
Research
2025 Report: Destructive Malware in Open Source Packages
Destructive malware is rising across open source registries, using delays and kill switches to wipe code, break builds, and disrupt CI/CD.
create-root-schema
Advanced tools
> 🌿 Combines schemas and types to help you modularize your GraphQL service
🌿 Combines schemas and types to help you modularize your GraphQL service
GraphQL is awesome, but there isn't yet a standardized way to break up schemas in a way that makes sense. By enforcing a simple standard (exporting certain variables) on all your schema files, you can break the service up in a way that makes sense for your project.
We believe this system allows you to make very few boilerplate changes to extend your service while also being very explicit—we don't like unnecessary magic.
ℹ️ This is just a very thin wrapper extending/replacing makeExecutableSchema.
See graphql-tools for more documentation.
All your schema files can export typeDefs, resolvers, and
schemaDirectives. All are optional.
To add functionality, each file may:
Query and/or Mutationgraphql-tools
documentation
more more informationgraphql-tools
documentation
more more information// Example Users schema file
import { fetchUser, fetchUsers } from './users';
export const typeDefs = /* GraphQL */ `
type User {
lastSeen: Timestamp
name: String
}
# Extend the root types to expose logic...
extend type Query {
user(id: ID!): User
users: [User]
}
`;
export const resolvers = {
Query: {
user: (_, { id }) => fetchUser(id),
users: () => fetchUsers()
}
};
Then, import the schema parts into a single file and create a root schema:
import {
combineSchemaDefinitions,
makeExecutableSchema
} from 'create-root-schema';
import * as device from './device';
import * as notification from './notification';
import * as user from './user';
// NOTE: Choose one of these options…
// - option 1: get the combined schema:
export default combineSchemaDefinitions([device, notification, user]);
// - option 2: both combine the schema and convert to an executable schema:
export default makeExecutableSchema([device, notification, user]);
apollo-server-express v2// ./schemas/index.js
import { combineSchemaDefinitions } from 'create-root-schema';
import * as device from './device';
import * as notification from './notification';
import * as user from './user';
export default combineSchemaDefinitions([brand, device, notification, user]);
// ./index.js
import { ApolloServer, gql } from 'apollo-server-express';
import express from 'express';
import schema from './schemas';
const app = express();
const server = new ApolloServer(schema);
server.applyMiddleware({ app });
app.listen({ port: 4000 }, () =>
console.log(`🚀 Server ready at http://localhost:4000${server.graphqlPath}`)
);
graphql-yoga// ./schemas/index.js
import { combineSchemaDefinitions } from 'create-root-schema';
import * as device from './device';
import * as notification from './notification';
import * as user from './user';
export default combineSchemaDefinitions([brand, device, notification, user]);
import { GraphQLServer } from 'graphql-yoga';
import schema from './schemas';
const server = new GraphQLServer(schema);
server.start(() => console.log('Server is running on localhost:4000'));
This is just a thin wrapper around makeExecutableSchema. Any options passed as the second argument will be forwarded directly to makeExecutableSchema.
import { makeExecutableSchema } from 'create-root-schema';
// See `graphql-tools` docs for more information
makeExecutableSchema([...schemas], { allowUndefinedInResolve: false });
With Yarn or npm installed, run:
yarn add create-root-schema
# ...or, if using `npm`
npm install create-root-schema
MIT
FAQs
> 🌿 Combines schemas and types to help you modularize your GraphQL service
The npm package create-root-schema receives a total of 1 weekly downloads. As such, create-root-schema popularity was classified as not popular.
We found that create-root-schema demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 10 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Destructive malware is rising across open source registries, using delays and kill switches to wipe code, break builds, and disrupt CI/CD.

Security News
Socket CTO Ahmad Nassri shares practical AI coding techniques, tools, and team workflows, plus what still feels noisy and why shipping remains human-led.

Research
/Security News
A five-month operation turned 27 npm packages into durable hosting for browser-run lures that mimic document-sharing portals and Microsoft sign-in, targeting 25 organizations across manufacturing, industrial automation, plastics, and healthcare for credential theft.