- Accept and respond with JSON: No, why? what if I want to work with XML? or format X or Y?
- Use nouns instead of verbs in endpoint paths: I don't care about that
- Name collections with plural nouns: I don't care about that
- Nesting resources for hierarchical objects: No, why?
- Handle errors gracefully and return standard error codes: nothing to do with REST specifically.
- Allow filtering, sorting, and pagination: yes, good luck coming up with the right query structure and sticking to it.
- Maintain Good Security Practices: nothing to do with REST specifically.
- Versioning our APIs: And here we are. How many HATEOAS people claimed it was blasphemy and it missed the point of REST?
None of these are an issue with GraphQL, just like they weren't an issue with SOAP. You get a schema both the client and the server must agree with, end of story.
As I said to a dev once, if your 'best practices' can't be automated with a CI tool, then you need to worry about creating that tool first...