@graphql-tools/mock
A set of utils for faster development of GraphQL tools
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Publisher change from ardatan to GitHub Actions is consistent with automated CI/CD release in graphql-tools monorepo; SLSA provenance confirms integrity. | ai | |
| publish-pattern | suspicious-version-number | AI (publish-pattern): Alpha pre-release version with commit hash is standard for CI/CD builds; stable pattern for this package. | ai | |
| provenance | no-provenance | AI (provenance): Provenance attestation is a CI/CD enhancement; absence is not a security blocker for established publishers. | ai | |
| phantom-deps | phantom-dep:tslib | AI (phantom-deps): tslib is a known implicit dependency in TypeScript projects and is correctly declared in package.json; stable for this package. | ai | |
| dependencies | unvetted-dep:ts-is-defined | AI (dependencies): ts-is-defined is a tiny, well-known TypeScript type-guard utility with no malicious signals; legitimate dependency for a TypeScript-first graphql-tools package. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): theguild-bot is a CI/CD automation account typical for monorepo releases; stable for this publisher. | ai | |
| source-diff | source-size-tripled | AI (source-diff): 3.5x growth consistent with feature additions; no obfuscation or malware signals. | ai | |
| source-diff | large-new-source-files | AI (source-diff): 32 new files reflect feature expansion in mature package; no injection indicators. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): Single new dependency on established utility; consistent with normal package evolution. | ai | |
| dependencies | unvetted-dep:fast-json-stable-stringify | AI (dependencies): fast-json-stable-stringify is a well-known, legitimate utility with no security concerns. | ai | |
| typosquat | typosquat.levenshtein:mocha | AI (typosquat): @graphql-tools/mock is a scoped package in the well-known graphql-tools monorepo; not a typosquat of mocha. | ai | |
| typosquat | typosquat.levenshtein:mobx | AI (typosquat): @graphql-tools/mock is a scoped package in the well-known graphql-tools monorepo; not a typosquat of mobx. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Missing README sections and keywords are typical for monorepo packages and pre-releases; not indicative of spam. | ai |
Versions (showing 51 of 119)
| Version | Deps | Published |
|---|---|---|
| 9.1.7 | 4 / 0 | |
| 9.1.6 | 4 / 0 | |
| 9.1.5 | 4 / 0 | |
| 9.1.4 | 4 / 0 | |
| 9.1.3 | 4 / 0 | |
| 9.1.2 | 4 / 0 | |
| 9.1.1 | 4 / 0 | |
| 9.1.0 | 4 / 0 | |
| 9.0.25 | 4 / 0 | |
| 9.0.24 | 4 / 0 | |
| 9.0.23 | 4 / 0 | |
| 9.0.22 | 4 / 0 | |
| 9.0.21 | 4 / 0 | |
| 9.0.20 | 4 / 0 | |
| 9.0.19 | 4 / 0 | |
| 9.0.18 | 4 / 0 | |
| 9.0.17 | 4 / 0 | |
| 9.0.16 | 4 / 0 | |
| 9.0.15 | 4 / 0 | |
| 9.0.14 | 4 / 0 | |
| 9.0.13 | 4 / 0 | |
| 9.0.12 | 4 / 0 | |
| 9.0.11 | 4 / 0 | |
| 9.0.10 | 4 / 0 | |
| 9.0.9 | 4 / 0 | |
| 9.0.8 | 4 / 0 | |
| 9.0.7 | 4 / 0 | |
| 9.0.6 | 4 / 0 | |
| 9.0.5 | 4 / 0 | |
| 9.0.4 | 4 / 0 | |
| 9.0.3 | 4 / 0 | |
| 9.0.2 | 4 / 0 | |
| 9.0.1 | 4 / 0 | |
| 9.0.0 | 4 / 0 | |
| 8.7.20 | 4 / 0 | |
| 8.7.19 | 4 / 0 | |
| 8.7.18 | 4 / 0 | |
| 8.7.17 | 4 / 0 | |
| 8.7.16 | 4 / 0 | |
| 8.7.15 | 4 / 0 | |
| 8.7.14 | 4 / 0 | |
| 8.7.13 | 4 / 0 | |
| 8.7.12 | 4 / 0 | |
| 8.7.11 | 4 / 0 | |
| 8.7.10 | 4 / 0 | |
| 8.7.9 | 4 / 0 | |
| 8.7.8 | 4 / 0 | |
| 8.7.7 | 4 / 0 | |
| 8.7.6 | 4 / 0 | |
| 8.7.5 | 4 / 0 | |
| 8.7.4 | 4 / 0 |
v9.1.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.1.6
2 findingsThis version was published by a different npm account than previous versions on 2026-04-09. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.1.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.1.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.1.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.1.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.1.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.1.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.0.25
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.0.24
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.0.23
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.0.22
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.0.21
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.0.20
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.0.19
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.0.18
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.0.17
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.0.16
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.0.15
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.0.14
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.0.13
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.0.12
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.0.11
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.0.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.0.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.0.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.0.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.0.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.0.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.0.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.0.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.0.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.0.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.0.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.7.20
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.7.19
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.7.18
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.7.17
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.7.16
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.7.15
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.7.14
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.7.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.7.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.7.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.7.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.7.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.7.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.7.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.7.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.7.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.7.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.