NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #3061 most downloaded on npm
A set of utils for faster development of GraphQL tools
Last release 23 days ago
11 Sep 2026
Ships fairly regularly
a new release about every 4 weeks
Rarely documented
notes for 7 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
4 years old
2277 releases · first in 2022
One column per quarter.
@graphql-tools/executor-http@3.4.1
@graphql-tools/executor-http@3.4.1
#2485 47fe3d6 Thanks @adam-drag! - Release the connection when an SSE subscription is torn down
handleEventStreamResponse called reader.releaseLock() on normal teardown,
which detaches the reader but leaves the response body un-cancelled, so the
underlying HTTP connection was never released and the socket stayed open until
the process exited. Long-running consumers accumulated one leaked connection per
disposed subscription.
It now calls reader.cancel(), which propagates cancellation and closes the
connection. The error path already used cancel(); only the normal path did not.
Closes https://github.com/graphql-hive/gateway/issues/2486
Nothing published for this version
Nothing published for this version
Nothing published for this version
@graphql-tools/executor-http@3.4.0
@graphql-tools/executor-http@3.4.0
#2604 ee4cc07 Thanks @enisdenjo! - Support GraphQL 16 with @graphql-tools/utils v12
Preserves GraphQL 16 compatibility while upgrading to @graphql-tools/utils v12, @graphql-tools/executor v2, and the compatible @graphql-tools/schema and @graphql-tools/merge releases. Consumers now receive consistent resolver and execution request types without conflicts between different GraphQL Tools versions.
Stitched and delegated operations handle the new executor variable result shape correctly, including variables used by directives. Resolver execution also supports the executor's cancellation and asynchronous work helpers while remaining compatible with the GraphQL 16 GraphQLResolveInfo API.
#2604 ee4cc07 Thanks @enisdenjo! - dependencies updates:
@graphql-tools/utils@^12.0.1 ↗︎ (from ^11.0.0, in dependencies)Updated dependencies [ee4cc07, ee4cc07]:
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Add the useContentTypeForGETRequests opt-in for GET requests that need content-type: application/json compatibility.
#2334 0f8706c Thanks @copilot-swe-agent! - Add useGETForHashedQueries support for downstream APQ requests so hash-only
query probes can use GET while full-query fallbacks continue to use POST.
Add the useContentTypeForGETRequests opt-in for GET requests that need
content-type: application/json compatibility.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
`786e06f` Thanks @ardatan! - Do not recursively return HTTP extensions
Nothing published for this version
Nothing published for this version
Nothing published for this version
@graphql-tools/executor-graphql-ws@3.2.0
@graphql-tools/executor-graphql-ws@3.2.0
#2211 59ef8f7 Thanks @ardatan! - Add exposeHTTPDetailsInExtensions flag to get Response details in the result extensions.
import { buildHTTPExecutor } from '@graphql-tools/executor-http';
const executor = buildHTTPExecutor({
exposeHTTPDetailsInExtensions: true,
});
Then in the result;
{
"data": {
"hello": "world"
},
"extensions": {
"request": {
"url": "http://localhost:4000/graphql",
"method": "POST",
"headers": {
"content-type": "application/json"
},
"body": "{\"query\":\"{ hello }\"}"
},
"response": {
"status": 200,
"statusText": "OK",
"headers": {
"content-type": "application/json"
}
}
}
}
f9d2f0e Thanks @ManrajSingh6! - Prevent reusing the cached inflight requests#2185 f85a9fe Thanks @elliotvilhelm! - Fix SSE data parsing when JSON payload contains literal "data:" substrings
The SSE event parser used msg.split('data:') to extract the data field, which
incorrectly splits on data: substrings inside the JSON payload (e.g., OAuth
scopes like file_metadata:read, data URIs like data:image/png). This caused
JSON.parse to fail with "Unterminated string in JSON" errors.
