Skip to content

[Vulnerabilities] Upgrade @graphql-codegen packages and @apollo/client to fix vulnerabilities#178

Merged
juanmrad merged 1 commit intovulnerability-patch-upgradesfrom
upgrade-graphql-codegen-and-apollo-vulnerabilities
Apr 6, 2026
Merged

[Vulnerabilities] Upgrade @graphql-codegen packages and @apollo/client to fix vulnerabilities#178
juanmrad merged 1 commit intovulnerability-patch-upgradesfrom
upgrade-graphql-codegen-and-apollo-vulnerabilities

Conversation

@juanmrad
Copy link
Copy Markdown
Member

@juanmrad juanmrad commented Apr 4, 2026

Context & Requests for Reviewers

Upgrade all @graphql-codegen/* packages to latest stable versions, resolving 11 of 13 root Dependabot alerts. This cleans up alerts in root dir.
Remaining 2 alerts are lodash pinned by upstream @graphql-codegen/plugin-helpers@6.2.0; a fix removing lodash is already in their latest alpha and should land in the next stable release

Copy link
Copy Markdown
Contributor

@vinaysrao1 vinaysrao1 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nicely done. I had to do a lot of googling and clauding to understand the changes.

@juanmrad juanmrad merged commit 4064f06 into vulnerability-patch-upgrades Apr 6, 2026
8 checks passed
@juanmrad juanmrad deleted the upgrade-graphql-codegen-and-apollo-vulnerabilities branch April 6, 2026 04:05
juanmrad added a commit that referenced this pull request Apr 6, 2026
* [Vulnerability][Patches] Apply patch to vulnerable dependencies

* [Vulnerabilities] Upgrade @graphql-codegen packages and @apollo/client to fix vulnerabilities (#178)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants