Package Health

@graphql-tools/delegate

A set of utils for faster development of GraphQL tools

Latest 12.2.1NPMNPM

73%

Total Score

caution

The linked repository does not identify this package, with a high-confidence workflow hygiene warning.

Health Score Breakdown

Lifecycle scriptscaution

The package has a prepack script, which runs during packaging rather than ordinary dependency installation. It is a minor supply-chain transparency consideration, not evidence of a harmful install hook.

Repo package mentioncaution

The linked repository is graphql-hive/gateway, while the package is @graphql-tools/delegate, and the README does not mention the package. That weakens confidence that the repository is the package's actual home.

Security policycaution

The linked repository has no security policy, leaving vulnerability-reporting expectations unclear. Active tooling and repository activity partly compensate, but do not remove this transparency gap.

Workflow auditcaution

All 6 workflows were analyzed and none uses untrusted checkout or script injection, but a high-confidence template-injection finding remains in examples.yml. The 21 unpinned references out of 66 are a minority and are not independently concerning.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Direct Dependencies

DependencyLast ReleaseScore
tslib
Version ^2.8.1
—
—
dataloader
Version ^2.2.3
—
—
@graphql-tools/utils
Version ^12.0.1
—
—
@repeaterjs/repeater
Version ^3.0.6
—
—
@graphql-tools/schema
Version ^10.1.1
—
—

Weekly Downloads

Info

Last Published
2 days ago
Created
6 years ago
Unpacked Size
0.4 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform