← Home

@graphql-codegen/visitor-plugin-common

51
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

dotansimhaardatankamilkisielaurigotheguild-bot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff large-new-source-files AI (source-diff): 22 new source files are consistent with feature additions in an active monorepo; no obfuscation or bundled injection signals. ai
dependencies unvetted-dep:@graphql-toolkit/relay-operation-optimizer AI (dependencies): Part of the graphql-toolkit ecosystem, used as a replacement for relay-compiler; contextually appropriate for this GraphQL codegen plugin. ai
dependencies unvetted-dep:pascal-case AI (dependencies): pascal-case is a well-known, widely-used utility package; appropriate dependency for a code generation plugin. ai
provenance missing-githead AI (provenance): Established publisher; missing gitHead in this version is a minor provenance signal but consistent with publishing patterns from this trusted maintainer. ai
publish-pattern new-deps-added AI (publish-pattern): New dependencies are all legitimate, established packages; consistent with feature development in active monorepo. ai
provenance no-provenance AI (provenance): Package predates Sigstore provenance attestation; published in 2020-era tooling. Stable false positive for this package. ai
npm-metadata no-description AI (npm-metadata): Missing description is a metadata quirk, not a malware indicator for this established package. ai
bogus-package bogus-package AI (bogus-package): This is a monorepo sub-package from the well-known graphql-codegen project; missing description/repo/keywords in package.json is standard for build artifacts from monorepos. ai
phantom-deps phantom-dep:tslib AI (phantom-deps): tslib is a known implicit dependency pattern for TypeScript libraries; stable for this package. ai
maintainer-change maintainer-added AI (maintainer-change): theguild-bot addition reflects The Guild's standard practice of using a bot account for automated publishing; not a compromise indicator. ai
provenance publisher-changed AI (provenance): theguild-bot is The Guild's official CI publishing account; the dotansimha → theguild-bot transition is a documented, legitimate org-level change for the graphql-code-generator project. ai
dependencies unvetted-dep:@graphql-tools/relay-operation-optimizer AI (dependencies): @graphql-tools/relay-operation-optimizer is part of The Guild's graphql-tools ecosystem; legitimate dependency for relay optimization support. ai
dependencies unvetted-dep:@graphql-codegen/plugin-helpers AI (dependencies): @graphql-codegen/plugin-helpers is a sibling package in the same graphql-code-generator monorepo; expected dependency. ai
dependencies unvetted-dep:@graphql-tools/utils AI (dependencies): @graphql-tools/utils is a core package from The Guild's graphql-tools monorepo; legitimate and expected. ai
dependencies unvetted-dep:change-case-all AI (dependencies): change-case-all is a well-known string casing utility; standard dependency in graphql-codegen ecosystem. ai
dependencies unvetted-dep:parse-filepath AI (dependencies): parse-filepath is a legitimate utility package; expected dependency for path handling in graphql-codegen plugins. ai

Versions (showing 51 of 464)

Hide prereleases View all versions
Version Deps Published
7.0.4 10 / 0
7.0.3 10 / 0
7.0.2 10 / 0
7.0.1 10 / 0
7.0.0 10 / 0
6.3.0 10 / 0
6.2.4 10 / 0
6.2.3 10 / 0
6.2.2 10 / 0
6.2.1 10 / 0
6.2.0 10 / 0
6.1.2 10 / 0
6.1.1 10 / 0
6.1.0 10 / 0
6.0.1 10 / 0
6.0.0 10 / 0
5.8.0 10 / 0
5.7.1 10 / 0
5.7.0 10 / 0
5.6.1 10 / 0
5.6.0 10 / 0
5.5.0 10 / 0
5.4.0 10 / 0
5.3.1 10 / 0
5.3.0 10 / 0
5.2.0 10 / 0
5.1.0 10 / 0
5.0.0 10 / 0
4.1.2 10 / 0
4.1.1 10 / 0
4.1.0 10 / 0
4.0.1 10 / 0
4.0.0 10 / 0
3.1.1 10 / 0
3.1.0 10 / 0
3.0.2 10 / 0
3.0.1 10 / 0
3.0.0 10 / 0
2.13.8 10 / 0
2.13.7 10 / 0
2.13.6 10 / 0
2.13.5 10 / 0
2.13.4 10 / 0
2.13.3 10 / 0
2.13.2 10 / 0
2.13.1 10 / 0
2.13.0 10 / 0
2.12.2 10 / 0
2.12.1 10 / 0
2.12.0 10 / 0
2.11.1 10 / 0

v7.0.4

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

v7.0.3

3 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

INFO Publisher changed: theguild-bot → GitHub Actions (on 2026-05-27) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2026-05-27. This could indicate a legitimate maintainer transition or an account compromise.

v7.0.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.2.4

2 findings
HIGH Publisher changed: dotansimha → theguild-bot (on 2026-03-06) provenance

This version was published by a different npm account than previous versions on 2026-03-06. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.2.3

2 findings
HIGH Publisher changed: dotansimha → theguild-bot (on 2026-02-18) provenance

This version was published by a different npm account than previous versions on 2026-02-18. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.2.2

2 findings
HIGH Publisher changed: dotansimha → theguild-bot (on 2025-12-18) provenance

This version was published by a different npm account than previous versions on 2025-12-18. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.2.1

2 findings
HIGH Publisher changed: dotansimha → theguild-bot (on 2025-11-29) provenance

This version was published by a different npm account than previous versions on 2025-11-29. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.2.0

2 findings
HIGH Publisher changed: dotansimha → theguild-bot (on 2025-11-20) provenance

This version was published by a different npm account than previous versions on 2025-11-20. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.1.2

2 findings
HIGH Publisher changed: dotansimha → theguild-bot (on 2025-11-13) provenance

This version was published by a different npm account than previous versions on 2025-11-13. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.1.1

2 findings
HIGH Publisher changed: dotansimha → theguild-bot (on 2025-11-12) provenance

This version was published by a different npm account than previous versions on 2025-11-12. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.1.0

2 findings
HIGH Publisher changed: dotansimha → theguild-bot (on 2025-10-05) provenance

This version was published by a different npm account than previous versions on 2025-10-05. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.0.1

2 findings
HIGH Publisher changed: dotansimha → theguild-bot (on 2025-09-29) provenance

This version was published by a different npm account than previous versions on 2025-09-29. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.0.0

2 findings
HIGH Publisher changed: dotansimha → theguild-bot (on 2025-09-07) provenance

This version was published by a different npm account than previous versions on 2025-09-07. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.8.0

2 findings
HIGH Publisher changed: dotansimha → theguild-bot (on 2025-03-27) provenance

This version was published by a different npm account than previous versions on 2025-03-27. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.7.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.7.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.6.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.6.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.4.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.3.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.1.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.1.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.1.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.0.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.0.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.0.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.13.8

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.13.7

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.13.6

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.13.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.13.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.13.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.13.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.13.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.13.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.12.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.12.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.11.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.