Skip to content

Conversation

@snyk-bot
Copy link

@snyk-bot snyk-bot commented Jul 8, 2021

Snyk has created this PR to upgrade graphql-tag from 2.11.0 to 2.12.4.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 5 versions ahead of your current version.
  • The recommended version was released 2 months ago, on 2021-04-29.
Release notes
Package name: graphql-tag
  • 2.12.4 - 2021-04-29
    • Allow fragments to be imported by name when using the webpack loader.
      @ dobesv in #257
  • 2.12.3 - 2021-03-19

    Bump npm version to 2.12.3.

  • 2.12.2 - 2021-03-18

    Bump npm version to 2.12.2.

  • 2.12.1 - 2021-02-12

    Bump npm version to 2.12.1.

  • 2.12.0 - 2021-01-29

    Bump npm version to 2.12.0.

  • 2.11.0 - 2020-07-28
    • package.json sideEffects changes to clearly identify that graphql-tag doesn't have side effects.
      @ hwillson in #313
from graphql-tag GitHub release notes
Commit messages
Package name: graphql-tag
  • d401fcf Version bump; prep for publish
  • 81cc596 Allow fragments to be imported by name when using the webpack loader (#257)
  • 2b99a7c Bump rollup from 2.41.5 to 2.42.2 (#384)
  • 60cf313 Bump @ types/mocha from 8.2.1 to 8.2.2 (#383)
  • 687ce1f Bump npm version to 2.12.3.
  • 4c4abdc Bump rollup from 2.41.4 to 2.41.5 (#382)
  • d16bce6 Update tslib to version 2.1.0. (#381)
  • 8200b07 Bump npm version to 2.12.2.
  • 9349c62 Mention PR #380 in CHANGELOG.md.
  • 0ac664a Avoid using Object.assign to attach extra properties to gql. (#380)
  • a0b864c Bump @ types/node from 14.14.28 to 14.14.35 (#378)
  • 5c9d46d Bump chai from 4.3.0 to 4.3.4 (#377)
  • 6944e41 Bump typescript from 4.1.5 to 4.2.3 (#367)
  • 5a0d5f2 Bump mocha from 8.3.0 to 8.3.2 (#375)
  • d0afc16 Bump rollup from 2.39.0 to 2.41.4 (#379)
  • e48e47d Bump @ types/mocha from 8.2.0 to 8.2.1 (#355)
  • d3ec1b3 Bump @ types/node from 14.14.27 to 14.14.28 (#353)
  • c0091e1 Bump npm version to 2.12.1.
  • dfe0e62 Avoid TypeScript `import type ...` syntax for now. (#352)
  • 5bbb229 Add "engines": { "node": ">=10" } to package.json (#309)
  • a2109aa Bump @ types/node from 14.14.22 to 14.14.27 (#351)
  • a9478eb Bump rollup from 2.38.5 to 2.39.0 (#349)
  • 84075de Bump mocha from 8.2.1 to 8.3.0 (#350)
  • 249e1a8 Fix the npm pack (#338)

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants