
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
@graph-ts/graph-lib
Advanced tools
An immutable TypeScript graphing library.
To add graph-lib to your project using npm:
$ npm install @graph-ts/graph-lib
In graph-lib, graphs and the nodes and edges that comprise graphs are immutable. Rather than
mutating the state to, for example, add nodes and edges to a graph, a new graph object is created
each time the graph is modified.
import { newGraph, addNodes, addEdge, getNodes, getEdges, Graph, Node, Edge } from '@graph-ts/graph-lib';
const a: Node = { id: 'a' };
const b: Node = { id: 'b' };
const ab: Edge = { id: 'ab', source: 'a', target: 'b' };
const g0: Graph = newGraph();
const g1: Graph = addNodes(g0, [a, b]);
const g2: Graph = addEdge(g1, ab);
g0 === g1; // false
g1 === g2; // false
g0 === g2; // false
getNodes(g0); // []
getEdges(g0); // []
getNodes(g1); // [a, b]
getEdges(g1); // []
getNodes(g2); // [a, b];
getEdges(g2); // [ab]
a.id = 'c'; // throws error, these objects are now immutable
ab.source = 'b'; // throws error, these objects are now immutable
Predictability! Redux! Time-travel! So many good reasons! I'll get to this part later...
Under the hood, graph-ts uses Immer to enforce
immutability. It uses structural sharing, meaning that a completely new graph is not
actually generated each time a graph is modified; rather, the parts that are unchanged
between the two are structurally shared (the introductory blog post for Immer, found
here
is an excellent resource if you're curious how this works in practice). The implication
here is that you're unlikely to run into performance issues due to immutability. Quoting
that Immer introduction:
The usual mantra holds here: It is always better to optimize for Developer Experience then for Runtime Performance, unless proven by measurements that you need to do otherwise.
FAQs
A functional TypeScript graphing library
We found that @graph-ts/graph-lib demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.