Skip to content

build(deps): bump the graphql group across 1 directory with 2 updates#2878

Open
dependabot[bot] wants to merge 1 commit into
trunkfrom
dependabot/npm_and_yarn/graphql-0221b342ab
Open

build(deps): bump the graphql group across 1 directory with 2 updates#2878
dependabot[bot] wants to merge 1 commit into
trunkfrom
dependabot/npm_and_yarn/graphql-0221b342ab

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 9, 2026

Copy link
Copy Markdown
Contributor

Bumps the graphql group with 2 updates in the / directory: @apollo/client and graphql.

Updates @apollo/client from 4.2.2 to 4.2.3

Release notes

Sourced from @​apollo/client's releases.

@​apollo/client@​4.2.3

Patch Changes

Changelog

Sourced from @​apollo/client's changelog.

4.2.3

Patch Changes

Commits

Updates graphql from 16.14.1 to 16.14.2

Release notes

Sourced from graphql's releases.

v16.14.2 (2026-06-09)

Docs 📝

Polish 💅

Committers: 2

Commits
  • dca5b4d chore(release): v16.14.2
  • 01f8503 docs: correct extension field comments - v16 (#4801)
  • b8087c3 docs: add Node.js tracing channels guide (#4788)
  • ec23905 docs: refresh website with broader execution/tracing update (#4794)
  • f8680fa docs: remove extra asterisks from single line jsdoc comments (#4792)
  • 6256444 docs: overhaul index and update/add additional migration guides (#4789)
  • e7e90ef docs: update documentation for v17 release candidate (#4787)
  • cae62e3 docs: restore missing docs
  • 35f1ff9 docs: increase spacing in embedded TOC
  • 56c868e docs: fix deprecated markings
  • Additional commits viewable in compare view

@github-actions

github-actions Bot commented Jun 9, 2026

Copy link
Copy Markdown
Contributor

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails
npm/@apollo/client 4.2.3 🟢 6.7
Details
CheckScoreReason
Code-Review🟢 4Found 9/21 approved changesets -- score normalized to 4
Maintained🟢 1030 commit(s) and 25 issue activity found in the last 90 days -- score normalized to 10
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Packaging⚠️ -1packaging workflow not detected
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Token-Permissions🟢 6detected GitHub workflow tokens with excessive permissions
Binary-Artifacts🟢 10no binaries found in the repo
Pinned-Dependencies🟢 8dependency not pinned by hash detected -- score normalized to 8
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection🟢 3branch protection is not maximal on development and all release branches
Security-Policy🟢 10security policy file detected
Fuzzing⚠️ 0project is not fuzzed
SAST🟢 4SAST tool is not run on all commits -- score normalized to 4
npm/graphql 16.14.2 🟢 7.2
Details
CheckScoreReason
Code-Review⚠️ 0Found 0/12 approved changesets -- score normalized to 0
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Maintained🟢 1030 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Packaging⚠️ -1packaging workflow not detected
Binary-Artifacts🟢 10no binaries found in the repo
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
Pinned-Dependencies🟢 4dependency not pinned by hash detected -- score normalized to 4
License🟢 10license file detected
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Signed-Releases⚠️ -1no releases found
Security-Policy🟢 10security policy file detected
Fuzzing⚠️ 0project is not fuzzed
SAST🟢 10SAST tool is run on all commits

Scanned Files

  • package.json

@sjinks

sjinks commented Jun 9, 2026

Copy link
Copy Markdown
Member

@dependabot rebase

@dependabot dependabot Bot changed the title build(deps): bump the graphql group with 2 updates build(deps): bump the graphql group across 1 directory with 2 updates Jun 9, 2026
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/graphql-0221b342ab branch from 1247f2f to 526b44e Compare June 9, 2026 19:31
Bumps the graphql group with 2 updates in the / directory: [@apollo/client](https://github.com/apollographql/apollo-client) and [graphql](https://github.com/graphql/graphql-js).


Updates `@apollo/client` from 4.2.2 to 4.2.3
- [Release notes](https://github.com/apollographql/apollo-client/releases)
- [Changelog](https://github.com/apollographql/apollo-client/blob/main/CHANGELOG.md)
- [Commits](https://github.com/apollographql/apollo-client/compare/@apollo/client@4.2.2...@apollo/client@4.2.3)

Updates `graphql` from 16.14.1 to 16.14.2
- [Release notes](https://github.com/graphql/graphql-js/releases)
- [Commits](graphql/graphql-js@v16.14.1...v16.14.2)

---
updated-dependencies:
- dependency-name: "@apollo/client"
  dependency-version: 4.2.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: graphql
- dependency-name: graphql
  dependency-version: 16.14.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: graphql
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/graphql-0221b342ab branch from 526b44e to 1a807da Compare June 10, 2026 12:23
@sonarqubecloud

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant