apollo-router

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Anomaly
AnomalyLOW
templates/v2/development.yaml

The fragment is a development-only router configuration and contains no evident malware or intentional supply-chain backdoor. Its main risks are insecure deployment settings: permissive CORS, unrestricted request-header propagation, detailed subgraph error disclosure, and enabled introspection/sandbox. The localhost bindings substantially reduce exposure in the shown configuration, but these settings should not be reused for a publicly reachable production router.

Confidence: 98%Severity: 57%
Audit Metadata
Analyzed At
Sep 15, 2026, 02:52 PM
Package URL
pkg:socket/skills-sh/apollographql%2Fskills%2Fapollo-router%2F@38dcdb383bce69881acf5e01632323e462c3252db304e332f6c787c06c4f46f8
Security Audit — socket — apollo-router