Repository navigation
refactor: Bump parse-server from 9.7.0 to 9.9.0 - #3401
Conversation
|
🚀 Thanks for opening this pull request! We appreciate your effort in improving the project. Please let us know once your pull request is ready for review. Tip
Note Please respond to review comments from AI agents just like you would to comments from a human reviewer. Let the reviewer resolve their own comments, unless they have reviewed and accepted your commit, or agreed with your explanation for why the feedback was incorrect. Caution Pull requests must be written using an AI agent with human supervision. Pull requests written entirely by a human will likely be rejected, because of lower code quality, higher review effort and the higher risk of introducing bugs. Please note that AI review comments on this pull request alone do not satisfy this requirement. Our CI and AI review are safeguards, not development tools. If many issues are flagged, rethink your development approach. Invest more effort in planning and design rather than using review cycles to fix low-quality code. |
|
@coderabbitai review |
✅ Action performedReview finished.
|
|
Important Review skippedNo new commits to review since the last review. ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
📝 WalkthroughWalkthroughUpdates ChangesDependency refresh
Estimated code review effort: 2 (Simple) | ~10 minutes Possibly related PRs
Suggested reviewers: Caution Pre-merge checks failedPlease resolve all errors before merging. Addressing warnings is optional.
❌ Failed checks (2 errors, 1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 2
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@package-lock.json`:
- Line 25197: Align the Node version configuration with parse-server@9.9.0:
update the CI matrix in ci.yml from 22.12.0 and 24.1.0 to supported versions,
update the root engines gate to match, and replace the stale .nvmrc value of
8.11 with a supported Node version.
In `@package.json`:
- Line 125: Update the parse-server dependency from 9.9.0 to a patched version
covering all applicable advisories, then regenerate the lockfile and verify the
browser-control harness still launches successfully. If no patched upgrade is
available, document strict service isolation and obtain an explicit security
exception before merging.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro
Run ID: 37a670fe-d422-449a-a447-dce4fbe713a6
📒 Files selected for processing (2)
package-lock.jsonpackage.json
| }, | ||
| "engines": { | ||
| "node": ">=20.19.0 <21.0.0 || >=22.12.0 <23.0.0 || >=24.11.0 <25.0.0" | ||
| "node": ">=20.19.0 <21.0.0 || >=22.13.0 <23.0.0 || >=24.11.0 <25.0.0" |
There was a problem hiding this comment.
🩺 Stability & Availability | 🟡 Minor | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
#!/usr/bin/env bash
set -euo pipefail
files="$(
fd -HI -t f . |
rg '(^|/)(package\.json|package-lock\.json|\.nvmrc|\.node-version|\.tool-versions|Dockerfile.*|.*\.(yml|yaml))$' || true
)"
printf '%s\n' "$files" |
xargs -r rg -n -i 'node-version|NODE_VERSION|engines|FROM node|20\.|22\.|24\.'Repository: parse-community/parse-dashboard
Length of output: 50388
🏁 Script executed:
#!/usr/bin/env bash
set -euo pipefail
printf '%s\n' "Top-level files:"
git ls-files | sed -n '1,200p'
printf '\n%s\n' "Candidate Node/version orchestration files:"
fd -HI -t f '(\.github/workflows/.*\.ya?ml$|package\.json$|package-lock\.json$|\.nvmrc$|\.node-version$|\.tool-versions$|Dockerfile.*$|docker-compose.*\.ya?ml$)' .
printf '\n%s\n' "Node-related config snippets:"
for f in \
.github/workflows/*.yml \
.github/workflows/*.yaml \
package.json \
.nvmrc \
.node-version \
.tool-versions \
Dockerfile \
Dockerfile.* \
docker-compose.yml \
docker-compose.yaml
do
[ -f "$f" ] || continue
echo "----- $f -----"
rg -n -i 'node|npx|engines|matrix|setup-node|version' "$f" || true
doneRepository: parse-community/parse-dashboard
Length of output: 50388
🏁 Script executed:
#!/usr/bin/env bash
set -euo pipefail
for f in package.json .nvmrc Dockerfile ci/nodeEngineCheck.mjs .github/workflows/ci.yml .github/workflows/ci-automated-check-environment.yml .github/workflows/release-automated.yml .github/workflows/release-manual-docker.yml .github/workflows/release-prepare-monthly.yml docker-compose.uffizzi.yml; do
[ -f "$f" ] || continue
echo "===== $f ====="
wc -l "$f"
cat -n "$f" | sed -n '1,260p'
echo
doneRepository: parse-community/parse-dashboard
Length of output: 37422
Align the Node versions with parse-server@9.9.0
.github/workflows/ci.yml still runs 22.12.0 and 24.1.0, but parse-server@9.9.0 requires >=22.13.0 and >=24.11.0. Update the CI matrix and the root engine gate together; .nvmrc is also stale and should move off 8.11.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@package-lock.json` at line 25197, Align the Node version configuration with
parse-server@9.9.0: update the CI matrix in ci.yml from 22.12.0 and 24.1.0 to
supported versions, update the root engines gate to match, and replace the stale
.nvmrc value of 8.11 with a supported Node version.
| "marked": "17.0.5", | ||
| "mongodb-runner": "6.7.3", | ||
| "parse-server": "9.7.0", | ||
| "parse-server": "9.9.0", |
There was a problem hiding this comment.
🔒 Security & Privacy | 🟠 Major | 🏗️ Heavy lift
Do not merge the 9.9.0 pin without a patched build or security exception.
The supplied OSV results report multiple HIGH advisories for this exact version. This is not an unused fixture: the browser-control harness launches parse-server during tests. Official advisories place 9.9.0 in affected ranges for pre-authentication DoS, MFA/protected-field disclosure, GraphQL schema disclosure, and routeAllowList batch bypass. Upgrade to a build covering all applicable fixes and regenerate the lockfile; otherwise document strict service isolation and obtain an explicit exception. (github.com)
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@package.json` at line 125, Update the parse-server dependency from 9.9.0 to a
patched version covering all applicable advisories, then regenerate the lockfile
and verify the browser-control harness still launches successfully. If no
patched upgrade is available, document strict service isolation and obtain an
explicit security exception before merging.
Sources: MCP tools, Linters/SAST tools
|
🎉 This change has been released in version 9.2.1-alpha.1 |
Replacement for #3361 (Dependabot), created off current
alphaso it includes the lockfile-stability fix (#3400). Bumps theparse-serverdev dependency (used for integration tests) from 9.7.0 to 9.9.0, pinned exact, with a fully regenerated lockfile.Closes #3361
Summary by CodeRabbit