The fix uses line-based parsing per the SSE spec: split on newlines first, then
find the line starting with data:.
dae3fe4 Thanks @copilot-swe-agent! - Fix missing NPM provenance attestation by enabling npmPublishProvenance in Yarn configuration9f29d58 Thanks @ardatan! - Support factory function in timeout option so that you can set timeout milliseconds dynamically per ExecutionRequest;
buildHTTPExecutor({
timeout: (request) => {
if (request.operationName === 'BigQuery') {
return 10000; // 10 seconds for the `BigQuery` operation
}
// Or infinite timeout for subscriptions
if (request.operationType === 'subscription') {
return undefined;
}
return 5000; // 5 seconds for other operations
},
});
#1842 93aa767 Thanks @dependabot! - dependencies updates:
@graphql-tools/utils@^11.0.0 ↗︎ (from ^10.10.3, in dependencies)Updated dependencies [93aa767]:
#1684 478d7e2 Thanks @dependabot! - dependencies updates:
@whatwg-node/fetch@^0.10.13 ↗︎ (from ^0.10.12, in dependencies)#1691 7ecaf7e Thanks @dependabot! - dependencies updates:
@graphql-tools/utils@^10.10.3 ↗︎ (from ^10.10.1, in dependencies)#1347 2993f24 Thanks @ardatan! - Avoid shared AbortController instance on CloudflareWorkers because it gives Cannot perform I/O on behalf of a different request. error.
This change ensures that the AbortController is only created when not running in a Cloudflare Workers environment.
Updated dependencies [7ecaf7e]:
#1608 9c789fb Thanks @ardatan! - dependencies updates:
@graphql-tools/utils@^10.10.1 ↗︎ (from ^10.9.1, in dependencies)@whatwg-node/fetch@^0.10.12 ↗︎ (from ^0.10.11, in dependencies)#1662 27789de Thanks @ardatan! - dependencies updates:
@graphql-tools/utils@^10.10.1 ↗︎ (from ^10.10.0, in dependencies)@whatwg-node/fetch@^0.10.12 ↗︎ (from ^0.10.11, in dependencies)c754a96 Thanks @ardatan! - Use more specific error codes;
GATEWAY_TIMEOUT -> Server could not get a response from upstream in time
SUBREQUEST_HTTP_ERROR -> An error occurred while making the HTTP request to the upstream
RESPONSE_VALIDATION_FAILED -> The response from upstream did not conform to the expected GraphQL response format
Updated dependencies [9c789fb, 27789de, 3f6b99d]:
#1654 efed5e0 Thanks @dependabot! - dependencies updates:
@graphql-tools/utils@^10.10.0 ↗︎ (from ^10.9.1, in dependencies)Updated dependencies [efed5e0]:
#1542 0a349fb Thanks @dependabot! - dependencies updates:
@whatwg-node/fetch@^0.10.11 ↗︎ (from ^0.10.10, in dependencies)d7b48a7]:
#1473 838ffec Thanks @dependabot! - dependencies updates:
@whatwg-node/promise-helpers@^1.3.2 ↗︎ (from ^1.3.0, in dependencies)#1495 fe99f74 Thanks @dependabot! - dependencies updates:
meros@^1.3.2 ↗︎ (from ^1.3.1, in dependencies)b0e5568]:
#956 46d2661 Thanks @EmrysMyrddin! - Drop Node 18 support
Least supported Node version is now v20.
#956 46d2661 Thanks @EmrysMyrddin! - Inflight request deduplication
Updated dependencies [46d2661]:
#1411 37113d1 Thanks @dependabot! - dependencies updates:
@whatwg-node/fetch@^0.10.10 ↗︎ (from ^0.10.9, in dependencies)#1358 8e37851 Thanks @dependabot! - dependencies updates:
@graphql-tools/utils@^10.9.1 ↗︎ (from ^10.9.0, in dependencies)Updated dependencies [8e37851]:
b59a266 Thanks @ardatan! - endpoint can now also be a factory function that returns the endpoint based on the ExecutionRequest. This allows creating dynamic endpoints, depending on environment variables or other runtime values.#1338 7287ffa Thanks @enisdenjo! - dependencies updates:
@whatwg-node/fetch@^0.10.9 ↗︎ (from ^0.10.8, in dependencies)#1344 a71236d Thanks @dependabot! - dependencies updates:
@graphql-tools/utils@^10.9.0 ↗︎ (from ^10.8.1, in dependencies)Updated dependencies [6215001, a71236d]:
ed323fa Thanks @dependabot! - dependencies updates:
meros@^1.3.1 ↗︎ (from ^1.2.1, in dependencies)54beb7a Thanks @ardatan! - dependencies updates:
@whatwg-node/fetch@^0.10.8 ↗︎ (from ^0.10.6, in dependencies)#1124 b7627d3 Thanks @enisdenjo! - Handle server sent events stream chunk containing multiple events
#1121 ef0e24c Thanks @enisdenjo! - Gracefully handle event stream reading errors and cancellations
#1124 b7627d3 Thanks @enisdenjo! - Flush incoming chunk before closing the stream
#997 4cf75cb Thanks @ardatan! - - BREAKING: HTTP Executor no longer takes serviceName as an option.
@graphql-mesh/transport-http-callback no longer handle DOWNSTREAM_SERVICE_ERROR error code with serviceName.DOWNSTREAM_SERVICE_ERROR error code and serviceName as a property. This behavior can be configured with subgraphErrors option of the createGatewayRuntime function or CLI config.subgraphError: {
errorCode: 'DOWNSTREAM_SERVICE_ERROR', // or `false` to remove this code completely
subgraphNameProp: 'serviceName' // or `false` to remove this prop completely
}
#1045 da47a0e Thanks @enisdenjo! - dependencies updates:
@whatwg-node/fetch@^0.10.6 ↗︎ (from ^0.10.4, in dependencies)#1045 da47a0e Thanks @enisdenjo! - Update graphql-yoga and whatwg-node packages
In light of https://github.com/ardatan/whatwg-node/pull/2305. Please upgrade as soon as possible!
#1015 9a120c8 Thanks @ardatan! - Add TypeError to originalError prop of the error thrown when no data and errors found in the HTTP response, then GraphQL Servers know that it is an unexpected error so it should be masked and logged separately instead of leaking to the client
c7ea2c5 Thanks @kroupacz! - Errors should not be swallowed when it is thrown from the shared root#532 4e33933 Thanks @EmrysMyrddin! - dependencies updates:
@whatwg-node/promise-helpers@^1.3.0 ↗︎ (from ^1.2.5, in dependencies)#922 c9cd206 Thanks @enisdenjo! - dependencies updates:
@graphql-hive/signal@workspace:^ ↗︎ (to dependencies)#929 dbfb0f7 Thanks @ardatan! - Throw an understandable error with HTTP details when the response is empty
Updated dependencies [c9cd206]:
278618a Thanks @ardatan! - dependencies updates:
@whatwg-node/promise-helpers@^1.2.5 ↗︎ (from ^1.0.0, in dependencies)9c2f323 Thanks @ardatan! - Ensure subgraph name is present in the upstream error extensions when HTTP Executor throws#726 6334b2e Thanks @ardatan! - dependencies updates:
@whatwg-node/promise-helpers@^1.0.0 ↗︎ (to dependencies)#727 c54a080 Thanks @renovate! - dependencies updates:
@whatwg-node/disposablestack@^0.0.6 ↗︎ (from ^0.0.5, in dependencies)#773 d949143 Thanks @renovate! - dependencies updates:
extract-files@^11.0.0 ↗︎ (from dependencies)#791 661b103 Thanks @ardatan! - dependencies updates:
value-or-promise@^1.0.12 ↗︎ (from dependencies)Updated dependencies [e393337]:
#696 a289faa Thanks @ardatan! - dependencies updates:
@whatwg-node/fetch@^0.10.4 ↗︎ (from ^0.10.1, in dependencies)#709 20d275c Thanks @renovate! - Subscription cancellation fix for Bun
Updated dependencies [a289faa]:
#620 d72209a Thanks @renovate! - dependencies updates:
@graphql-tools/utils@^10.8.1 ↗︎ (from ^10.7.0, in dependencies)Updated dependencies [d72209a]:
#598 8c80ac9 Thanks @ardatan! - dependencies updates:
@graphql-hive/gateway-abort-signal-any@workspace:^ ↗︎ (from dependencies)#598 8c80ac9 Thanks @ardatan! - Use native AbortSignal, AbortController APIs instead of custom ones
#420 14152f7 Thanks @ardatan! - - In case of schema reload, throw SCHEMA_RELOAD error while recreating the transports and executors
SHUTTING_DOWN error while cleaning the transports and executors upPreviously, these errors are only thrown for subscriptions not it is thrown in other type of operations as well. And previously the thrown errors during these two cleanup and restart process were cryptic, now the mentioned two errors above are thrown with more clear messages
c60a8f4]:
#381 55eb1b4 Thanks @ardatan! - dependencies updates:
@graphql-tools/executor-common@workspace:^ ↗︎ (to dependencies)#381 55eb1b4 Thanks @ardatan! - This is a bugfix with some internal changes, no user action is needed. This bugfix and improvement is done to improve the stability of some components of the gateway;
Like HMAC Upstream Signature plugin, different components of the gateway were using different ways of serializing the execution request.
