
Product
Socket Firewall Now Blocks Malicious VS Code and Open VSX Extensions
Socket Firewall blocks malicious VS Code and Open VSX extensions before install, protecting developers from compromised editor marketplaces.
@apollo/usage-reporting-protobuf
Advanced tools
apollo-reporting-protobufNote: The Apollo usage reporting API is subject to change. We strongly encourage developers to contact Apollo support at
support@apollographql.comto discuss their use case prior to building their own reporting agent using this module.
This module provides JavaScript/TypeScript
Protocol buffer definitions
for the Apollo usage reporting API. These definitions are generated for
consumption from the reports.proto file which is defined internally within
Apollo.
Note: Due to a dependency on Unix tools (e.g.
bash,grep, etc.), the development of this module requires a Unix system. There is no reason why this can't be avoided, the time just hasn't been taken to make those changes. We'd happily accept a PR which makes the appropriate changes!
Currently, this package generates a majority of its code with
@apollo/protobufjs (a fork of
protobufjs that we maintain
specifically for this package) based on the reports.proto file. The output is
generated with the generate npm script.
The root of the repository provides some devDependencies necessary to build
these definitions; these will be installed by running npm install at the root
of this workspace. When making changes to this module, run scripts via npm run SCRIPTNAME -w @apollo/usage-reporting-protobuf in the root of this monorepo in
order to update the definitions in this module. The -w flag is shorthand for
--workspace; this monorepo leverages NPM workspaces to manage its packages.
To update reports.proto to the current version recognized by the Studio usage
reporting ingress, run npm run update-proto -w @apollo/usage-reporting-protobuf. To then regenerate the JS and TS files, run
npm run generate -w @apollo/usage-reporting-protobuf. We check in the
generated code and only regenerate it manually, partially to make builds faster
(no need to run pbjs on every npm install) and partially so that we don't have
to make sure that pbjs runs on every Node version that we support.
protobufjs is a comprehensive library for working with Protocol Buffers in JavaScript. It provides utilities for defining, encoding, and decoding protobuf messages. Unlike @apollo/usage-reporting-protobuf, which is specific to Apollo's usage reporting, protobufjs is a general-purpose library that can be used for any protobuf-related tasks.
google-protobuf is the official Protocol Buffers library for JavaScript provided by Google. It offers similar functionalities for defining, encoding, and decoding protobuf messages. It is more general-purpose compared to @apollo/usage-reporting-protobuf, which is tailored for Apollo's usage reporting.
grpc is a high-performance, open-source universal RPC framework that uses Protocol Buffers for serialization. It provides tools for defining services and messages using protobuf and supports various languages. While grpc is more focused on RPC communication, it also includes functionalities for working with protobuf messages, making it a broader tool compared to @apollo/usage-reporting-protobuf.
FAQs
Protobuf format for Apollo usage reporting
The npm package @apollo/usage-reporting-protobuf receives a total of 2,531,271 weekly downloads. As such, @apollo/usage-reporting-protobuf popularity was classified as popular.
We found that @apollo/usage-reporting-protobuf demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 5 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Product
Socket Firewall blocks malicious VS Code and Open VSX extensions before install, protecting developers from compromised editor marketplaces.

Research
More than 140 Mastra npm packages were compromised in a supply chain attack that used a typosquatted dependency to deliver a cross-platform infostealer during installation.

Research
/Security News
A new npm package tests AI malware scanners with prompt injection, safety-triggering comments, context flooding, and obfuscated JavaScript.