@types/graphql
TypeScript definitions for graphql
18
Versions
MIT
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
No source commit
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
types
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | dormant-publish | AI (publish-pattern): This is a one-time stub/redirect package published when graphql adopted bundled types. Dormancy is expected; the types publisher has 2448 approved / 0 rejected packages. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): Adding graphql as a dependency is the explicit mechanism of this stub redirect package — consumers get graphql's own bundled types. Not an attack vector. | ai | |
| phantom-deps | phantom-dep:graphql | AI (phantom-deps): Stub package with no code files by design; graphql dep is declared to pull in the real package, not to be imported directly. | ai | |
| source-diff | source-size-dropped | AI (source-diff): Intentional: prior versions shipped type definitions; this stub version has none because graphql now bundles its own types. Zero source size is expected. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Stub/redirect packages are intentionally tiny with minimal README. This is a known DefinitelyTyped migration pattern, not spam. | ai |