
Security News
The Hidden Blast Radius of the Axios Compromise
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.
Quickly create an opinionated Node-ApolloExpress GraphQL API that connects to any MongoDB cluster.
CLI tool for quick starting a GraphQL server with Node, Apollo-Express, Mongoose and MongoDB.
Usage:
In your terminal navigate to the folder you wish to work in and run:
npx graphgooseThis will install and run graphgoose for you automatically and ask you to choose your templates.
The quick start is for simple projects and designed to get you quickly up and running to experiment with GraphQL. The modular start is in beta and built with the intention of giving you a base for starting a GraphQL API for a larger project.
Note: please do not raise an issue for the following items, if you would like to work on any of them please reach out to rahat on twitter @rahatcodes or by email rahat@rahatcodes.com.
The following are all items being working on for v1.0.0 (est. release January 2020)
Stretch goals:
FAQs
Quickly create an opinionated Node-ApolloExpress GraphQL API that connects to any MongoDB cluster.
The npm package graphgoose receives a total of 4 weekly downloads. As such, graphgoose popularity was classified as not popular.
We found that graphgoose demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.