Fix consumer-facing CVEs by upgrading graphql-codegen to v7 - #92
Merged
Merged
Conversation
The seven Dependabot commits that landed after 1.4.0 only changed `resolutions`, which is Yarn-only and honored solely from the root project. It ships inside the tarball but is inert there, so consumers resolved the exact same transitive tree as 1.4.0: 17 high-severity advisories, rooted in immutable <3.8.4 and lodash <=4.17.23 (the latter being the version the resolutions pinned to). Fixing that requires moving the direct dependency ranges. Bumping @graphql-codegen/cli alone clears only 5 of 17; the immutable and lodash roots come in via typescript-graphql-request and import-types-preset, so all four codegen packages have to move together. With them bumped a simulated consumer install audits clean (17 high -> 0). Two build fixes were needed: - auto-bind@5 is ESM-only and codegen's CJS build require()s it, so it is pinned to 4.0.0. - codegen v7's typescript-operations emits schema enums and inputs itself, duplicating the typescript plugin (188 TS errors). `importSchemaTypesFrom` suppresses that; pointing it at the output file and stripping the self-import and namespace prefix in the existing post-processing keeps the output a single flat file. Public surface is held steady where possible: 38/38 SDK methods, no operation types removed, return types unchanged, and 0 removed exports. __typename is restored via addTypename/nonOptionalTypename, and the four codegen helper types (Exact, MakeOptional, MakeMaybe, MakeEmpty) are re-exported so 1.x importers keep them. One type-level break remains and is not configurable away: v7 makes nullable result fields non-optional, since such fields can only be null at runtime, never undefined. Combined with the now-required __typename, code that *constructs* result objects (test fixtures, mocks) must add __typename and spell out nullable fields. Reading responses is unaffected, including __typename union narrowing over result/error types. Claude-Session: https://claude.ai/code/session_01XAMVwbhshgNFmGj4sL18x7
src/bin.ts (shipped as fragment-node-client-codegen, which customers run against their own schemas) uses the same plugin stack as src/codegen.ts and so hit the same v7 duplication: the generated client declared CurrencyCode as both an enum and a type and failed to compile with TS2567. Apply the same importSchemaTypesFrom treatment and strip the self-import and namespace prefix in the existing post-processing, so customer output stays a single flat file. Regenerate the test fixture accordingly. Claude-Session: https://claude.ai/code/session_01XAMVwbhshgNFmGj4sL18x7
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Targets a new
v1base branch cut from04507bf(the never-published 1.5.0 bump), so the v1 line can be released without touchingdev.Why
The seven Dependabot commits that landed after 1.4.0 only changed
resolutions. That field is Yarn-only and honored solely from the root project — it ships inside the tarball but is inert there. Consumers therefore resolved the same transitive tree as 1.4.0.A simulated consumer install of 1.5.0's dependencies audits at 17 high-severity advisories, rooted in
immutable <3.8.4andlodash <=4.17.23(the latter being exactly what the resolutions pinned to).Bumping
@graphql-codegen/clialone clears only 5 of 17 — theimmutableandlodashroots arrive viatypescript-graphql-requestandimport-types-preset, so all four codegen packages move together.clionlyBuild fixes required
auto-bind@5is ESM-only and codegen's CJS buildrequire()s it → pinned to4.0.0.typescript-operationsemits schema enums/inputs itself, duplicating thetypescriptplugin (188 TS errors).importSchemaTypesFromsuppresses that; pointing it at the output file and stripping the self-import andTypes.prefix in post-processing keeps a single flat file.src/bin.ts— thefragment-node-client-codegenCLI customers run against their own schemas. Without it, generated clients declareCurrencyCodeas both enum and type and fail to compile (TS2567).Public surface
Held steady: 38/38 SDK methods, no operation types removed, return types unchanged, 0 removed exports.
__typenamerestored viaaddTypename/nonOptionalTypename; the four codegen helpers (Exact,MakeOptional,MakeMaybe,MakeEmpty) re-exported for 1.x importers.One type-level break is not configurable away: v7 makes nullable result fields non-optional, since they can only be
nullat runtime, neverundefined. With the now-required__typename, code that constructs result objects (fixtures, mocks) must add__typenameand spell out nullable fields. Reading responses is unaffected, including__typenameunion narrowing.Verification
Locally: build, typecheck, and both "up-to-date" gates pass on a clean tree. The 12 integration tests need
CLIENT_ID/CLIENT_SECRET, so this PR exists to run them.https://claude.ai/code/session_01XAMVwbhshgNFmGj4sL18x7