Closed
Conversation
Contributor
There was a problem hiding this comment.
Code Review
This pull request addresses security vulnerabilities in nodemailer and opentelemetry-go, fixes a schema composition error involving @inaccessible federation types, and increments the deployment version to 11.0.3. A redundant Cargo.lock entry was identified in the .gitignore file that should be removed.
| Cargo.lock | ||
| Cargo.lock | ||
| Cargo.lock | ||
| Cargo.lock |
Contributor
Contributor
🚀 Snapshot Release (
|
| Package | Version | Info |
|---|---|---|
@graphql-hive/laboratory |
0.1.4-rc-20260416110134-6d8aa2bf6564616ec1973c8cd43a0cdef7db0fe0 |
npm ↗︎ unpkg ↗︎ |
@graphql-hive/render-laboratory |
0.1.4-rc-20260416110134-6d8aa2bf6564616ec1973c8cd43a0cdef7db0fe0 |
npm ↗︎ unpkg ↗︎ |
hive |
11.0.3-rc-20260416110134-6d8aa2bf6564616ec1973c8cd43a0cdef7db0fe0 |
npm ↗︎ unpkg ↗︎ |
Contributor
|
🐋 This PR was built and pushed to the following Docker images: Targets: Platforms: Image Tag: |
a8a2f54 to
f7a74ce
Compare
0a59eef to
ed9ab34
Compare
e1525ed to
fab4b03
Compare
56fd2a5 to
7d4ef94
Compare
48b4e71 to
e3d9750
Compare
0b23e0f to
4a8bd4f
Compare
75d178b to
c46b2f2
Compare
5f2df94 to
9c6989c
Compare
2d3342f to
5706e2d
Compare
ea485b4 to
a237b4e
Compare
bc13535 to
fe06dde
Compare
2a6e534 to
d7e7025
Compare
n1ru4l
approved these changes
Apr 16, 2026
8f9ca86 to
5a85fb9
Compare
6d8aa2b to
730771f
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.
Releases
@graphql-hive/laboratory@0.1.4
Patch Changes
#7963
4a8bd4fThanks @mskorokhodov! - Implemented functionality that allows
to have multiple queries in same operation while working only with focused one (run button, query
builder)
#7892
fab4b03Thanks @mskorokhodov! - Hive Laboratory renders Hive Router
query plan if included in response extensions
@graphql-hive/render-laboratory@0.1.4
Patch Changes
#7963
4a8bd4fThanks @mskorokhodov! - Implemented functionality that allows
to have multiple queries in same operation while working only with focused one (run button, query
builder)
#7892
fab4b03Thanks @mskorokhodov! - Hive Laboratory renders Hive Router
query plan if included in response extensions
Updated dependencies
[
4a8bd4f,fab4b03]:hive@11.0.3
Patch Changes
#7993
730771fThanks @n1ru4l! - Address vulnerability
GHSA-72c6-fx6q-fr5w.
#7988
d7e7025Thanks @n1ru4l! - Address vulnerability
GHSA-247c-9743-5963.
#7961
40fd27dThanks @n1ru4l! - Update
nodemailerto address vulnerabilityGHSA-vvjj-xcjg-gr5g.
#7993
730771fThanks @n1ru4l! - Address vulnerability
GHSA-v9ww-2j6r-98q6.
#7976
ed9ab34Thanks @n1ru4l! - address vulnerability
GHSA-r4q5-vmmm-2653
#7967
9708f71Thanks @n1ru4l! - Fix schema contract composition applying
@inaccessibleon the federation typesContextArgumentandFieldValueon the supergraph SDL.This mitigates the following error in apollo-router upon processing the supergraph:
#7993
730771fThanks @n1ru4l! - Address vulnerability
GHSA-xq3m-2v4x-88gg.
#7978
9c6989cThanks @jdolle! - Add schema linting support for type extensions
#7993
730771fThanks @n1ru4l! - Address vulnerability
CVE-2026-6414.
#7988
d7e7025Thanks @n1ru4l! - Address vulnerability
GHSA-39q2-94rc-95cp.
#7980
c46b2f2Thanks @n1ru4l! - Address vulnerability
GHSA-fvcv-3m26-pcqx.
#7993
730771fThanks @n1ru4l! - Address vulnerability
CVE-2026-6410.
#7961
40fd27dThanks @n1ru4l! - Update
opentelemetry-goto address vulnerabilityCVE-2026-39883.