Skip to content

Fix consumer-facing CVEs by upgrading graphql-codegen to v7 - #92

Merged
vigneshwerv merged 2 commits into
v1from
fix/v1-consumer-cves
Sep 24, 2026
Merged

vigneshwerv merged 2 commits into
v1from
fix/v1-consumer-cves

Conversation

@vigneshwerv

Copy link
Copy Markdown
Contributor

Targets a new v1 base branch cut from 04507bf (the never-published 1.5.0 bump), so the v1 line can be released without touching dev.

Why

The seven Dependabot commits that landed after 1.4.0 only changed resolutions. That field is Yarn-only and honored solely from the root project — it ships inside the tarball but is inert there. Consumers therefore resolved the same transitive tree as 1.4.0.

A simulated consumer install of 1.5.0's dependencies audits at 17 high-severity advisories, rooted in immutable <3.8.4 and lodash <=4.17.23 (the latter being exactly what the resolutions pinned to).

Bumping @graphql-codegen/cli alone clears only 5 of 17 — the immutable and lodash roots arrive via typescript-graphql-request and import-types-preset, so all four codegen packages move together.

vulnerabilities
baseline 17 high
cli only 12 high
all four 0

Build fixes required

  • auto-bind@5 is ESM-only and codegen's CJS build require()s it → pinned to 4.0.0.
  • codegen v7's typescript-operations emits schema enums/inputs itself, duplicating the typescript plugin (188 TS errors). importSchemaTypesFrom suppresses that; pointing it at the output file and stripping the self-import and Types. prefix in post-processing keeps a single flat file.
  • The same fix applies to src/bin.ts — the fragment-node-client-codegen CLI customers run against their own schemas. Without it, generated clients declare CurrencyCode as both enum and type and fail to compile (TS2567).

Public surface

Held steady: 38/38 SDK methods, no operation types removed, return types unchanged, 0 removed exports. __typename restored via addTypename/nonOptionalTypename; the four codegen helpers (Exact, MakeOptional, MakeMaybe, MakeEmpty) re-exported for 1.x importers.

One type-level break is not configurable away: v7 makes nullable result fields non-optional, since they can only be null at runtime, never undefined. With the now-required __typename, code that constructs result objects (fixtures, mocks) must add __typename and spell out nullable fields. Reading responses is unaffected, including __typename union narrowing.

Verification

Locally: build, typecheck, and both "up-to-date" gates pass on a clean tree. The 12 integration tests need CLIENT_ID/CLIENT_SECRET, so this PR exists to run them.

https://claude.ai/code/session_01XAMVwbhshgNFmGj4sL18x7

The seven Dependabot commits that landed after 1.4.0 only changed
`resolutions`, which is Yarn-only and honored solely from the root project.
It ships inside the tarball but is inert there, so consumers resolved the
exact same transitive tree as 1.4.0: 17 high-severity advisories, rooted in
immutable <3.8.4 and lodash <=4.17.23 (the latter being the version the
resolutions pinned to).

Fixing that requires moving the direct dependency ranges. Bumping
@graphql-codegen/cli alone clears only 5 of 17; the immutable and lodash
roots come in via typescript-graphql-request and import-types-preset, so all
four codegen packages have to move together. With them bumped a simulated
consumer install audits clean (17 high -> 0).

Two build fixes were needed:

- auto-bind@5 is ESM-only and codegen's CJS build require()s it, so it is
  pinned to 4.0.0.
- codegen v7's typescript-operations emits schema enums and inputs itself,
  duplicating the typescript plugin (188 TS errors). `importSchemaTypesFrom`
  suppresses that; pointing it at the output file and stripping the
  self-import and namespace prefix in the existing post-processing keeps the
  output a single flat file.

Public surface is held steady where possible: 38/38 SDK methods, no
operation types removed, return types unchanged, and 0 removed exports.
__typename is restored via addTypename/nonOptionalTypename, and the four
codegen helper types (Exact, MakeOptional, MakeMaybe, MakeEmpty) are
re-exported so 1.x importers keep them.

One type-level break remains and is not configurable away: v7 makes nullable
result fields non-optional, since such fields can only be null at runtime,
never undefined. Combined with the now-required __typename, code that
*constructs* result objects (test fixtures, mocks) must add __typename and
spell out nullable fields. Reading responses is unaffected, including
__typename union narrowing over result/error types.

Claude-Session: https://claude.ai/code/session_01XAMVwbhshgNFmGj4sL18x7
src/bin.ts (shipped as fragment-node-client-codegen, which customers run
against their own schemas) uses the same plugin stack as src/codegen.ts and
so hit the same v7 duplication: the generated client declared CurrencyCode
as both an enum and a type and failed to compile with TS2567.

Apply the same importSchemaTypesFrom treatment and strip the self-import and
namespace prefix in the existing post-processing, so customer output stays a
single flat file. Regenerate the test fixture accordingly.

Claude-Session: https://claude.ai/code/session_01XAMVwbhshgNFmGj4sL18x7
@vigneshwerv
vigneshwerv merged commit 9f0ab94 into v1 Sep 24, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant