@morphql/server
MorphQL Server Core - Headless transformation engine
42
Versions
MIT
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
hyperwindmill
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@nestjs/platform-express | AI (dependencies): @nestjs/platform-express is a mainstream, well-known NestJS package; not a real risk for this NestJS server package. | ai | |
| phantom-deps | phantom-dep:reflect-metadata | AI (phantom-deps): reflect-metadata is a known implicit/side-effect dependency required by NestJS decorators; not directly imported by design. | ai | |
| phantom-deps | phantom-dep:rxjs | AI (phantom-deps): rxjs is a standard NestJS transitive dependency; commonly declared but not directly imported in NestJS server packages. | ai | |
| phantom-deps | phantom-dep:ioredis | AI (phantom-deps): ioredis is declared as a runtime dep and referenced in config; indirect/conditional usage is normal for NestJS server packages. | ai | |
| phantom-deps | phantom-dep:@nestjs/platform-express | AI (phantom-deps): Platform adapter used indirectly by NestJS bootstrap; not directly imported in application code by design. | ai | |
| typosquat | typosquat.levenshtein:semver | AI (typosquat): @morphql/server is a scoped package in the MorphQL ecosystem; similarity to 'semver' is coincidental substring overlap, not impersonation. Stable false positive for this package. | ai |
Versions (showing 42 of 42)
| Version | Deps | Published |
|---|---|---|
| 0.1.46 | 1 / 5 | |
| 0.1.45 | 1 / 5 | |
| 0.1.44 | 1 / 5 | |
| 0.1.43 | 1 / 5 | |
| 0.1.42 | 1 / 5 | |
| 0.1.41 | 1 / 5 | |
| 0.1.39 | 1 / 5 | |
| 0.1.38 | 1 / 5 | |
| 0.1.37 | 1 / 5 | |
| 0.1.36 | 1 / 5 | |
| 0.1.35 | 1 / 5 | |
| 0.1.34 | 1 / 5 | |
| 0.1.33 | 1 / 5 | |
| 0.1.32 | 1 / 5 | |
| 0.1.31 | 1 / 5 | |
| 0.1.30 | 1 / 5 | |
| 0.1.29 | 1 / 5 | |
| 0.1.28 | 1 / 5 | |
| 0.1.27 | 1 / 5 | |
| 0.1.26 | 1 / 5 | |
| 0.1.25 | 1 / 5 | |
| 0.1.24 | 1 / 5 | |
| 0.1.23 | 1 / 5 | |
| 0.1.22 | 1 / 5 | |
| 0.1.21 | 1 / 5 | |
| 0.1.20 | 1 / 5 | |
| 0.1.19 | 1 / 5 | |
| 0.1.18 | 1 / 5 | |
| 0.1.17 | 1 / 5 | |
| 0.1.16 | 1 / 5 | |
| 0.1.15 | 1 / 5 | |
| 0.1.14 | 1 / 5 | |
| 0.1.13 | 1 / 5 | |
| 0.1.12 | 1 / 5 | |
| 0.1.11 | 1 / 5 | |
| 0.1.10 | 1 / 5 | |
| 0.1.9 | 9 / 24 | |
| 0.1.8 | 8 / 23 | |
| 0.1.7 | 8 / 23 | |
| 0.1.6 | 8 / 23 | |
| 0.1.5 | 8 / 23 | |
| 0.1.3 | 8 / 23 |
v0.1.46
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.45
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.