mirror of
https://github.com/parse-community/parse-server
synced 2026-08-09 13:03:18 +00:00
# [9.7.0](https://github.com/parse-community/parse-server/compare/9.6.1...9.7.0) (2026-03-30) ### Bug Fixes * Auth data exposed via verify password endpoint ([GHSA-wp76-gg32-8258](https://github.com/parse-community/parse-server/security/advisories/GHSA-wp76-gg32-8258)) ([#10323](https://github.com/parse-community/parse-server/issues/10323)) ([770be86](https://github.com/parse-community/parse-server/commit/770be8647424d92f5425c41fa81065ffbbb171ed)) * Batch login sub-request rate limit uses IP-based keying ([#10349](https://github.com/parse-community/parse-server/issues/10349)) ([63c37c4](https://github.com/parse-community/parse-server/commit/63c37c49c7a72dc617635da8859004503021b8fd)) * Cloud Code trigger context vulnerable to prototype pollution ([#10352](https://github.com/parse-community/parse-server/issues/10352)) ([d5f5128](https://github.com/parse-community/parse-server/commit/d5f5128ade49749856d8ad5f9750ffd26d44836a)) * Cloud function validator bypass via prototype chain traversal ([GHSA-vpj2-qq7w-5qq6](https://github.com/parse-community/parse-server/security/advisories/GHSA-vpj2-qq7w-5qq6)) ([#10342](https://github.com/parse-community/parse-server/issues/10342)) ([dc59e27](https://github.com/parse-community/parse-server/commit/dc59e272665644083c5b7f6862d88ce1ef0b2674)) * Duplicate session destruction can cause unhandled promise rejection ([#10319](https://github.com/parse-community/parse-server/issues/10319)) ([92791c1](https://github.com/parse-community/parse-server/commit/92791c1d1d4b042a0e615ba45dcef491b904eccf)) * GraphQL API endpoint ignores CORS origin restriction ([GHSA-q3p6-g7c4-829c](https://github.com/parse-community/parse-server/security/advisories/GHSA-q3p6-g7c4-829c)) ([#10334](https://github.com/parse-community/parse-server/issues/10334)) ([4dd0d3d](https://github.com/parse-community/parse-server/commit/4dd0d3d8be1c39664c74ad10bb0abaa76bc41203)) * GraphQL complexity validator exponential fragment traversal DoS ([GHSA-mfj6-6p54-m98c](https://github.com/parse-community/parse-server/security/advisories/GHSA-mfj6-6p54-m98c)) ([#10344](https://github.com/parse-community/parse-server/issues/10344)) ([f759bda](https://github.com/parse-community/parse-server/commit/f759bda075298ec44e2b4fb57659a0c56620483b)) * LiveQuery protected field leak via shared mutable state across concurrent subscribers ([GHSA-m983-v2ff-wq65](https://github.com/parse-community/parse-server/security/advisories/GHSA-m983-v2ff-wq65)) ([#10330](https://github.com/parse-community/parse-server/issues/10330)) ([776c71c](https://github.com/parse-community/parse-server/commit/776c71c3078e77d38c94937f463741793609d055)) * LiveQuery protected-field guard bypass via array-like logical operator value ([GHSA-mmg8-87c5-jrc2](https://github.com/parse-community/parse-server/security/advisories/GHSA-mmg8-87c5-jrc2)) ([#10350](https://github.com/parse-community/parse-server/issues/10350)) ([f63fd1a](https://github.com/parse-community/parse-server/commit/f63fd1a3fe0a7c1c5fe809f01b0e04759e8c9b98)) * Maintenance