Some of them were ignoring variables if it is empty, some of not, this was causing the signature generation to be different for the same query.
For example, it was working as expected in Proxy mode, but not working as expected in Federation Gateway mode.
With this change, now we have a shared helper to serialize the upstream execution request with a memoized print function for query AST etc to have a consistent serialization so consistent signature generation for HMAC.
For example instead of using print, you should use defaultPrintFn that memoizes print operation and also used the string version of it parsed before by Envelop/Yoga.
-import { print } from 'graphql';
-const query = print(parsedQuery);
+import { defaultPrintFn } from '@graphql-tools/executor-common';
+const query = defaultPrintFn(parsedQuery);
Or instead of creating objects from ExecutionRequest, use serializeExecutionRequest helper.
-const serializedRequest = {
- query: print(executionRequest.document),
- variables: executionRequest.variables,
- operationName: executionRequest.operationName,
- extensions: executionRequest.extensions,
-};
+import { serializeExecutionRequest } from '@graphql-tools/executor-common';
+const serializedRequest = serializeExecutionRequest(executionRequest);
Updated dependencies [55eb1b4]:
#373 e606975 Thanks @ardatan! - dependencies updates:
@graphql-tools/utils@^10.7.0 ↗︎ (from ^10.6.2, in dependencies)#367 15975c2 Thanks @ardatan! - Fix the combination of upstreamRetry and upstreamTimeout together
When you use upstreamRetry and upstreamTimeout together, the upstreamRetry wasn't applied properly when the request is timed out with upstreamTimeout.
Updated dependencies [e606975, e606975]:
#322 23b8987 Thanks @ardatan! - dependencies updates:
@graphql-hive/gateway-abort-signal-any@workspace:^ ↗︎ (to dependencies)Updated dependencies [23b8987]:
#313 367b359 Thanks @ardatan! - Automatic Persisted Queries support for upstream requests
For HTTP Executor;
buildHTTPExecutor({
// ...
apq: true,
});
For Gateway Configuration;
export const gatewayConfig = defineConfig({
transportEntries: {
'*': {
options: {
apq: true,
},
},
},
});
34d1224 Thanks @ardatan! - dependencies updates:
tslib@^2.8.1 ↗︎ (from ^2.4.0, in dependencies)cdca511 Thanks @ardatan! - dependencies updates:
@graphql-tools/utils@^10.6.2 ↗︎ (from ^10.6.0, in dependencies)2e0add3 Thanks @ardatan! - dependencies updates:
@whatwg-node/fetch@^0.10.1 ↗︎ (from ^0.10.0, in dependencies)#164 310613d Thanks @ardatan! - dependencies updates:
@graphql-tools/utils@^10.6.0 ↗︎ (from ^10.5.6, in dependencies)#180 9438e21 Thanks @ardatan! - dependencies updates:
@whatwg-node/disposablestack@^0.0.5 ↗︎ (to dependencies)#180 9438e21 Thanks @ardatan! - Use new explicit resource management internally
#199 b534288 Thanks @ardatan! - Logs are now easier to read, bigger results not do not create bigger outputs but instead they are all logged in a single line
#98 697308d Thanks @ardatan! - Bun support by using native Bun API whenever possible
dc5043b]:
#6663
d06afe3
Thanks @renovate! - dependencies updates:
@whatwg-node/fetch@^0.10.0 ↗︎
(from ^0.9.0, in dependencies)#6658
04d5cd7
Thanks @enisdenjo! - Cancel SSE stream even while waiting for next
event
cf2ce5e]:
f9dd3d6
Thanks @ardatan! - Details in the extensions when an unexpected
error occurs;
{
"request": {
"url": "https://api.example.com/graphql",
"method": "POST",
"body": {
