@apollo/server

@apollo/server breaking-changes badge

@apollo/server (latest known version: 5.5.1) has 5 known breaking changes on record, each backed by a source URL.

Actively maintainedLatest known version: 5.5.1npm ↗

Security advisories

GHSA-68jh-rf6x-836fLOW>=4.7.1 <4.7.4

@apollo/server vulnerable to unsafe application of Content Security Policy via reused nonces

source ↗

GHSA-8r69-3cvp-wxc3MODERATE>=3.0.0 <3.11.0 || <4.1.0

Batched HTTP requests may set incorrect `cache-control` response header

source ↗

GHSA-9q82-xgwf-vj6hMODERATE<5.5.0 || <=3.13.0

Apollo Server: Browser bug allows for bypass of XS-Search (read-only Cross-Site Request Forgery) prevention

source ↗

GHSA-j5g3-5c8r-7qfxLOW<4.9.3 || >=3.0.0 <3.12.1 || <2.26.1

Prevent logging invalid header values

source ↗

GHSA-mp6q-xf9x-fwf7HIGH>=2.0.0 <=3.13.0 || >=4.2.0 <4.13.0 || >=5.0.0 <5.4.0

Apollo Serve vulnerable to Denial of Service with `startStandaloneServer`

source ↗

Recent changes

v@apollo/server@5.0.0-rc.0Breaking

Apollo Server v5 has very few breaking API changes. It is a small upgrade focused largely on adjusting which versions of Node.js and Express are supported. Read our [migration guide](https://www.apollographql.com/docs/apollo-server/migration/) for more details on how to update your app. - Dropped support for Node.js v14, v16, and v18, which are no longer under [long-term support](https://nodejs.org/en/about/releases/#releases) from the Node.js Foundation. Apollo Server 5 supports Node.js v20 and later; v24 is recommended. Ensure you are on a non-EOL version of Node.js before upgrading Apollo Server. - Dropped support for versions of the `graphql` library older than `v16.11.0`. (Apollo Server 4 supports `graphql` `v16.6.0` or later.) Upgrade `graphql` before upgrading Apollo Server. - Express integration requires a separate package. In Apollo Server 4, you could import the Express 4 middleware from `@apollo/server/express4`, or you could import it from the separate package `@as-integrations/express4`. In Apollo Server 5, you must import it from the separate package. You can migrate your server to the new package before upgrading to Apollo Server 5. (You can also use `@as-integrations/express5` for a middleware that works with Express 5.) - Usage Reporting, Schema Reporting, and Subscription Callback plugins now use the Node.js built-in `fetch` implementation for HTTP requests by default, instead of the `node-fetch` npm package. If your server uses an HTTP proxy to make HTTP requests, you need to configure it in a slightly different way. See the [migration guide](https://www.apollographql.com/docs/apollo-server/migration/) for details. - The server started with `startStandaloneServer` no longer uses Express. This is mostly invisible, but it does set slightly fewer headers. If you rely on the fact that this server is based on Express, you should explicitly use the Express middleware. - The experimental support for incremental delivery directives `@defer` and `@stream` (which requires using a pre-release version of `graphql` v17) now explicitly only works with version `17.0.0-alpha.2` of `graphql`. Note that this supports the same incremental delivery protocol implemented by Apollo Server 4, which is not the same protocol in the latest alpha version of `graphql`. As this support is experimental, we may switch over from "only `alpha.2` is supported" to "only a newer alpha or final release is supported, with a different protocol" during the lifetime of Apollo Server 5. - Apollo Server is now compiled by the TypeScript compiler targeting the ES2023 standard rather than the ES2020 standard. - Apollo Server 5 responds to requests with variable coercion errors (eg, if a number is passed in the `variables` map for a variable declared in the operation as a `String`) with a 400 status code, indicating a client error. This is also the behavior of Apollo Server 3. Apollo Server 4 mistakenly responds to these requests with a 200 status code by default; we recommended the use of the `status400ForVariableCoercionErrors: true` option to restore the intended behavior. That option now defaults to true. - The unsafe `precomputedNonce` option to landing page plugins (which was only non-deprecated for 8 days) has been removed.

source ↗

v@apollo/server@5.0.0Breaking

Apollo Server v5 has very few breaking API changes. It is a small upgrade focused largely on adjusting which versions of Node.js and Express are supported. Read our [migration guide](https://www.apollographql.com/docs/apollo-server/migration/) for more details on how to update your app. - Dropped support for Node.js v14, v16, and v18, which are no longer under [long-term support](https://nodejs.org/en/about/releases/#releases) from the Node.js Foundation. Apollo Server 5 supports Node.js v20 and later; v24 is recommended. Ensure you are on a non-EOL version of Node.js before upgrading Apollo Server. - Dropped support for versions of the `graphql` library older than `v16.11.0`. (Apollo Server 4 supports `graphql` `v16.6.0` or later.) Upgrade `graphql` before upgrading Apollo Server. - Express integration requires a separate package. In Apollo Server 4, you could import the Express 4 middleware from `@apollo/server/express4`, or you could import it from the separate package `@as-integrations/express4`. In Apollo Server 5, you must import it from the separate package. You can migrate your server to the new package before upgrading to Apollo Server 5. (You can also use `@as-integrations/express5` for a middleware that works with Express 5.) - Usage Reporting, Schema Reporting, and Subscription Callback plugins now use the Node.js built-in `fetch` implementation for HTTP requests by default, instead of the `node-fetch` npm package. If your server uses an HTTP proxy to make HTTP requests, you need to configure it in a slightly different way. See the [migration guide](https://www.apollographql.com/docs/apollo-server/migration/) for details. - The server started with `startStandaloneServer` no longer uses Express. This is mostly invisible, but it does set slightly fewer headers. If you rely on the fact that this server is based on Express, you should explicitly use the Express middleware. - The experimental support for incremental delivery directives `@defer` and `@stream` (which requires using a pre-release version of `graphql` v17) now explicitly only works with version `17.0.0-alpha.2` of `graphql`. Note that this supports the same incremental delivery protocol implemented by Apollo Server 4, which is not the same protocol in the latest alpha version of `graphql`. As this support is experimental, we may switch over from "only `alpha.2` is supported" to "only a newer alpha or final release is supported, with a different protocol" during the lifetime of Apollo Server 5. - Apollo Server is now compiled by the TypeScript compiler targeting the ES2023 standard rather than the ES2020 standard. - Apollo Server 5 responds to requests with variable coercion errors (eg, if a number is passed in the `variables` map for a variable declared in the operation as a `String`) with a 400 status code, indicating a client error. This is also the behavior of Apollo Server 3. Apollo Server 4 mistakenly responds to these requests with a 200 status code by default; we recommended the use of the `status400ForVariableCoercionErrors: true` option to restore the intended behavior. That option now defaults to true. - The unsafe `precomputedNonce` option to landing page plugins (which was only non-deprecated for 8 days) has been removed.

source ↗

v@apollo/server@4.0.0Breaking

Apollo Server contains quite a few breaking changes: most notably, a brand new package name! Read our [migration guide](https://www.apollographql.com/docs/apollo-server/migration/) for more details on how to update your app.

source ↗

v@apollo/usage-reporting-protobuf@4.0.0Breaking

Version @apollo/usage-reporting-protobuf@4.0.0 is a semver-major release over @apollo/server-gateway-interface@2.0.0-rc.0, but no breaking change was detected in the release notes text - flagged for manual review.

source ↗

v@apollo/server-gateway-interface@2.0.0Breaking

Version @apollo/server-gateway-interface@2.0.0 is a semver-major release over @apollo/server-gateway-interface@1.1.1, but no breaking change was detected in the release notes text - flagged for manual review.

source ↗

Check what changed for @apollo/server since your installed version, live.

Open the playground →