Skip to content

refactor: Bump parse-server from 9.7.0 to 9.9.0 - #3401

Merged
mtrezza merged 1 commit into
parse-community:alphafrom
mtrezza:refactor/parse-server-9.9.0
Jul 13, 2026
Merged

mtrezza merged 1 commit into
parse-community:alphafrom
mtrezza:refactor/parse-server-9.9.0

Conversation

@mtrezza

@mtrezza mtrezza commented Jul 13, 2026 •

Copy link
Copy Markdown
Member

Replacement for #3361 (Dependabot), created off current alpha so it includes the lockfile-stability fix (#3400). Bumps the parse-server dev dependency (used for integration tests) from 9.7.0 to 9.9.0, pinned exact, with a fully regenerated lockfile.

Closes #3361

Summary by CodeRabbit

  • Chores
    • Updated Parse Server to version 9.9.0.
    • Refreshed project dependency versions and lockfile resolutions.
    • Added and removed transitive packages as required by the updated dependency set.

@parse-github-assistant

Copy link
Copy Markdown

🚀 Thanks for opening this pull request! We appreciate your effort in improving the project. Please let us know once your pull request is ready for review.

Tip

  • Keep pull requests small. Large PRs will be rejected. Break complex features into smaller, incremental PRs.
  • Use Test Driven Development. Write failing tests before implementing functionality. Ensure tests pass.
  • Group code into logical blocks. Add a short comment before each block to explain its purpose.
  • We offer conceptual guidance. Coding is up to you. PRs must be merge-ready for human review.
  • Our review focuses on concept, not quality. PRs with code issues will be rejected. Use an AI agent.
  • Human review time is precious. Avoid review ping-pong. Inspect and test your AI-generated code.

Note

Please respond to review comments from AI agents just like you would to comments from a human reviewer. Let the reviewer resolve their own comments, unless they have reviewed and accepted your commit, or agreed with your explanation for why the feedback was incorrect.

Caution

Pull requests must be written using an AI agent with human supervision. Pull requests written entirely by a human will likely be rejected, because of lower code quality, higher review effort and the higher risk of introducing bugs. Please note that AI review comments on this pull request alone do not satisfy this requirement. Our CI and AI review are safeguards, not development tools. If many issues are flagged, rethink your development approach. Invest more effort in planning and design rather than using review cycles to fix low-quality code.

@mtrezza

mtrezza commented Jul 13, 2026

Copy link
Copy Markdown
Member Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Jul 13, 2026 •

Copy link
Copy Markdown
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@coderabbitai

coderabbitai Bot commented Jul 13, 2026 •

Copy link
Copy Markdown

Review Change Stack

Important

Review skipped

No new commits to review since the last review.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: e6c6c5cc-5474-4ad4-9b1f-ae6bff2f1aea

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

Updates parse-server from 9.7.0 to 9.9.0 and regenerates package-lock.json, refreshing Firebase, Google Cloud, GraphQL, gRPC, protobuf, XML, networking, and utility dependencies.

Changes

Dependency refresh

Layer / File(s) Summary
Parse Server upgrade
package.json, package-lock.json
Updates the parse-server development dependency and lockfile resolution to 9.9.0, including related Parse, push, Expo, and runtime package updates.
Service and protocol library refresh
package-lock.json
Refreshes Firebase, Google Cloud, authentication, logging, GraphQL, gRPC, protobuf, and UUID lock entries.
Utility and XML dependency refresh
package-lock.json
Updates utility, XML, networking, cryptography, metadata, and newly introduced transitive package entries.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

Suggested reviewers: semantic-release-bot, dependabot[bot], parseplatformorg, dblythy, cbaker6


Caution

Pre-merge checks failed

Please resolve all errors before merging. Addressing warnings is optional.

  • Ignore

❌ Failed checks (2 errors, 1 warning)

Check name Status Explanation Resolution
Description check ❌ Error The description mentions the upgrade, but it omits the required Issue, Approach, and Tasks sections from the template. Add the missing ## Issue, ## Approach, and ## Tasks sections, including the checklist items required by the template.
Engage In Review Feedback ❌ Error The PR only bumps parse-server; review concerns remain unaddressed (.nvmrc=8.11, CI Node 22.12/24.1) and there’s no evidence of discussion or retraction. Engage the reviewer in-thread, then either implement the requested changes (engine/lockfile/security) or get explicit retraction before resolving.
Security Check ⚠️ Warning The PR pins parse-server to 9.9.0, which GitHub Advisory GHSA-38m6-82c8-4xfm marks as affected (>=9.0.0,<9.9.1-alpha.1) with high-severity pre-auth DoS. Bump parse-server to a version outside the affected range and regenerate the lockfile; 9.9.0 is not safe to merge.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title matches the PR's main change: upgrading parse-server from 9.7.0 to 9.9.0.
Linked Issues check ✅ Passed The PR updates parse-server to 9.9.0 as requested and aligns with the linked issue's upgrade objective.
Out of Scope Changes check ✅ Passed The lockfile churn is consistent with a full regeneration from the parse-server upgrade and does not show unrelated scope creep.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@package-lock.json`:
- Line 25197: Align the Node version configuration with parse-server@9.9.0:
update the CI matrix in ci.yml from 22.12.0 and 24.1.0 to supported versions,
update the root engines gate to match, and replace the stale .nvmrc value of
8.11 with a supported Node version.

In `@package.json`:
- Line 125: Update the parse-server dependency from 9.9.0 to a patched version
covering all applicable advisories, then regenerate the lockfile and verify the
browser-control harness still launches successfully. If no patched upgrade is
available, document strict service isolation and obtain an explicit security
exception before merging.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 37a670fe-d422-449a-a447-dce4fbe713a6

📥 Commits

Reviewing files that changed from the base of the PR and between b925272 and c323a9d.

📒 Files selected for processing (2)
  • package-lock.json
  • package.json

Comment thread package-lock.json
},
"engines": {
"node": ">=20.19.0 <21.0.0 || >=22.12.0 <23.0.0 || >=24.11.0 <25.0.0"
"node": ">=20.19.0 <21.0.0 || >=22.13.0 <23.0.0 || >=24.11.0 <25.0.0"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🩺 Stability & Availability | 🟡 Minor | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/usr/bin/env bash
set -euo pipefail

files="$(
  fd -HI -t f . |
    rg '(^|/)(package\.json|package-lock\.json|\.nvmrc|\.node-version|\.tool-versions|Dockerfile.*|.*\.(yml|yaml))$' || true
)"

printf '%s\n' "$files" |
  xargs -r rg -n -i 'node-version|NODE_VERSION|engines|FROM node|20\.|22\.|24\.'

Repository: parse-community/parse-dashboard

Length of output: 50388


🏁 Script executed:

#!/usr/bin/env bash
set -euo pipefail

printf '%s\n' "Top-level files:"
git ls-files | sed -n '1,200p'

printf '\n%s\n' "Candidate Node/version orchestration files:"
fd -HI -t f '(\.github/workflows/.*\.ya?ml$|package\.json$|package-lock\.json$|\.nvmrc$|\.node-version$|\.tool-versions$|Dockerfile.*$|docker-compose.*\.ya?ml$)' .

printf '\n%s\n' "Node-related config snippets:"
for f in \
  .github/workflows/*.yml \
  .github/workflows/*.yaml \
  package.json \
  .nvmrc \
  .node-version \
  .tool-versions \
  Dockerfile \
  Dockerfile.* \
  docker-compose.yml \
  docker-compose.yaml
do
  [ -f "$f" ] || continue
  echo "----- $f -----"
  rg -n -i 'node|npx|engines|matrix|setup-node|version' "$f" || true
done

Repository: parse-community/parse-dashboard

Length of output: 50388


🏁 Script executed:

#!/usr/bin/env bash
set -euo pipefail

for f in package.json .nvmrc Dockerfile ci/nodeEngineCheck.mjs .github/workflows/ci.yml .github/workflows/ci-automated-check-environment.yml .github/workflows/release-automated.yml .github/workflows/release-manual-docker.yml .github/workflows/release-prepare-monthly.yml docker-compose.uffizzi.yml; do
  [ -f "$f" ] || continue
  echo "===== $f ====="
  wc -l "$f"
  cat -n "$f" | sed -n '1,260p'
  echo
done

Repository: parse-community/parse-dashboard

Length of output: 37422


Align the Node versions with parse-server@9.9.0
.github/workflows/ci.yml still runs 22.12.0 and 24.1.0, but parse-server@9.9.0 requires >=22.13.0 and >=24.11.0. Update the CI matrix and the root engine gate together; .nvmrc is also stale and should move off 8.11.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@package-lock.json` at line 25197, Align the Node version configuration with
parse-server@9.9.0: update the CI matrix in ci.yml from 22.12.0 and 24.1.0 to
supported versions, update the root engines gate to match, and replace the stale
.nvmrc value of 8.11 with a supported Node version.

Comment thread package.json
"marked": "17.0.5",
"mongodb-runner": "6.7.3",
"parse-server": "9.7.0",
"parse-server": "9.9.0",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟠 Major | 🏗️ Heavy lift

Do not merge the 9.9.0 pin without a patched build or security exception.

The supplied OSV results report multiple HIGH advisories for this exact version. This is not an unused fixture: the browser-control harness launches parse-server during tests. Official advisories place 9.9.0 in affected ranges for pre-authentication DoS, MFA/protected-field disclosure, GraphQL schema disclosure, and routeAllowList batch bypass. Upgrade to a build covering all applicable fixes and regenerate the lockfile; otherwise document strict service isolation and obtain an explicit exception. (github.com)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@package.json` at line 125, Update the parse-server dependency from 9.9.0 to a
patched version covering all applicable advisories, then regenerate the lockfile
and verify the browser-control harness still launches successfully. If no
patched upgrade is available, document strict service isolation and obtain an
explicit security exception before merging.

Sources: MCP tools, Linters/SAST tools

@mtrezza
mtrezza merged commit 4fc1c0b into parse-community:alpha Jul 13, 2026
11 checks passed
@parseplatformorg

Copy link
Copy Markdown
Contributor

🎉 This change has been released in version 9.2.1-alpha.1

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

state:released-alpha Released as alpha version

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants