← Home

@apollo/query-planner

8
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

dkucapollo-botphryneasabernix

Keywords

graphqlfederationgatewayserverapollo

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@apollo/query-graphs AI (dependencies): @apollo/query-graphs is a sibling package in the Apollo Federation monorepo, always published at the same version as @apollo/query-planner. Stable false positive for this package. ai
license uncommon-license:Elastic-2.0 AI (license): Apollo Federation packages consistently use Elastic-2.0; this is intentional and stable across all versions of this package. ai
phantom-deps phantom-dep:deep-equal AI (phantom-deps): deep-equal is a declared runtime dependency in package.json; phantom-dep flag is a false positive for this package's usage pattern. ai

Versions (showing 8 of 8)

Version Deps Published
2.14.1 6 / 0
2.14.0 6 / 0
2.13.3 6 / 0
2.13.2 6 / 0
2.12.3 6 / 0
2.11.6 6 / 0
2.10.5 6 / 0
2.9.6 6 / 0

v2.14.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.14.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.13.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.