key blocked from querying protected fields ([#10290](https://github.com/parse-community/parse-server/issues/10290)) ([7c8b213](https://github.com/parse-community/parse-server/commit/7c8b213d96f1fd79f27d3a2bc01bef8bcaf588cd)) * MFA single-use token bypass via concurrent authData login requests ([GHSA-w73w-g5xw-rwhf](https://github.com/parse-community/parse-server/security/advisories/GHSA-w73w-g5xw-rwhf)) ([#10326](https://github.com/parse-community/parse-server/issues/10326)) ([e7efbeb](https://github.com/parse-community/parse-server/commit/e7efbebba398ce6abe5b6b6fb9829c6ebe310fbf)) * Missing error messages in Parse errors ([#10304](https://github.com/parse-community/parse-server/issues/10304)) ([f128048](https://github.com/parse-community/parse-server/commit/f12804800bc9232de02b4314e886bab6b169f041)) * Postgres query on non-existent column throws internal server error ([#10308](https://github.com/parse-community/parse-server/issues/10308)) ([c5c4325](https://github.com/parse-community/parse-server/commit/c5c43259d1f98af5bbbbc44d9daf7c0f1f8168d3)) * Session field immutability bypass via falsy-value guard ([GHSA-f6j3-w9v3-cq22](https://github.com/parse-community/parse-server/security/advisories/GHSA-f6j3-w9v3-cq22)) ([#10347](https://github.com/parse-community/parse-server/issues/10347)) ([9080296](https://github.com/parse-community/parse-server/commit/90802969fc713b7bc9733d7255c7519a6ed75d21)) ### Features * Add `protectedFieldsSaveResponseExempt` option to strip protected fields from save responses ([#10289](https://github.com/parse-community/parse-server/issues/10289)) ([4f7cb53](https://github.com/parse-community/parse-server/commit/4f7cb53bd114554cf9e6d7855b5e8911cb87544b)) * Add `protectedFieldsTriggerExempt` option to exempt Cloud Code triggers from `protectedFields` ([#10288](https://github.com/parse-community/parse-server/issues/10288)) ([1610f98](https://github.com/parse-community/parse-server/commit/1610f98316f7cb1120a7e20be7a1570b0e116df7)) * Add support for `partialFilterExpression` in MongoDB storage adapter ([#10346](https://github.com/parse-community/parse-server/issues/10346)) ([8dd7bf2](https://github.com/parse-community/parse-server/commit/8dd7bf2f61c07b0467d6dbc7aad5142db6694339)) * Extend storage adapter interface to optionally return `matchedCount` and `modifiedCount` from `DatabaseController.update` with `many: true` ([#10353](https://github.com/parse-community/parse-server/issues/10353)) ([aea7596](https://github.com/parse-community/parse-server/commit/aea7596cd2336c1c179ae130efd550f1596f5f3a))
173 lines
6.3 KiB
JSON
173 lines
6.3 KiB
JSON
{
|
|
"name": "parse-server",
|
|
"version": "9.7.0",
|
|
"description": "An express module providing a Parse-compatible API server",
|
|
"main": "lib/index.js",
|
|
"repository": {
|
|
"type": "git",
|
|
"url": "https://github.com/parse-community/parse-server"
|
|
},
|
|
"files": [
|
|
"bin/",
|
|
"lib/",
|
|
"public/",
|
|
"views/",
|
|
"LICENSE",
|
|
"NOTICE",
|
|
"postinstall.js",
