@sushindustries/github
0.1.07 viewsGitHub as an Apollo Connectors provider: a schema that composes into any supergraph and answers from GitHub's public REST API, with no resolvers and no token.
pnpm add @sushindustries/githubGitHub as an Apollo Connectors provider. One schema file, no resolvers, no server, no token.
Install
pnpm add @sushindustries/githubThen compose it into your supergraph:
federation_version: =2.12.0
subgraphs:
github:
routing_url: http://localhost
schema:
file: node_modules/@sushindustries/github/schema.graphqlrover supergraph compose --config ./supergraph.yamlWhat it answers
query {
repository(owner: "sushindustries", name: "sushindustries") {
nameWithOwner
stars
pushedAt
commits(limit: 5) { sha message author committedAt }
pullRequests(limit: 5) { number title draft author }
workflowRuns(limit: 5) { name status conclusion branch }
}
repositories(owner: "sushindustries", limit: 10) { name stars pushedAt }
}Repository is an entity keyed on owner and name, so anything else in your
supergraph that knows those two can hand over a stub and get the rest back.
No token, on purpose
Every endpoint here is public. There is no authorization header, and adding
one is not an improvement anybody should make casually: Connectors cannot omit
a header conditionally, so a Bearer {$env.GITHUB_TOKEN} with the variable
unset sends Bearer and GitHub answers 401 Bad credentials on every call.
That version composed cleanly and failed on the first request.
The unauthenticated ceiling is sixty requests an hour. A deployment that needs more should add the header in its own router configuration, where it can be sure the value exists.
Checking it
rover supergraph compose --config ./supergraph.yaml # composes
rover connector run --schema schema.graphql \
-c "Query.repository" \
-v '{"$args": {"owner": "sushindustries", "name": "sushindustries"}}'
rover connector test # 20 assertionsThe tests mock GitHub rather than calling it. A test that hits GitHub tests
GitHub: it goes red when somebody else deploys, and it spends the rate limit
this provider is built around. rover connector run is there for checking
against the real thing.