@apollographql/graphql-language-service-interface
Interface to the GraphQL Language Service
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Apollo consolidated publishing under apollo-bot in 2018; this is a known org-wide transition, not a compromise. apollo-bot has 2518 approved packages. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): apollo-bot and nim are legitimate Apollo org accounts; addition is part of Apollo's 2018 publishing consolidation. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): mdg/sashko removal is consistent with Apollo's org restructuring; no evidence of hostile takeover. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New deps are the unscoped equivalents of the previously scoped @apollographql/* deps being replaced — a clean refactor, not new attack surface. | ai |
Versions (showing 5 of 5)
| Version | Deps | Published |
|---|---|---|
| 2.0.2 | 3 / 0 | |
| 2.0.1 | 3 / 0 | |
| 2.0.0 | 3 / 0 | |
| 1.3.2 | 4 / 0 | |
| 1.3.1 | 4 / 0 |
v2.0.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.1
2 findingsThis version was published by a different npm account than previous versions on 2018-11-04. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.0
2 findingsThis version was published by a different npm account than previous versions on 2018-11-04. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.