|
|
"README.md",
|
|
"types"
|
|
],
|
|
"license": "Apache-2.0",
|
|
"dependencies": {
|
|
"@apollo/server": "5.5.0",
|
|
"@as-integrations/express5": "1.1.2",
|
|
"@graphql-tools/merge": "9.0.24",
|
|
"@graphql-tools/schema": "10.0.23",
|
|
"@graphql-tools/utils": "10.8.6",
|
|
"@parse/fs-files-adapter": "3.0.0",
|
|
"@parse/push-adapter": "8.3.1",
|
|
"bcryptjs": "3.0.3",
|
|
"commander": "14.0.3",
|
|
"cors": "2.8.6",
|
|
"express": "5.2.1",
|
|
"express-rate-limit": "8.3.0",
|
|
"follow-redirects": "1.15.11",
|
|
"graphql": "16.13.2",
|
|
"graphql-list-fields": "2.0.4",
|
|
"graphql-relay": "0.10.2",
|
|
"graphql-upload": "15.0.2",
|
|
"intersect": "1.0.1",
|
|
"jsonwebtoken": "9.0.2",
|
|
"jwks-rsa": "3.2.0",
|
|
"ldapjs": "3.0.7",
|
|
"lodash": "4.17.23",
|
|
"lru-cache": "11.2.7",
|
|
"mime": "4.0.7",
|
|
"mongodb": "7.1.0",
|
|
"mustache": "4.2.0",
|
|
"otpauth": "9.4.0",
|
|
"parse": "8.5.0",
|
|
"path-to-regexp": "8.4.0",
|
|
"pg-monitor": "3.1.0",
|
|
"pg-promise": "12.6.0",
|
|
"pluralize": "8.0.0",
|
|
"punycode": "2.3.1",
|
|
"rate-limit-redis": "4.3.1",
|
|
"redis": "5.11.0",
|
|
"semver": "7.7.2",
|
|
"tv4": "1.3.0",
|
|
"uuid": "11.1.0",
|
|
"winston": "3.19.0",
|
|
"winston-daily-rotate-file": "5.0.0",
|
|
"ws": "8.20.0"
|
|
},
|
|
"devDependencies": {
|
|
"@actions/core": "3.0.0",
|
|
"@apollo/client": "3.13.8",
|
|
"@babel/cli": "7.27.0",
|
|
"@babel/core": "7.29.0",
|
|
"@babel/eslint-parser": "7.28.6",
|
|
"@babel/plugin-proposal-object-rest-spread": "7.20.7",
|
|
"@babel/plugin-transform-flow-strip-types": "7.27.1",
|
|
"@babel/preset-env": "7.27.2",
|
|
"@babel/preset-typescript": "7.27.1",
|
|
"@saithodev/semantic-release-backmerge": "4.0.1",
|
|
"@semantic-release/changelog": "6.0.3",
|
|
"@semantic-release/commit-analyzer": "13.0.1",
|
|
"@semantic-release/git": "10.0.1",
|
|
"@semantic-release/github": "12.0.6",
|
|
"@semantic-release/npm": "13.0.0",
|
|
"@semantic-release/release-notes-generator": "14.1.0",
|
|
"all-node-versions": "13.0.1",
|
|
"apollo-upload-client": "18.0.1",
|
|
"clean-jsdoc-theme": "4.3.0",
|
|
"cross-env": "7.0.3",
|
|
"deep-diff": "1.0.2",
|
|
"eslint": "9.27.0",
|
|
"eslint-plugin-expect-type": "0.6.2",
|
|
"eslint-plugin-unused-imports": "4.4.1",
|
|
"form-data": "4.0.5",
|
|
"globals": "17.3.0",
|
|
"graphql-tag": "2.12.6",
|
|
"jasmine": "6.1.0",
|
|
"jasmine-spec-reporter": "7.0.0",
|
|
"jsdoc": "4.0.4",
|
|
"jsdoc-babel": "0.5.0",
|
|
"lint-staged": "16.2.7",
|
|
"m": "1.10.0",
|
|
"madge": "8.0.0",
|
|
"mock-files-adapter": "file:spec/dependencies/mock-files-adapter",
|
|
"mock-mail-adapter": "file:spec/dependencies/mock-mail-adapter",
|
|
"mongodb-runner": "5.9.3",
|
|
"node-abort-controller": "3.1.1",
|
|
"node-fetch": "3.2.10",
|
|
"nyc": "17.1.0",
|
|
"prettier": "3.8.1",
|
|
"semantic-release": "25.0.3",
|
|
"typescript": "5.9.3",
|
|
"typescript-eslint": "8.53.1",
|
|
"yaml": "2.8.2"
|
|
},
|
|
"scripts": {
|
|
"ci:check": "node ./ci/ciCheck.js",
|
|
"ci:checkNodeEngine": "node ./ci/nodeEngineCheck.js",
|
|
"ci:definitionsCheck": "node ./ci/definitionsCheck.js",
