@graphcommerce/graphql
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | dormant-publish | AI (publish-pattern): Large monorepo with 637 versions; activity gaps are plausible for ecosystem-wide releases, no malicious indicators present. | ai | |
| dependencies | unvetted-dep:apollo3-cache-persist | AI (dependencies): apollo3-cache-persist is a well-known Apollo cache persistence library; stable legitimate dependency for this package. | ai | |
| dependencies | unvetted-dep:@graphql-codegen/typescript-apollo-client-helpers | AI (dependencies): Official graphql-codegen plugin from The Guild; legitimate codegen tooling dependency. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Established monorepo package with 637 versions and 48 approved dependents; sparse metadata is typical for internal monorepo packages. | ai | |
| phantom-deps | phantom-dep:@graphql-codegen/fragment-matcher | AI (phantom-deps): Same codegen plugin pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@graphql-codegen/typed-document-node | AI (phantom-deps): Same codegen plugin pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@graphql-codegen/add | AI (phantom-deps): GraphQL codegen plugins declared as deps for consumer config use, not direct imports — stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@graphql-codegen/typescript-document-nodes | AI (phantom-deps): Same codegen plugin pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@graphql-codegen/typescript-apollo-client-helpers | AI (phantom-deps): Same codegen plugin pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@graphql-codegen/typescript-operations | AI (phantom-deps): Same codegen plugin pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@graphql-codegen/schema-ast | AI (phantom-deps): Same codegen plugin pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@graphql-codegen/typescript | AI (phantom-deps): Same codegen plugin pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@graphql-codegen/introspection | AI (phantom-deps): Same codegen plugin pattern; stable false positive for this package. | ai |
Versions (showing 4 of 4)
| Version | Deps | Published |
|---|---|---|
| 10.0.3 | 13 / 0 | |
| 10.0.2 | 13 / 0 | |
| 10.0.1 | 13 / 0 | |
| 10.0.0 | 13 / 0 |
v10.0.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v10.0.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v10.0.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.