← Home

graphile-settings

graphile settings

40
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

pyramationluca608phatg

Keywords

graphilesettingsconfigurationconstructivegraphql

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff source-size-tripled AI (source-diff): Size growth explained by new deps/build output from v5 migration. ai
source-diff large-new-source-files AI (source-diff): Matches documented major-version migration to postgraphile v5/grafast stack. ai
phantom-deps phantom-dep:graphql AI (phantom-deps): Config-referenced peer dep, not directly imported; typical for settings package. ai
maintainer-change maintainer-added AI (maintainer-change): Consistent with org rename/consolidation under same trusted publisher. ai
publish-pattern rapid-publish AI (publish-pattern): High-volume publisher with 252 versions; rapid publishes are consistent with automated CI/CD release pipeline. ai
publish-pattern new-deps-added AI (publish-pattern): Package is a graphile plugin aggregator; adding graphile-ecosystem deps is expected behavior for this package. ai
dependencies unvetted-dep:postgraphile-plugin-connection-filter AI (dependencies): Well-known PostGraphile plugin; stable for this package. ai
dependencies unvetted-dep:@pyramation/postgis AI (dependencies): Same pyramation org as publisher; stable ecosystem dep. ai
dependencies unvetted-dep:graphile-simple-inflector AI (dependencies): Graphile ecosystem plugin; stable for this package. ai
dependencies unvetted-dep:graphile-search-plugin AI (dependencies): Graphile ecosystem plugin; stable for this package. ai
dependencies unvetted-dep:@launchql/upload-names AI (dependencies): Same launchql org; stable ecosystem dep. ai
dependencies unvetted-dep:@launchql/s3-streamer AI (dependencies): Same launchql org; stable ecosystem dep. ai
dependencies unvetted-dep:graphile-meta-schema AI (dependencies): Graphile ecosystem plugin; stable for this package. ai
dependencies unvetted-dep:postgraphile-derived-upload-field AI (dependencies): PostGraphile ecosystem plugin; stable for this package. ai
dependencies unvetted-dep:@launchql/env AI (dependencies): Same launchql org as publisher; consistent ecosystem pattern across versions. ai
dependencies unvetted-dep:graphile-i18n AI (dependencies): Graphile ecosystem plugin; stable pattern for this settings aggregator package. ai
dependencies unvetted-dep:@launchql/types AI (dependencies): Same launchql org; stable ecosystem dep. ai
dependencies unvetted-dep:@pyramation/postgraphile-plugin-fulltext-filter AI (dependencies): Same pyramation org as publisher; stable ecosystem dep. ai
dependencies unvetted-dep:postgraphile-plugin-connection-filter-postgis AI (dependencies): PostGraphile ecosystem plugin; stable for this package. ai
phantom-deps phantom-dep:graphile-settings AI (phantom-deps): Self-referential dep in config aggregator; stable false positive. ai
phantom-deps phantom-dep:graphql-tag AI (phantom-deps): Config aggregator pattern; deps declared for consumers, not directly imported. ai
phantom-deps phantom-dep:graphile-query AI (phantom-deps): Config aggregator pattern; deps declared for consumers, not directly imported. ai
phantom-deps phantom-dep:graphql-upload AI (phantom-deps): Config aggregator pattern; deps declared for consumers, not directly imported. ai
phantom-deps phantom-dep:postgraphile-derived-upload-field AI (phantom-deps): Config aggregator pattern; deps declared for consumers, not directly imported. ai
publish-pattern dormant-publish AI (publish-pattern): Publisher has extensive trusted history; dormancy followed by minor version bump is low risk for this package. ai
dependencies unvetted-dep:@graphile-contrib/pg-many-to-many AI (dependencies): Known Graphile ecosystem plugin; RC version pinned explicitly, consistent with this package's graphile-stack usage. ai
phantom-deps phantom-dep:@constructive-io/graphql-types AI (phantom-deps): Config/settings package; deps declared for consumer use, not direct import. ai
phantom-deps phantom-dep:@aws-sdk/client-s3 AI (phantom-deps): Config/settings package; deps declared for consumer use, not direct import. ai
phantom-deps phantom-dep:@dataplan/json AI (phantom-deps): Config/settings package; deps declared for consumer use, not direct import. ai
phantom-deps phantom-dep:@pgpmjs/types AI (phantom-deps): Config/settings package; deps declared for consumer use, not direct import. ai
phantom-deps phantom-dep:@dataplan/pg AI (phantom-deps): Config/settings package; deps declared for consumer use, not direct import. ai
phantom-deps phantom-dep:request-ip AI (phantom-deps): Config/settings package; deps declared for consumer use, not direct import. ai
phantom-deps phantom-dep:tamedevil AI (phantom-deps): Config/settings package; deps declared for consumer use, not direct import. ai
phantom-deps phantom-dep:lru-cache AI (phantom-deps): Config/settings package; deps declared for consumer use, not direct import. ai
phantom-deps phantom-dep:grafserv AI (phantom-deps): Config/settings package; deps declared for consumer use, not direct import. ai
phantom-deps phantom-dep:express AI (phantom-deps): Config/settings package; deps declared for consumer use, not direct import. ai
phantom-deps phantom-dep:pg AI (phantom-deps): Config/settings package; deps declared for consumer use, not direct import. ai
phantom-deps phantom-dep:cors AI (phantom-deps): Config/settings package; deps declared for consumer use, not direct import. ai
provenance no-provenance AI (provenance): Established publisher with strong track record; lack of provenance is common and not a disqualifier here. ai

Versions (showing 40 of 40)

Version Deps Published
5.12.0 42 / 8
5.7.0 42 / 8
5.6.1 41 / 8
5.6.0 41 / 8
5.3.1 41 / 8
5.2.3 41 / 8
4.23.0 37 / 8
4.22.3 37 / 8
4.22.2 37 / 8
4.22.1 37 / 8
4.22.0 37 / 9
4.21.7 36 / 9
4.21.6 36 / 9
4.21.4 36 / 9
4.21.3 36 / 9
4.21.2 36 / 9
4.21.0 36 / 9
4.20.1 36 / 9
4.19.0 35 / 9
4.18.9 32 / 9
4.18.7 32 / 9
4.18.6 32 / 9
4.18.4 32 / 9
4.18.3 32 / 9
4.18.2 32 / 9
4.16.1 32 / 9
4.10.2 32 / 9
4.0.0 19 / 7
3.0.5 25 / 7
3.0.1 25 / 7
2.9.35 25 / 7
2.6.11 25 / 7
2.6.3 25 / 7
2.6.2 25 / 7
2.6.1 25 / 7
2.6.0 24 / 7
2.5.5 24 / 7
2.5.4 25 / 7
2.5.3 25 / 7
2.5.2 25 / 7

v5.12.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.16.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.0.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.0.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.9.35

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.