"query": "query { hello }"
}
},
"response": {
"status": 500,
"statusText": "Internal Server Error",
"headers": {
"content-type": "application/json"
},
"body": {
"errors": [
{
"message": "Internal Server Error"
}
]
}
}
}
97c88a0
Thanks @enisdenjo! - Handle AggregateErrors by expanding them to
result errorsbec6eac
Thanks @renovate! - dependencies updates:
@graphql-tools/utils@^10.3.2 ↗︎
(from ^10.3.1, in dependencies)#6332
7be6930
Thanks @kamilkisiela! - Strip ignored characters when printing
a query in executor-http
Updated dependencies
[a276ba8]:
#6325
9792e80
Thanks @ardatan! - Make the executor disposable optional
Updated dependencies
[9792e80]:
#6299
b0ffac8
Thanks @EmrysMyrddin! - When proxying the requests to the HTTP
executor, it should return `GraphQLError` instances in `errors` array
46eab79
Thanks @ardatan! - Fixed potential leak on executor disposal
cacf20f
Thanks @ardatan! - Implement Symbol.dispose or Symbol.asyncDispose
to make `Executor`s `Disposable`cacf20f]:
83c0af0
Thanks @enisdenjo! - dependencies updates:
@graphql-tools/utils@^10.0.13 ↗︎
(from ^10.0.2, in dependencies)9d18cce
Thanks @enisdenjo! - Error when both data and errors fields are
empty12b578e
Thanks @felamaslen! - Fixed http executor to allow custom
content-type headerb798b3b
Thanks @ardatan! - Memoize the print result automatically, and able
to accept a custom print functioncfbd2e07
Thanks @enisdenjo! - Handle chunked and no-space messages in SSE#5396
bb8f169e
Thanks @ardatan! - dependencies updates:
dset@^3.1.2 ↗︎ (from
dependencies)#5396
bb8f169e
Thanks @ardatan! - Move the merging logic of incremental results to
the utils package
Updated dependencies
[bb8f169e,
bb8f169e]:
944a68e8
Thanks @ardatan! - dependencies updates:
@whatwg-node/fetch@^0.9.0 ↗︎
(from ^0.8.1, in dependencies)944a68e8,
944a68e8]:
26f6d221
Thanks @ardatan! - dependencies updates:
@whatwg-node/fetch@^0.8.1 ↗︎
(from ^0.8.0, in dependencies)1b948acc
Thanks @renovate! - dependencies updates:
@whatwg-node/fetch@^0.8.0 ↗︎
(from ^0.7.0, in dependencies)ab4cf86b
Thanks @renovate! - dependencies updates:
@whatwg-node/fetch@^0.7.0 ↗︎
(from ^0.6.9, in dependencies)b09ea282
Thanks @renovate! - dependencies updates:
@graphql-tools/utils@^9.2.0 ↗︎
(from 9.2.0, in dependencies)value-or-promise@^1.0.12 ↗︎ (from
1.0.12, in dependencies)@whatwg-node/fetch@^0.6.9 ↗︎
(from 0.6.5, in dependencies)@repeaterjs/repeater@^3.0.4 ↗︎
(from 3.0.4, in dependencies)dset@^3.1.2 ↗︎ (from
3.1.2, in dependencies)meros@^1.2.1 ↗︎ (from
1.2.1, in dependencies)b5c8f640]:
034b868f
Thanks @renovate! - dependencies updates:
@whatwg-node/fetch@0.6.5 ↗︎ (from
0.6.2, in dependencies)d9bcb5b6
Thanks @renovate! - dependencies updates:
@whatwg-node/fetch@0.6.2 ↗︎ (from
0.6.1, in dependencies)#4941
0e5d250c
Thanks @renovate! - dependencies updates:
@whatwg-node/fetch@0.6.1 ↗︎ (from
0.5.4, in dependencies)#4943
a4d36fcc
Thanks @renovate! - dependencies updates:
value-or-promise@1.0.12 ↗︎ (from
1.0.11, in dependencies)Updated dependencies
[e3ec35ed]:
d0383dd6
Thanks @renovate! - dependencies updates:
@whatwg-node/fetch@0.5.4 ↗︎ (from
0.5.3, in dependencies)#4887
904fe770
Thanks @ardatan! - Fix leak on Node 14 and add cancellation to async
iterables correctly
Updated dependencies
[904fe770]:
13c24883]:
92dd4714
Thanks @renovate! - dependencies updates:
@whatwg-node/fetch@0.5.3 ↗︎ (from
0.5.1, in dependencies)7411a5e7]:
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →