Skip to content

refactor: Bump parse-server to 9.10.1, npm to 11.20.0, tar to 7.5.22, fast-xml-parser to 5.11.1, uuid to 11.1.1 and @tootallnate/once to 2.0.1 - #617

Merged
mtrezza merged 1 commit into
parse-community:masterfrom
mtrezza:refactor/parse-server-9.10.1
Sep 26, 2026
Merged

mtrezza merged 1 commit into
parse-community:masterfrom
mtrezza:refactor/parse-server-9.10.1

Conversation

@mtrezza

@mtrezza mtrezza commented Sep 26, 2026

Copy link
Copy Markdown
Member

Issue

Fixes 16 open Dependabot security alerts. All affected packages are development-only dependencies, so the published package is not affected.

Alert Severity Package Advisory Fixed by
390 high ip-address GHSA-mwp4-54f8-5fhr express-rate-limit 8.7.0 (via parse-server) → ip-address 10.7.2; bundled in npm → 10.5.0
367 high brace-expansion GHSA-3jxr-9vmj-r5cp npm 11.20.0 bundles brace-expansion 5.0.9
355 high ws GHSA-96hv-2xvq-fx4p parse-server 9.10.1 / parse 8.6.2 pin ws 8.21.3
393, 392, 391 medium undici GHSA-v3r7-h72x-cjcm, GHSA-8xcm-r25x-g524, GHSA-m8rv-5g2x-5cg5 npm 11.20.0 bundles undici 6.28.0
353, 354, 352 medium / low undici GHSA-p88m-4jfj-68fv, GHSA-g8m3-5g58-fq7m, GHSA-35p6-xmwp-9g52 npm 11.20.0 bundles undici 6.28.0
384, 383, 304 medium ip-address GHSA-4xrf-jv44-h6hh, GHSA-22jq-vg5j-6vgg, GHSA-v2v4-37r5-5v8g see alert 390
373 medium tar GHSA-w8wr-v893-vjvp tar 7.5.22 (top-level and bundled in npm)
300 medium fast-xml-parser GHSA-gh4j-gqv2-49f6 fast-xml-parser 5.11.1
298 medium follow-redirects GHSA-r4q5-vmmm-2653 parse-server 9.10.1 pins follow-redirects 1.16.0
316 low @tootallnate/once GHSA-vpq2-c234-7xj6 @tootallnate/once 2.0.1

Not fixed by this PR:

  • decompress (alerts 363, 378, 396): no patched version exists.
  • uuid (alert 315): the top-level copy is updated to 11.1.1, but other copies stay on 8.x / 9.x because gaxios, google-gax, teeny-request and istanbul-lib-processinfo pin ^8 / ^9.

Approach

Upgrades the parse-server devDependency from 9.10.0 to 9.10.1 (exact pin), and updates the transitive dependencies npm (11.17.0 → 11.20.0), tar (7.5.16 → 7.5.22), fast-xml-parser (5.5.8 → 5.11.1), uuid (11.1.0 → 11.1.1) and @tootallnate/once (2.0.0 → 2.0.1) within their existing parent ranges. No overrides were added.

The parse-server upgrade also moves @parse/push-adapter (8.4.0 → 8.5.5), parse (8.5.0 → 8.6.2), ws (→ 8.21.3), express-rate-limit (8.3.1 → 8.7.0), follow-redirects (1.15.11 → 1.16.0) and their subtrees (e.g. firebase-admin 13.9.0, @google-cloud/storage 7.22.0, google-auth-library 10.9.1). The lock file diff is limited to these packages and their dependencies.

CI installs parse-server@8 / parse-server@9 at job time, so the Parse Server 9 jobs already test against 9.10.1.

Changes

Breaking Changes

None for this repository. fast-xml-parser 5.7.0 tightens entity handling as part of its security fix (see above); its only consumer here parses entity-free GCS responses in a code path this repository does not use.

Code Changes Required

None. The upgrade is a drop-in replacement (manifest and lock file only).

Tasks

No tasks apply; this PR only updates development dependencies in the manifest and lock file.

…o 11.20.0, tar from 7.5.16 to 7.5.22, fast-xml-parser from 5.5.8 to 5.11.1, uuid from 11.1.0 to 11.1.1 and @tootallnate/once from 2.0.0 to 2.0.1
@parse-github-assistant

Copy link
Copy Markdown

🚀 Thanks for opening this pull request! We appreciate your effort in improving the project. Please let us know once your pull request is ready for review.

Tip

  • Keep pull requests small. Large PRs will be rejected. Break complex features into smaller, incremental PRs.
  • Use Test Driven Development. Write failing tests before implementing functionality. Ensure tests pass.
  • Group code into logical blocks. Add a short comment before each block to explain its purpose.
  • We offer conceptual guidance. Coding is up to you. PRs must be merge-ready for human review.
  • Our review focuses on concept, not quality. PRs with code issues will be rejected. Use an AI agent.
  • Human review time is precious. Avoid review ping-pong. Inspect and test your AI-generated code.

Note

Please respond to review comments from AI agents just like you would to comments from a human reviewer. Let the reviewer resolve their own comments, unless they have reviewed and accepted your commit, or agreed with your explanation for why the feedback was incorrect.

Caution

Pull requests must be written using an AI agent with human supervision. Pull requests written entirely by a human will likely be rejected, because of lower code quality, higher review effort and the higher risk of introducing bugs. Please note that AI review comments on this pull request alone do not satisfy this requirement. Our CI and AI review are safeguards, not development tools. If many issues are flagged, rethink your development approach. Invest more effort in planning and design rather than using review cycles to fix low-quality code.

@coderabbitai

coderabbitai Bot commented Sep 26, 2026

Copy link
Copy Markdown

Warning

Review limit reached

  • Ask an admin to enable usage-based reviews

Open in CodeRabbit

Reviews can continue after your included limit without a manual trigger. An admin must approve usage-based billing.

Next included review available in 25 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available. Your 65 included PR review attempts over the past 7 days set your current allowance at 1 review per hour.

The included review limit has been reached and this organization has disabled usage-based review continuation. Wait for reviews to reset or ask a billing admin to change After included review limits.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Essentials

Run ID: 15d9ae05-0fd0-4a6e-aa2e-dc7366a09818

📥 Commits

Reviewing files that changed from the base of the PR and between 7ec3959 and 8364a3f.

📒 Files selected for processing (2)
  • package-lock.json
  • package.json

Comment @coderabbitai help to get the list of available commands.

@mtrezza mtrezza changed the title refactor: Bump parse-server from 9.10.0 to 9.10.1, npm from 11.17.0 to 11.20.0, tar from 7.5.16 to 7.5.22, fast-xml-parser from 5.5.8 to 5.11.1, uuid from 11.1.0 to 11.1.1 and @tootallnate/once from 2.0.0 to 2.0.1 refactor: Bump parse-server to 9.10.1, npm to 11.20.0, tar to 7.5.22, fast-xml-parser to 5.11.1, uuid to 11.1.1 and @tootallnate/once to 2.0.1 Sep 26, 2026
@mtrezza
mtrezza merged commit d6f6d2a into parse-community:master Sep 26, 2026
11 checks passed
@mtrezza
mtrezza deleted the refactor/parse-server-9.10.1 branch September 26, 2026 01:54
@codecov

codecov Bot commented Sep 26, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 97.77%. Comparing base (7ec3959) to head (8364a3f).
⚠️ Report is 1 commits behind head on master.

Additional details and impacted files
@@           Coverage Diff           @@
##           master     #617   +/-   ##
=======================================
  Coverage   97.77%   97.77%           
=======================================
  Files           2        2           
  Lines         225      225           
=======================================
  Hits          220      220           
  Misses          5        5           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant