graphiql
An graphical interactive in-browser GraphQL IDE.
100
Versions
MIT
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
benjiemjmahoneleebyroni1gacaofbwincentkassensortaasiandrummerthomasheyenbrockags-
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:markdown-it | AI (dependencies): markdown-it is a well-known, widely-used Markdown parser with a long history and millions of weekly downloads. Its use in graphiql for rendering descriptions is legitimate and expected. | ai | |
| provenance | no-provenance | AI (provenance): graphiql is a long-established, high-trust package under the official graphql org; lack of Sigstore provenance is not a meaningful risk signal here. | ai | |
| phantom-deps | phantom-dep:markdown-it | AI (phantom-deps): markdown-it is a declared runtime dep used in the bundled output; phantom-dep flag reflects monorepo build structure, not a security issue. | ai | |
| phantom-deps | phantom-dep:graphql-language-service | AI (phantom-deps): graphql-language-service is a declared runtime dep in this monorepo package; phantom-dep flag is a build artifact, not a security concern. | ai |