Skip to content

build(deps): bump graphql-yoga from 5.22.0 to 5.24.1 - #871

Merged
github-actions[bot] merged 1 commit into
mainfrom
dependabot/npm_and_yarn/graphql-yoga-5.24.1
Sep 25, 2026
Merged

github-actions[bot] merged 1 commit into
mainfrom
dependabot/npm_and_yarn/graphql-yoga-5.24.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 25, 2026

Copy link
Copy Markdown
Contributor

Bumps graphql-yoga from 5.22.0 to 5.24.1.

Changelog

Sourced from graphql-yoga's changelog.

5.24.1

Patch Changes

  • #4586 c6a9aa4 Thanks @鈥媋rdatan! - Fixes the issue thrown in the plugin that limits the incoming request body's size, when the incoming Request object is not the instance of the fetchAPI.Request which is usually the ponyfill implementation from @whatwg-node/node-fetch.

    This will be fixed in the following breaking release in @whatwg-node/node-fetch but in order to unblock the current users of GraphQL Yoga, a small normalization layer has been added to the plugin as a temporary workaround.

    Since the native Request.body is a native ReadableStream, that doesn't support other TransformStream implementation to its pipeThrough method, the limiting implementation didn't work properly.

    When the user ran Yoga within Next.js that uses the native Request object, it threw a TypeError which causes a cryptic 500 Internal Server Error for Next.js users.

    This workaround checks whether the incoming Request's body object is an instance of the native ReadableStream and applies the appropriate TransformStream implementation to ensure the request body size limiting works correctly.

5.24.0

Minor Changes

  • #4580 3763aca Thanks @鈥媏goodwinx! - Limit the size of incoming HTTP request bodies by default to protect against denial-of-service attacks from oversized payloads.

    Requests whose Content-Length exceeds the limit are rejected with an HTTP 413 response before the body is read, and the limit is also enforced while streaming the body so that requests with a missing, incorrect, or chunked-transfer-encoded body are covered too.

    The default limit is 25 MB. Configure it with the new maxRequestBodySize option, or set it to false to disable the limit (not recommended unless an upstream reverse proxy already enforces one):

    createYoga({
      // Allow bodies up to 25 MB
      maxRequestBodySize: 25_000_000
    })

    Also return an HTTP 400 response for malformed multipart/form-data requests (e.g. a missing or

... (truncated)

Commits
  • 9ce0b19 chore(release): update monorepo packages versions (#4587)
  • c6a9aa4 fix(use-limit-request-body-size): pick the right TransformStream (#4586)
  • 1e996e0 Merge commit from fork
  • 73fe2a0 chore(release): update monorepo packages versions (#4581)
  • ad15071 fix: fix changeset (#4582)
  • 7bff35c chore: update package.json files to contain homepage and bugs.url (#4577)
  • 3763aca fix(http): prevent unbounded http request body parsing DoS (#4580)
  • 6e0932f chore(release): update monorepo packages versions (#4570)
  • d3b4164 fix: keep SSE keep-alive pings during stream backpressure (#4573)
  • c80f43c Reduce website/ to the docs content (#4569)
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [graphql-yoga](https://github.com/graphql-hive/graphql-yoga/tree/HEAD/packages/graphql-yoga) from 5.22.0 to 5.24.1.
- [Release notes](https://github.com/graphql-hive/graphql-yoga/releases)
- [Changelog](https://github.com/graphql-hive/graphql-yoga/blob/main/packages/graphql-yoga/CHANGELOG.md)
- [Commits](https://github.com/graphql-hive/graphql-yoga/commits/graphql-yoga@5.24.1/packages/graphql-yoga)

---
updated-dependencies:
- dependency-name: graphql-yoga
  dependency-version: 5.24.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 25, 2026
@github-actions
github-actions Bot enabled auto-merge (squash) September 25, 2026 07:05
@github-actions
github-actions Bot merged commit 6b49148 into main Sep 25, 2026
4 checks passed
@github-actions
github-actions Bot deleted the dependabot/npm_and_yarn/graphql-yoga-5.24.1 branch September 25, 2026 07:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants