Skip to content

fix(deps): update dependency graphql-yoga to v5.24.1 - #4649

Merged
lowsky merged 1 commit into
mainfrom
renovate/graphql-yoga-5.x
Sep 24, 2026
Merged

lowsky merged 1 commit into
mainfrom
renovate/graphql-yoga-5.x

Conversation

@lowsky

@lowsky lowsky commented Sep 17, 2026

Copy link
Copy Markdown
Owner

This PR contains the following updates:

Package Change Age Confidence
graphql-yoga (source) 5.23.0 → 5.24.1 age confidence

Release Notes

graphql-hive/graphql-yoga (graphql-yoga)

v5.24.1

Compare Source

Patch Changes
  • #​4586
    c6a9aa4
    Thanks @​ardatan! - Fixes the issue thrown in the plugin that limits
    the incoming request body's size, when the incoming Request object is not the instance of the
    fetchAPI.Request which is usually the ponyfill implementation from @whatwg-node/node-fetch.

    This will be fixed in the following breaking release in @whatwg-node/node-fetch but in order to
    unblock the current users of GraphQL Yoga, a small normalization layer has been added to the
    plugin as a temporary workaround.

    Since the native Request.body is a native ReadableStream, that doesn't support other
    TransformStream implementation to its pipeThrough method, the limiting implementation didn't
    work properly.

    When the user ran Yoga within Next.js that uses the native Request object, it threw a
    TypeError which causes a cryptic 500 Internal Server Error for Next.js users.

    This workaround checks whether the incoming Request's body object is an instance of the native
    ReadableStream and applies the appropriate TransformStream implementation to ensure the
    request body size limiting works correctly.

v5.24.0

Compare Source

Minor Changes
  • #​4580
    3763aca
    Thanks @​egoodwinx! - Limit the size of incoming HTTP request
    bodies by default to protect against denial-of-service attacks from oversized payloads.

    Requests whose Content-Length exceeds the limit are rejected with an HTTP 413 response before
    the body is read, and the limit is also enforced while streaming the body so that requests with a
    missing, incorrect, or chunked-transfer-encoded body are covered too.

    The default limit is 25 MB. Configure it with the new maxRequestBodySize option, or set it to
    false to disable the limit (not recommended unless an upstream reverse proxy already enforces
    one):

    createYoga({
      // Allow bodies up to 25 MB
      maxRequestBodySize: 25_000_000
    })

    Also return an HTTP 400 response for malformed multipart/form-data requests (e.g. a missing or
    invalid boundary), instead of masking the parse error as a generic 500 Internal Server Error.

Patch Changes

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Never, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@lowsky
lowsky enabled auto-merge (squash) September 17, 2026 18:10
@vercel

vercel Bot commented Sep 17, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
coolboard Ready Ready Preview Sep 24, 2026 6:53pm UTC

@coderabbitai

coderabbitai Bot commented Sep 17, 2026 •

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: b63f47b2-031f-48b7-bc76-608823ebbbac


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@codacy-production

Copy link
Copy Markdown

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

🟢 Metrics 0 complexity · 0 duplication

Metric Results
Complexity 0
Duplication 0

View in Codacy

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

@cypress

cypress Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

coolboard    Run #414

Run Properties:  status check passed Passed #414  •  git commit 1b72359be1: fix(deps): update dependency graphql-yoga to v5.24.1
Project coolboard
Branch Review renovate/graphql-yoga-5.x
Run status status check passed Passed #414
Run duration 00m 34s
Commit git commit 1b72359be1: fix(deps): update dependency graphql-yoga to v5.24.1
Committer Renovate
View all properties for this run ↗︎

Test results
Tests that failed  Failures 0
Tests that were flaky  Flaky 0
Tests that did not run due to a developer annotating a test with .skip  Pending 0
Tests that did not run due to a failure in a mocha hook  Skipped 0
Tests that passed  Passing 7
⚠️ You've recorded test results over your free plan limit.
Upgrade your plan to view test results.
View all changes introduced in this branch ↗︎

@lowsky
lowsky force-pushed the renovate/graphql-yoga-5.x branch from 10d74be to 1b72359 Compare September 24, 2026 18:47
@lowsky
lowsky merged commit c36b478 into main Sep 24, 2026
8 checks passed
@lowsky
lowsky deleted the renovate/graphql-yoga-5.x branch September 24, 2026 18:55

This branch was successfully deployed

1 active deployment
Preview — 1b72359b Deployed Sep 24, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants