Security News
pnpm 10.0.0 Blocks Lifecycle Scripts by Default
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
codegen-typescript-graphql-module-declarations-plugin
Advanced tools
This [graphql-code-generator](https://graphql-code-generator.com/) plugin is based on the [TypeScript GraphQL Files Modules](https://graphql-code-generator.com/docs/plugins/typescript-graphql-files-modules), but generates typed document nodes, using the t
This graphql-code-generator plugin is based on the TypeScript GraphQL Files Modules, but generates typed document nodes, using the types generated earlier by TypedDocumentNode plugin.
You need to run graphql-code-generator with the TypedDocumentNode plugin first and set typedDocumentNodeModule
option to the module path of the generated file.
For configuration options see index.ts.
This plugin generates TypeScript typings for .graphql
files containing GraphQL documents, which later on can be consumed using graphql-tag/loader
or use string
types if you will use the operations as raw strings, and get type-check and type-safety for your imports. This means that any time you import objects from .graphql
files, your IDE will provide auto-complete.
This plugin also handles .graphql
files containing multiple GraphQL documents, and name the imports according to the operation name.
⚠ Fragments are not generated with named imports, only as default imports, due to
graphql-tag/loader
behavior.
FAQs
This [graphql-code-generator](https://graphql-code-generator.com/) plugin is based on the [TypeScript GraphQL Files Modules](https://graphql-code-generator.com/docs/plugins/typescript-graphql-files-modules), but generates typed document nodes, using the t
We found that codegen-typescript-graphql-module-declarations-plugin demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
Product
Socket now supports uv.lock files to ensure consistent, secure dependency resolution for Python projects and enhance supply chain security.
Research
Security News
Socket researchers have discovered multiple malicious npm packages targeting Solana private keys, abusing Gmail to exfiltrate the data and drain Solana wallets.