Skip to content

[pull] main from graphql:main - #219

Merged
pull[bot] merged 15 commits into
SimenB:mainfrom
graphql:main
Sep 13, 2026
Merged

pull[bot] merged 15 commits into
SimenB:mainfrom
graphql:main

Conversation

@pull

@pull pull Bot commented Sep 13, 2026 •

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

dependabot Bot and others added 15 commits September 12, 2026 21:34
`@babel/helper-string-parser` has no source, configuration, build, or
test consumer (`git grep -n "@babel/helper-string-parser" --
":!pnpm-lock.yaml"` only finds the manifest declaration), so this
removes the stale dev dependency instead of upgrading it.

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Trevor Scheer <trevor.scheer@gmail.com>
The two Webpack examples use the same CLI/server pair, so updating them
separately leaves their peer ranges inconsistent. This groups
`webpack-cli` v7 and `webpack-dev-server` v6, updates
`webpack-bundle-analyzer` to a compatible release, and removes
`@webpack-cli/serve` because CLI v7 provides the `serve` command
directly.

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Both consumers use `concurrently` only through its CLI, and their
existing command syntax remains supported. This updates the shared dev
tool to v10; its Node 22+ requirement is compatible with this repo’s
Node 24 toolchain.

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Trevor Scheer <trevor.scheer@gmail.com>
`cypress` is only used for GraphiQL’s end-to-end suite. This updates the
dev dependency to v16; the existing config and all 59 browser tests
continue to work unchanged.

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Trevor Scheer <trevor.scheer@gmail.com>
`express` is confined to GraphiQL’s end-to-end test server. This updates
it to v5 and removes the unused root `@types/express` declaration; the
server starts normally and all 59 Cypress tests pass.

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Trevor Scheer <trevor.scheer@gmail.com>
This groups the shared extension tooling updates: `@vscode/vsce` v3 and
`esbuild` 0.28. VSCE v3 rejects combining a package `files` allowlist
with `.vscodeignore`, so the syntax extension now relies on its existing
allowlist alone. All three VSIX packages and both extension bundles
build successfully.

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Trevor Scheer <trevor.scheer@gmail.com>
This groups the Vite 8 and React Router 8 updates across the examples
and shared build tooling. Vite 8’s UMD handling now uses
`esmExternalRequirePlugin`, and the GraphiQL UMD build keeps its React
18 JSX runtime compatibility while the workspace and examples use React
19.

The VS Code extension bundlers also externalize Vue compiler’s optional
`ejs` import so clean installs continue to bundle under `esbuild` 0.28.

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Trevor Scheer <trevor.scheer@gmail.com>
This groups the low-lift major updates for `rimraf`, `execa`, and
`eslint-plugin-react-hooks`.

It migrates the `rimraf` sync import, enables the v7 React Compiler lint
rules with two targeted suppressions for intentional effect-driven
state, and keeps the Monaco test on `execa` v10. `mkdirp` is replaced
with Node’s recursive `mkdirSync`; its unused server declaration,
`@types/mkdirp`, `@types/rimraf`, and a redundant CodeMirror `rimraf`
declaration are removed.

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Trevor Scheer <trevor.scheer@gmail.com>
`graphql-config` already owns the `cosmiconfig` dependency used by the
VS Code execution extension. This removes the unused direct declaration
instead of introducing a second major version.

`cosmiconfig-toml-loader` stays because it satisfies `graphql-config`’s
optional peer and supports the extension’s `.toml` activation patterns.

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Trevor Scheer <trevor.scheer@gmail.com>
Updates `markdown-it` to v15 and moves the workspace override with it so
the new version is actually installed. The existing default import and
rendering setup remain compatible; the focused `@graphiql/react` build
and test suite pass.

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Trevor Scheer <trevor.scheer@gmail.com>
Updates `framer-motion` to v13. The `Reorder` API used by the tabs
component remains compatible, and the focused `@graphiql/react` build
and test suite pass without source changes.

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Trevor Scheer <trevor.scheer@gmail.com>
Updates `@babel/parser` and `@babel/types` to v8 together. Parser
plugins for syntax that Babel 8 enables by default are removed because
those plugin names are no longer accepted.\n\nThe language-server build
and all 117 focused tests pass.

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Trevor Scheer <trevor.scheer@gmail.com>
Updates the direct `vscode-jsonrpc` dependency to v9. The logger
interface used by the language server remains compatible; the server
build and all 117 focused tests pass without source changes.

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Trevor Scheer <trevor.scheer@gmail.com>
Updates `lru-cache` to v11 and `glob` to v13 together in
`graphql-language-service-server`. The file discovery path now uses the
current promise API and typed path metadata instead of the removed event
emitter and `statCache` APIs.\n\nThe server build and all 117 focused
tests pass.

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Trevor Scheer <trevor.scheer@gmail.com>
Updates `get-value` to v4. The package exposes a named runtime export
but still publishes default-only TypeScript metadata, so the existing
typed default import is retained with a narrow lint exception.\n\nThe
full lint pass plus the focused `@graphiql/react` build and 26 tests
pass.

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Trevor Scheer <trevor.scheer@gmail.com>
@pull pull Bot locked and limited conversation to collaborators Sep 13, 2026
@pull pull Bot added the ⤵️ pull label Sep 13, 2026
@pull
pull Bot merged commit d7093c3 into SimenB:main Sep 13, 2026
@pull
pull Bot deployed to deploy September 13, 2026 08:12 Active

This branch was successfully deployed

1 active deployment
deploy — d7093c36 Deployed Sep 13, 2026 by pull[bot] via Release #112
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants