← Home

@apollo/client-devtools-vscode

This package is meant to be used to connect your Apollo Client instance with the Apollo Client devtools in the [Apollo GraphQL](https://marketplace.visualstudio.com/items?itemName=apollographql.vscode-apollo) VSCode extension.

40
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

phryneasjerelmillerapollo-botabernix

Keywords

apolloapollo-clientdevtoolsvscode

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Publisher changed to GitHub Actions CI/CD with SLSA provenance attestation; legitimate automation transition for apollographql org. ai
phantom-deps phantom-dep:zen-observable AI (phantom-deps): zen-observable is a bundler/config reference in this package; stable false positive. ai
source-diff encoded-string-file:vscode-server.js AI (source-diff): Long strings are JSON-embedded Apollo Client error messages in a webpack bundle; not obfuscated payloads. ai
publish-pattern dormant-publish AI (publish-pattern): SLSA provenance attestation confirms CI/CD publish from official apollographql org; dormancy is not a risk here. ai

Versions (showing 40 of 40)

Version Deps Published
4.26.0 1 / 0
4.25.6 1 / 0
4.25.5 1 / 0
4.25.4 1 / 0
4.25.3 1 / 0
4.25.2 1 / 0
4.25.1 1 / 0
4.25.0 1 / 0
4.24.9 1 / 0
4.24.8 1 / 0
4.24.7 1 / 0
4.24.6 1 / 0
4.24.5 1 / 0
4.24.4 1 / 0
4.24.3 1 / 0
4.24.2 1 / 0
4.24.1 1 / 0
4.24.0 1 / 0
4.23.2 1 / 0
4.23.1 1 / 0
4.23.0 1 / 0
4.22.3 1 / 0
4.22.2 1 / 0
4.22.1 1 / 0
4.22.0 1 / 0
4.21.11 1 / 0
4.21.10 1 / 0
4.21.9 1 / 0
4.21.8 1 / 0
4.21.7 1 / 0
4.21.6 1 / 0
4.21.5 1 / 0
4.21.4 1 / 0
4.21.3 1 / 0
4.21.2 1 / 0
4.21.1 1 / 0
4.21.0 1 / 0
4.20.2 1 / 0
4.20.1 1 / 0
4.20.0 1 / 0

v4.26.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.