← Home

relay-compiler

A compiler tool for building GraphQL-driven applications.

74
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

fbyuzhirelay-bot

Keywords

graphqlrelay

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:eval-usage AI (semgrep): eval('require') is a documented pattern in relay-compiler for optional dynamic require of relay-config, wrapped in try/catch. Not malicious — stable across versions. ai
semgrep semgrep:child-process-spawn AI (semgrep): Spawning 'watchman version' is core relay-compiler functionality for Watchman file-watching integration. Expected and stable for this package. ai
npm-metadata bundled-binaries AI (npm-metadata): relay-compiler ships platform-specific native binaries (Rust-compiled) as its core distribution mechanism; bundled binaries are expected and stable for this package. ai
semgrep semgrep:child-process-import AI (semgrep): cli.js uses child_process.spawn to invoke the bundled native binary — standard pattern for npm-wrapped native executables; stable false positive for this package. ai
bogus-package bogus-package AI (bogus-package): The 'fb' maintainer flag is a false positive — fb is the official Facebook/Meta npm account used for the Relay ecosystem, not a spam publisher. ai

Versions (showing 74 of 174)

Hide prereleases
Version Deps Published
0.0.0-main-b1b31af9 0 / 0
0.0.0-main-b073aa00 0 / 0
0.0.0-main-b022911d 0 / 0
0.0.0-main-af641f94 0 / 0
0.0.0-main-ae3b14b5 0 / 0
0.0.0-main-ae115109 0 / 0
0.0.0-main-ad6ce634 0 / 0
0.0.0-main-a7814f16 0 / 0
0.0.0-main-a101d75a 0 / 0
0.0.0-main-a04ac7ee 0 / 0
0.0.0-main-9ff4e6b7 0 / 0
0.0.0-main-9f298caa 0 / 0
0.0.0-main-9af45f9c 0 / 0
0.0.0-main-996f53e1 0 / 0
0.0.0-main-970e3ee9 0 / 0
0.0.0-main-9383fb1a 0 / 0
0.0.0-main-91f84912 0 / 0
0.0.0-main-8c7073bd 0 / 0
0.0.0-main-884c06ea 0 / 0
0.0.0-main-87aabe9a 0 / 0
0.0.0-main-86dc40df 0 / 0
0.0.0-main-85e0875e 0 / 0
0.0.0-main-84ea7a01 0 / 0
0.0.0-main-81090797 0 / 0
0.0.0-main-80a4ff5f 0 / 0
0.0.0-main-7e516a41 0 / 0
0.0.0-main-7d0678ab 0 / 0
0.0.0-main-7c99ae28 0 / 0
0.0.0-main-7b61962a 0 / 0
0.0.0-main-79df993f 0 / 0
0.0.0-main-78bdad5b 0 / 0
0.0.0-main-781a30af 0 / 0
0.0.0-main-76a2dad0 0 / 0
0.0.0-main-760249a8 0 / 0
0.0.0-main-759b47d8 0 / 0
0.0.0-main-6d5b9307 0 / 0
0.0.0-main-6cd701c5 0 / 0
0.0.0-main-6af2d441 0 / 0
0.0.0-main-6495c952 0 / 0
0.0.0-main-5ee00e19 0 / 0
0.0.0-main-5e667ccc 0 / 0
0.0.0-main-58c21fe0 0 / 0
0.0.0-main-55eeaa43 0 / 0
0.0.0-main-531c3803 0 / 0
0.0.0-main-51e56eac 0 / 0
0.0.0-main-4e70ebf6 0 / 0
0.0.0-main-4e2fa215 0 / 0
0.0.0-main-4de8b860 0 / 0
0.0.0-main-4b91f033 0 / 0
0.0.0-main-46a1644f 0 / 0
0.0.0-main-4613c9d1 0 / 0
0.0.0-main-3e9007ef 0 / 0
0.0.0-main-3b446dfe 0 / 0
0.0.0-main-3a6510b0 0 / 0
0.0.0-main-39400b58 0 / 0
0.0.0-main-36a3be5f 0 / 0
0.0.0-main-30d76027 0 / 0
0.0.0-main-30caed30 0 / 0
0.0.0-main-2dcfb6a9 0 / 0
0.0.0-main-2ae7e5a9 0 / 0
0.0.0-main-2ae56ea3 0 / 0
0.0.0-main-2ad2c99a 0 / 0
0.0.0-main-28522d56 0 / 0
0.0.0-main-1e3069ee 0 / 0
0.0.0-main-1afa309f 0 / 0
0.0.0-main-1a6eb684 0 / 0
0.0.0-main-1916b1ca 0 / 0
0.0.0-main-15a2303e 0 / 0
0.0.0-main-13e88d1e 0 / 0
0.0.0-main-114c1929 0 / 0
0.0.0-main-10e3e73c 0 / 0
0.0.0-main-0d1b2fd4 0 / 0
0.0.0-main-0cb085d8 0 / 0
0.0.0-main-0528962e 0 / 0