
Product
Introducing Socket Scanning for VS Code Marketplace Extensions
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.
@galaxy-stack/orbit-graphql-federation
Advanced tools
Apollo Federation (v2) subgraph support for the Orbit GraphQL package — @key entities, _service/_entities federation queries, and directive generation.
bun add @galaxy-stack/orbit-graphql-federation @galaxy-stack/orbit-graphql graphql
import 'reflect-metadata';
import { FederationSchemaBuilder } from '@galaxy-stack/orbit-graphql-federation';
import { Key, External, Provides } from '@galaxy-stack/orbit-graphql-federation';
import { GraphQLObjectType, GraphQLString } from 'graphql';
@Key('upc')
class Product {}
const builder = new FederationSchemaBuilder();
builder.registerEntity(Product, new GraphQLObjectType({
name: 'Product',
fields: { upc: { type: GraphQLString }, name: { type: GraphQLString } },
}));
builder.registerReferenceResolver('Product', async (rep) => {
return products.find((p) => p.upc === rep.upc) ?? null;
});
const schema = builder.buildSubgraphSchema();
// schema exposes _service { sdl } and _entities(representations)
Class-level: @Key(fields), @Extends(), @Shareable(), @Inaccessible(), @Tag(name), @Directive(sdl)
Property-level: @External(), @Requires(fields), @Provides(fields), @Shareable(), @Inaccessible(), @Override(from), @Tag(name)
Method-level: @ResolveReference() (alias @ReferenceResolver())
_entities stamps __typename on resolved entities so the _Entity union resolves even when reference resolvers omit it.generateFederatedSDL prints the federated schema (including _service and _entities), so entity-only subgraphs produce valid SDL.{ service, rpc } (GrpcMethod decorator contract) and { service, method }.FAQs
GraphQL Federation support for Orbit framework
The npm package @galaxy-stack/orbit-graphql-federation receives a total of 54 weekly downloads. As such, @galaxy-stack/orbit-graphql-federation popularity was classified as not popular.
We found that @galaxy-stack/orbit-graphql-federation demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.