
Research
/Security News
Critical Vulnerability in NestJS Devtools: Localhost RCE via Sandbox Escape
A flawed sandbox in @nestjs/devtools-integration lets attackers run code on your machine via CSRF, leading to full Remote Code Execution (RCE).
io-ts-graphql-codegen
Advanced tools
This plugin for [graphql code generator](https://graphql-code-generator.com) generates types and runtime codecs for a given GraphQL Schema using [io-ts](https://github.com/gcanti/io-ts) to give runtime type safety.
This plugin for graphql code generator generates types and runtime codecs for a given GraphQL Schema using io-ts to give runtime type safety.
FragmentSpread
selectionssubscription
operation types__typename
will be generated on all types and selections automaticallyThe general flow to generate the types is as follows:
io-ts
's Intersection type is bound to a minimum of 2 codecs and a maximum of 5. When performing selections and merging them with intersection types these bounds need to be honored. Currently this plugin only supports the merging of 25 codecs.FAQs
This plugin for [graphql code generator](https://graphql-code-generator.com) generates types and runtime codecs for a given GraphQL Schema using [io-ts](https://github.com/gcanti/io-ts) to give runtime type safety.
The npm package io-ts-graphql-codegen receives a total of 6 weekly downloads. As such, io-ts-graphql-codegen popularity was classified as not popular.
We found that io-ts-graphql-codegen demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
/Security News
A flawed sandbox in @nestjs/devtools-integration lets attackers run code on your machine via CSRF, leading to full Remote Code Execution (RCE).
Product
Customize license detection with Socket’s new license overlays: gain control, reduce noise, and handle edge cases with precision.
Product
Socket now supports Rust and Cargo, offering package search for all users and experimental SBOM generation for enterprise projects.