Skip to content

refactor: Bump @graphql-tools/utils, @graphql-tools/schema and @graphql-tools/merge - #10760

Open
dependabot[bot] wants to merge 1 commit into
alphafrom
dependabot/npm_and_yarn/multi-88f7087ad3
Open

dependabot[bot] wants to merge 1 commit into
alphafrom
dependabot/npm_and_yarn/multi-88f7087ad3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Bumps @graphql-tools/utils, @graphql-tools/schema and @graphql-tools/merge. These dependencies needed to be updated together.
Updates @graphql-tools/utils from 11.2.2 to 12.0.3

Changelog

Sourced from @​graphql-tools/utils's changelog.

12.0.3

Patch Changes

  • #8482 19f5b33 Thanks @​ardatan! - Compare incremental path keys to __proto__ at the property access in setObjectKeyPath, in addition to the existing isSafeObjectKey check.

12.0.2

Patch Changes

  • #8456 b1fbba2 Thanks @​renovate! - dependencies updates:

  • #8467 20d36a5 Thanks @​ardatan! - Fix prototype pollution in mergeIncrementalResult

    Path segments are now rejected unless they are primitive strings or numbers, and keys named __proto__, constructor or prototype are still blocked. Previously a non-primitive segment such as ["__proto__"] bypassed the string equality guard and was coerced into a write on Object.prototype.

    Also exports shared isSafeObjectKey / isDangerousObjectKey helpers used by this path walker and other package call sites. @graphql-tools/merge and @graphql-tools/mock are patched so they ship with the new imports; updateInternalDependencies raises their utils floor when 12.0.2 is versioned.

12.0.1

Patch Changes

  • #8368 60db079 Thanks @​ardatan! - Omit mutation/subscription from printSchemaWithDirectives when those root types are no longer present on the schema (e.g. after pruneSchema).

  • #8366 57e316d Thanks @​ardatan! - Allow % in paths checked by isValidPath (e.g. directories from URL-encoded repo names).

  • #8370 1c1c5a0 Thanks @​ardatan! - Clean up observableToAsyncIterable queues and unsubscribe when the observable completes, so iterators do not retain references after done. Fixes leak detection flakes related to #8057.

  • #8370 1c1c5a0 Thanks @​ardatan! - Prefer runtime description values over stale astNode descriptions in printSchemaWithDirectives / getDescriptionNode. Fixes #5508.

  • #8423 0b9529f Thanks @​enisdenjo! - Fix prototype pollution in mergeDeep

    Source keys named __proto__, constructor or prototype are now skipped at every recursion level, and the check for an existing key uses hasOwnProperty instead of in, so inherited properties are never used as merge targets.

    Previously, merging untrusted data such as JSON.parse('{"constructor":{"__proto__":{"call":"x"}}}') could reach and overwrite properties on Object.prototype or Function.prototype.

12.0.0

Major Changes

  • #8346 2273c21 Thanks @​ardatan! - This release adds GraphQL v17 support and aligns the existing executor implementation with the latest GraphQL v17 API changes. The following changes are included:

    • getAsyncHelpers is now available on GraphQLResolveInfo. Its track method is used whenever waitUntil is available, as in Yoga's Explicit Resource Management

... (truncated)

Commits
  • 944121e Upcoming Release Changes (#8483)
  • 19f5b33 fix(utils): compare path keys to proto at the property access (#8482)
  • 3a43b4b Upcoming Release Changes (#8460)
  • 20d36a5 fix(utils): block prototype pollution in mergeIncrementalResult paths
  • b1fbba2 fix(deps): update dependency @​whatwg-node/promise-helpers to v2 (#8456)
  • 77bbaec build(deps): bump the actions-deps group with 7 updates (#8434)
  • 861011f build(deps): bump the actions-deps group with 6 updates (#8432)
  • 8b9b7df chore(release): update monorepo packages versions (#8365)
  • 0b9529f Fix prototype pollution in mergeDeep (#8423)
  • 23ca392 chore(deps): update dependency graphql-scalars to v2 (#8385)
  • Additional commits viewable in compare view

Updates @graphql-tools/schema from 10.0.31 to 10.1.3

Changelog

Sourced from @​graphql-tools/schema's changelog.

10.1.3

Patch Changes

  • Updated dependencies [19f5b33]:
    • @​graphql-tools/utils@​12.0.3
    • @​graphql-tools/merge@​9.2.6

10.1.2

Patch Changes

10.1.1

Patch Changes

10.1.0

Minor Changes

  • #8346 2273c21 Thanks @​ardatan! - This release adds GraphQL v17 support and aligns the existing executor implementation with the latest GraphQL v17 API changes. The following changes are included:

    • getAsyncHelpers is now available on GraphQLResolveInfo. Its track method is used whenever waitUntil is available, as in Yoga's Explicit Resource Management
    • getAbortSignal is now available on GraphQLResolveInfo, matching behavior that was already available in this executor implementation, as in Yoga's Execution Cancellation
    • GraphQLResolveInfo automatically aligns variableValues according to the GraphQL version for better compatibility. In GraphQL v17 and above, variableValues follows the wrapped shape ({ coerced, sources }) expected by GraphQL APIs. In GraphQL v16 and below, variableValues remains a flat map as in previous versions.
    • If your custom scalar resolvers define __serialize and __parseValue, they are automatically mapped to coerceOutputValue and coerceInputValue in GraphQL v17.
    • BREAKING: @graphql-tools/executor's getVariableValues now returns { variableValues } on success, where variableValues is a VariableValues object ({ coerced, sources }). On failure, it returns { errors }.
    • BREAKING: collectFields, shouldIncludeNode, getDeferValues, and collectSubFields now

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​graphql-tools/schema since your current version.


Updates @graphql-tools/merge from 9.1.7 to 9.2.6

Changelog

Sourced from @​graphql-tools/merge's changelog.

9.2.6

Patch Changes

  • Updated dependencies [19f5b33]:
    • @​graphql-tools/utils@​12.0.3

9.2.5

Patch Changes

  • #8467 20d36a5 Thanks @​ardatan! - Fix prototype pollution in mergeIncrementalResult

    Path segments are now rejected unless they are primitive strings or numbers, and keys named __proto__, constructor or prototype are still blocked. Previously a non-primitive segment such as ["__proto__"] bypassed the string equality guard and was coerced into a write on Object.prototype.

    Also exports shared isSafeObjectKey / isDangerousObjectKey helpers used by this path walker and other package call sites. @graphql-tools/merge and @graphql-tools/mock are patched so they ship with the new imports; updateInternalDependencies raises their utils floor when 12.0.2 is versioned.

  • Updated dependencies [b1fbba2, 20d36a5]:

    • @​graphql-tools/utils@​12.0.2

9.2.4

Patch Changes

  • #8367 2262087 Thanks @​ardatan! - Preserve multiple applications of the same directive when extending a type even if the repeatable directive definition is not present in the merge inputs.

  • #8394 5523c4b Thanks @​bengry! - Write the synthesized default operation types back onto the schema definition node, so merging a schema extension that has no operation block (federation SDL, for example) still produces a query root on graphql@17.

  • Updated dependencies [60db079, 57e316d, 1c1c5a0, 1c1c5a0, 0b9529f]:

    • @​graphql-tools/utils@​12.0.1

9.2.3

Patch Changes

  • #8349 7fe0319 Thanks @​aarne! - Pass the collected directive definitions to mergeSchemaDefs so repeatable directives on schema definitions and extend schema extensions (e.g. a repeatable @link) are kept as separate instances instead of being collapsed and having their arguments merged.

