parse-blockchain
parse-blockchain copied to clipboard
Bump parse-server from 4.10.10 to 5.4.1
Bumps parse-server from 4.10.10 to 5.4.1.
Release notes
Sourced from parse-server's releases.
5.4.1
5.4.1 (2023-01-31)
Bug Fixes
- The client IP address may be determined incorrectly in some cases; it is now required to set the Parse Server option
trustProxyaccordingly if Parse Server runs behind a proxy server, see the express framework's trust proxy setting; this fixes a security vulnerability in which the Parse Server optionmasterKeyIpsmay be circumvented, see GHSA-vm5r-c87r-pf6x (#8369) (e016d81)5.4.0
5.4.0 (2022-11-19)
Bug Fixes
- GraphQL query ignores condition
equalTowith valuefalse(#8032) (7f5a15d)- Internal indices for classes
_Idempotencyand_Roleare not protected in defined schema (#8121) (c16f529)- LiveQuery with
containedInnot working when object field is an array (#8128) (1d9605b)- Push notifications
badgedoesn't update with Installation beforeSave trigger (#8162) (3c75c2b)- Query aggregation pipeline cannot handle value of type
DatewhendirectAccess: true(#8167) (e424137)- Relation constraints in compound queries
Parse.Query.or,Parse.Query.andnot working (#8203) (28f0d26)- Security upgrade undici from 5.6.0 to 5.8.0 (#8108) (4aa016b)
- Sorting by non-existing value throws
INVALID_SERVER_ERRORon Postgres (#8157) (3b775a1)- Updating object includes unchanged keys in client response for certain key types (#8159) (37af1d7)
Features
- Add convenience access to Parse Server configuration in Cloud Code via
Parse.Server(#8244) (9f11115)- Add option to change the default value of the
Parse.Query.limit()constraint (#8152) (0388956)- Add support for MongoDB 6 (#8242) (aba0081)
- Add support for Postgres 15 (#8215) (2feb6c4)
- LiveQuery support for unsorted distance queries (#8221) (0f763da)
5.4.0-beta.1
5.4.0-beta.1 (2022-10-29)
Bug Fixes
- graphQL query ignores condition
equalTowith valuefalse(#8032) (7f5a15d)- internal indices for classes
_Idempotencyand_Roleare not protected in defined schema (#8121) (c16f529)- liveQuery with
containedInnot working when object field is an array (#8128) (1d9605b)- push notifications
badgedoesn't update with Installation beforeSave trigger (#8162) (3c75c2b)- query aggregation pipeline cannot handle value of type
DatewhendirectAccess: true(#8167) (e424137)- relation constraints in compound queries
Parse.Query.or,Parse.Query.andnot working (#8203) (28f0d26)- security upgrade undici from 5.6.0 to 5.8.0 (#8108) (4aa016b)
- sorting by non-existing value throws
INVALID_SERVER_ERRORon Postgres (#8157) (3b775a1)- updating object includes unchanged keys in client response for certain key types (#8159) (37af1d7)
Features
... (truncated)
Commits
30576f1chore(release): 5.4.1 [skip ci]e016d81fix: The client IP address may be determined incorrectly in some cases; it is...c8bc200ci: Add LTS branches to CI workflow09d04b0ci: update auto-release workflow38f64beci: update auto-release for LTS9b34b02chore(release): 5.4.0 [skip ci]e373f09build: Release (#8324)a9a9772Merge branch 'release' into beta735669arefactor: Prototype pollution via Cloud Code Webhooks; fixes security vulnera...fd8a11bchore(release): 5.3.3 [skip ci]- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)@dependabot use these labelswill set the current labels as the default for future PRs for this repo and language@dependabot use these reviewerswill set the current reviewers as the default for future PRs for this repo and language@dependabot use these assigneeswill set the current assignees as the default for future PRs for this repo and language@dependabot use this milestonewill set the current milestone as the default for future PRs for this repo and language
You can disable automated security fix PRs for this repo from the Security Alerts page.