Automic VaultAutomic Vault

brew

graphql-inspector を Homebrew でインストール

graphql-inspector のインストール経路、実行ファイル、メタデータ、AI エージェント向けセキュリティノートを確認します。

インストール

追加のインストールコマンド

macOS

Homebrew確認済み · 100%
brew install graphql-inspector

local Homebrew formula metadata

概要

パッケージ概要

Validate schema, get schema change notifications, validate operations, and more

コマンドとエイリアス

  • graphql-inspector

履歴

プロジェクトの歴史と使われ方

GraphQL Inspector is a suite of schema-management tools for GraphQL APIs. It compares schemas, classifies schema changes, validates operations and fragments, reports coverage, finds duplicate or similar types, and exposes those capabilities through a CLI, GitHub Action, and programmatic API.

Its package identity is strongly tied to CI: it turns GraphQL schema evolution into something package users can check before merge, rather than discovering broken operations at runtime.

プロジェクトの歴史

The Guild introduced GraphQL Inspector as part of its broader GraphQL tool stack after building Angular Apollo, GraphQL Code Generator, and GraphQL Modules. The introductory article described it as a tool for keeping a GraphQL API and its clients well developed, with schema comparison, schema coverage, operation validation, and GitHub integration.

The GitHub README and documentation kept the same core pitch: compare two schemas, explain each change as breaking, non-breaking, or dangerous, validate documents and fragments, and find similar or duplicated types. The project later moved under the graphql-hive GitHub organization while remaining part of The Guild's GraphQL tool family.

Over time GraphQL Inspector split functionality into packages such as core, cli, action, diff-command, validate-command, coverage-command, and loaders. That packaging model mirrors the tool's purpose: users can install the CLI for all features, the CI-focused packages for smaller automation, or the core API to build custom tooling.

採用の歴史

GraphQL Inspector gained traction where GraphQL schemas are versioned in Git and teams want pull requests to show API impact. The GitHub Action documentation describes checks that compare pull-request schema changes against a branch and annotate changes in code review.

The continuous-integration documentation emphasizes schema diffing as the common case and breaks features into installable commands and loaders for `.graphql` files, code files, JSON introspection, Git, GitHub, and GraphQL endpoints. This made the tool fit both monorepo and service-oriented workflows.

Its adoption also benefited from The Guild ecosystem. GraphQL CLI 4.1 named GraphQL Inspector alongside GraphQL Code Generator as a recommended workflow for production GraphQL applications, placing Inspector in a larger toolchain rather than as a one-off checker.

使われ方

The CLI is installed as `@graphql-inspector/cli` with the `graphql` peer dependency and run as `graphql-inspector`. Common commands include `diff`, `validate`, `coverage`, `similar`, `introspect`, and `serve`.

CI users often run `graphql-inspector diff` between a schema in Git and the schema produced by a branch. The GitHub Action variant can annotate changes and fail a pull request on breaking changes unless the workflow configuration allows them.

Programmatic users import functions such as `diff`, `validate`, and `coverage` from `@graphql-inspector/core`, which makes the tool useful inside custom release gates, dashboards, and registry-like workflows.

パッケージ好きにとっての重要性

GraphQL Inspector is a canonical example of GraphQL's schema-as-contract packaging problem. The package is not about serving requests; it is about preventing downstream clients from being surprised by schema changes.

Its split package layout is also package-nerd bait: core library, CLI, CI variant, action bundle, command packages, and loader packages all map neatly to different install sizes and automation targets.

For Homebrew users, it packages a JavaScript GraphQL CI tool as a system-level executable, which is handy for teams that prefer reproducible shell tooling outside per-project `node_modules`.

タイムライン

  • 2019: The Guild introduced GraphQL Inspector with schema comparison, coverage, validation, and GitHub integration.
  • 2020: The Guild published additional GraphQL Inspector guidance around remote control, environments, CI, schema notifications, and upcoming features.
  • 2020: GraphQL CLI 4.1 included GraphQL Inspector as part of recommended GraphQL development workflows.
  • 2020s: The project evolved into a multi-package tool with CLI, CI, Action, loaders, and core API packages.

Related projects

  • GraphQL Hive is the adjacent schema registry and monitoring project promoted in the GraphQL Inspector README.
  • GraphQL Code Generator often appears in the same workflow because one tool checks schema changes while the other generates typed client or server artifacts.
  • GraphQL CLI integrated Inspector features and helped position it as part of a broader GraphQL developer workflow.
  • Ruby's GraphQL Schema Comparator is named in the README as a source from which part of the library was ported.

セキュリティ状態

リスクレベル: グリーン

narrow executable package without higher-risk signals.

リスク分類器

リスク グリーン · 信頼度 低 · appliance

理由

  • narrow executable package without higher-risk signals

信号

  • metadata:no-higher-risk-signals

インストール挙動

  • formula メタデータに Homebrew post-install フックは記録されていません。
  • Homebrew bottle メタデータは 1 個のプラットフォームターゲットで利用できます。
  • 1 件の実行時依存関係とともにインストールされます。

推奨レビュー

エージェントに無人実行させる前に、このツールが平文の認証情報を読むか、リモート状態を書き込むか、成果物を公開するか、プラグインを起動するかを確認してください。

実行可能ファイル

インストールされる実行可能ファイル

コマンド種類公開範囲メモ
graphql-inspectorcliグローバル実行可能ファイル

鮮度

バージョンと鮮度

これらの信号は、ページ生成時期、パッケージマネージャの活動、上流リリース比較を分けて示します。バージョン遅れは、証拠 URL と比較可能なバージョンがある場合だけ警告されます。

ページ生成日2026-07-26
マネージャ版6.0.8
マネージャ更新日2026-05-02
ローカルデータOK
上流not checked
検出された最新未検出

https://the-guild.dev/graphql/inspector

インストールメタデータ

パッケージメタデータ

パッケージキーbrew:graphql-inspector
バージョン6.0.8
パッケージマネージャHomebrew
パッケージマネージャページhttps://formulae.brew.sh/formula/graphql-inspector
ホームページhttps://the-guild.dev/graphql/inspector
リポジトリhttps://github.com/graphql-hive/graphql-inspector
上流ドキュメントhttps://the-guild.dev/graphql/inspector/docs
ライセンスMIT
ソースアーカイブhttps://registry.npmjs.org/@graphql-inspector/cli/-/cli-6.0.8.tgz
最終更新2026-05-02T04:18:19Z
Pulseupdated
依存関係node
Bottle利用可能 (対象 all)
Homebrew post-install未定義
サービス宣言なし

レジストリ情報

ソースデータベース詳細

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Namegraphql-inspector
Version Scheme0
Revision0
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • stable

ソース経路

リポジトリデータから生成

このページは scripts/generate-pkg-sqlite.py が生成した非公開のパッケージ SQLite アーティファクトから av-web によって提供されます。

使用ソース

  • Geiger risk classifier
  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated package history
  • package relationship graph
  • package version freshness
  • package-page enrichment