and bundled dependency updates (undici6.28.0,ip-address10.5.0,brace-expansion5.0.9,tar7.5.22). Only used by@semantic-release/npmduring releases.list,maxDecompressionRatioguard with a default of 1000, unzip disposal on abort)@nodable/entities; 5.7.0 (the security fix) no longer lets entity values form other entity names or allows numeric external entities; DOCTYPE validation,endIndexnode metadata and parser fixes. The only consumer is@google-cloud/storage(optional dependency offirebase-admin), which uses a defaultXMLParserin its transfer manager. This code path is not used by this repository.Breaking Changes
None for this repository. fast-xml-parser 5.7.0 tightens entity handling as part of its security fix (see above); its only consumer here parses entity-free GCS responses in a code path this repository does not use.
Code Changes Required
None. The upgrade is a drop-in replacement (manifest and lock file only).
Tasks
No tasks apply; this PR only updates development dependencies in the manifest and lock file.