|
|
"definitions": "node ./resources/buildConfigDefinitions.js && prettier --write 'src/Options/*.js'",
|
|
"docs": "jsdoc -c ./jsdoc-conf.json",
|
|
"lint": "eslint --cache ./ --flag unstable_config_lookup_from_file",
|
|
"lint-fix": "eslint --fix --cache ./ --flag unstable_config_lookup_from_file",
|
|
"build": "babel src/ -d lib/ --copy-files --extensions '.ts,.js'",
|
|
"build:types": "tsc",
|
|
"watch": "babel --watch src/ -d lib/ --copy-files",
|
|
"watch:ts": "tsc --watch",
|
|
"test:mongodb:7.0.16": "MONGODB_VERSION=7.0.16 npm run test",
|
|
"test:mongodb:8.0.4": "MONGODB_VERSION=8.0.4 npm run test",
|
|
"test:postgres:testonly": "cross-env PARSE_SERVER_TEST_DB=postgres PARSE_SERVER_TEST_DATABASE_URI=postgres://postgres:password@localhost:5432/parse_server_postgres_adapter_test_database npm run testonly",
|
|
"testonly": "cross-env MONGODB_VERSION=${MONGODB_VERSION:=8.0.4} MONGODB_TOPOLOGY=${MONGODB_TOPOLOGY:=standalone} TESTING=1 jasmine",
|
|
"test": "cross-env MONGODB_VERSION=${MONGODB_VERSION:=8.0.4} MONGODB_TOPOLOGY=${MONGODB_TOPOLOGY:=standalone} mongodb-runner exec -t ${MONGODB_TOPOLOGY} --version ${MONGODB_VERSION} -- --port 27017 -- npm run testonly",
|
|
"test:types": "eslint types/tests.ts -c ./types/eslint.config.mjs",
|
|
"coverage:mongodb": "cross-env MONGODB_VERSION=${MONGODB_VERSION:=8.0.4} MONGODB_TOPOLOGY=${MONGODB_TOPOLOGY:=standalone} mongodb-runner exec -t ${MONGODB_TOPOLOGY} --version ${MONGODB_VERSION} -- --port 27017 -- npm run coverage",
|
|
"coverage": "cross-env MONGODB_VERSION=${MONGODB_VERSION:=8.0.4} MONGODB_TOPOLOGY=${MONGODB_TOPOLOGY:=standalone} TESTING=1 nyc jasmine",
|
|
"start": "node ./bin/parse-server",
|
|
"prettier": "prettier --write {src,spec}/{**/*,*}.js",
|
|
"prepare": "npm run build",
|
|
"postinstall": "node -p 'require(\"./postinstall.js\")()'",
|
|
"madge:circular": "node_modules/.bin/madge ./src --circular",
|
|
"benchmark": "cross-env MONGODB_VERSION=8.0.4 MONGODB_TOPOLOGY=standalone mongodb-runner exec -t standalone --version 8.0.4 -- --port 27017 -- npm run benchmark:only",
|
|
"benchmark:only": "node --expose-gc --max-old-space-size=1024 benchmark/performance.js",
|
|
"benchmark:quick": "cross-env BENCHMARK_ITERATIONS=10 npm run benchmark:only"
|
|
},
|
|
"types": "types/index.d.ts",
|
|
"engines": {
|
|
"node": ">=20.19.0 <21.0.0 || >=22.12.0 <23.0.0 || >=24.11.0 <25.0.0"
|
|
},
|
|
"bin": {
|
|
"parse-server": "bin/parse-server"
|
|
},
|
|
"optionalDependencies": {
|
|
"@node-rs/bcrypt": "1.10.7"
|
|
},
|
|
"collective": {
|
|
"type": "opencollective",
|
|
"url": "https://opencollective.com/parse-server",
|
|
"logo": "https://opencollective.com/parse-server/logo.txt?reverse=true&variant=binary"
|
|
},
|
|
"funding": {
|
|
"type": "opencollective",
|
|
"url": "https://opencollective.com/parse-server"
|
|
},
|
|
"husky": {
|
|
"hooks": {
|
|
"pre-commit": "lint-staged"
|
|
}
|
|
},
|
|
"lint-staged": {
|
|
"{src,spec}/{**/*,*}.js": [
|
|
"prettier --write",
|
|
"eslint --fix --cache",
|
|
"git add"
|
|
]
|
|
}
|
|
}
|