  • Updated dependencies [2273c21]:

    • @​graphql-tools/utils@​12.0.0

9.2.2

Patch Changes

... (truncated)

Commits
  • 944121e Upcoming Release Changes (#8483)
  • 3a43b4b Upcoming Release Changes (#8460)
  • 20d36a5 fix(utils): block prototype pollution in mergeIncrementalResult paths
  • 77bbaec build(deps): bump the actions-deps group with 7 updates (#8434)
  • 861011f build(deps): bump the actions-deps group with 6 updates (#8432)
  • 8b9b7df chore(release): update monorepo packages versions (#8365)
  • 5523c4b fix(merge): don't drop the synthesized operation types on graphql 17 (#8394)
  • 2262087 fix(merge): preserve multi-instance directives when extending types (#8367)
  • 0f00a44 chore: use HTTPS git URLs for package repository metadata (#8376)
  • 9feabd9 chore(release): update monorepo packages versions (#8327)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​graphql-tools/merge since your current version.


@dependabot dependabot Bot added dependencies Bot label; pull requests that updates a dependency file javascript Pull requests that update javascript code labels Oct 7, 2026
@coderabbitai

coderabbitai Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 2f27e713-e892-46f4-8346-8371740cf9ae

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@codecov

codecov Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 93.99%. Comparing base (bee4082) to head (4bfc1ff).
⚠️ Report is 1 commits behind head on alpha.

Additional details and impacted files
@@           Coverage Diff           @@
##            alpha   #10760   +/-   ##
=======================================
  Coverage   93.99%   93.99%           
=======================================
  Files         193      193           
  Lines       17126    17126           
  Branches      259      259           
=======================================
  Hits        16098    16098           
  Misses       1006     1006           
  Partials       22       22           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/multi-88f7087ad3 branch 5 times, most recently from e728682 to cbdbc87 Compare October 9, 2026 10:07
…ql-tools/merge

Bumps [@graphql-tools/utils](https://github.com/ardatan/graphql-tools/tree/HEAD/packages/utils), [@graphql-tools/schema](https://github.com/ardatan/graphql-tools/tree/HEAD/packages/schema) and [@graphql-tools/merge](https://github.com/ardatan/graphql-tools/tree/HEAD/packages/merge). These dependencies needed to be updated together.

Updates `@graphql-tools/utils` from 11.2.2 to 12.0.3
- [Release notes](https://github.com/ardatan/graphql-tools/releases)
- [Changelog](https://github.com/ardatan/graphql-tools/blob/master/packages/utils/CHANGELOG.md)
- [Commits](https://github.com/ardatan/graphql-tools/commits/@graphql-tools/utils@12.0.3/packages/utils)

Updates `@graphql-tools/schema` from 10.0.31 to 10.1.3
- [Release notes](https://github.com/ardatan/graphql-tools/releases)
- [Changelog](https://github.com/ardatan/graphql-tools/blob/master/packages/schema/CHANGELOG.md)
- [Commits](https://github.com/ardatan/graphql-tools/commits/@graphql-tools/schema@10.1.3/packages/schema)

Updates `@graphql-tools/merge` from 9.1.7 to 9.2.6
- [Release notes](https://github.com/ardatan/graphql-tools/releases)
- [Changelog](https://github.com/ardatan/graphql-tools/blob/master/packages/merge/CHANGELOG.md)
- [Commits](https://github.com/ardatan/graphql-tools/commits/@graphql-tools/merge@9.2.6/packages/merge)

---
updated-dependencies:
- dependency-name: "@graphql-tools/merge"
  dependency-version: 9.2.6
  dependency-type: direct:production
- dependency-name: "@graphql-tools/schema"
  dependency-version: 10.1.3
  dependency-type: direct:production
- dependency-name: "@graphql-tools/utils"
  dependency-version: 12.0.3
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/multi-88f7087ad3 branch from cbdbc87 to 4bfc1ff Compare October 10, 2026 02:04

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Bot label; pull requests that updates a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants