← Home

@aahoughton/oav

HTTP-aware OpenAPI request/response validator. Batteries-included distribution: re-exports @aahoughton/oav-core, adds YAML readers, ships the `oav` CLI. For a zero-runtime-dep install, use @aahoughton/oav-core directly.

18
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

aahoughton

Keywords

api-validationclihttpjson-schemajson-schema-2020-12json-schema-validatoroasopenapiopenapi-3.0openapi-3.1openapi-3.2openapi-request-validatoropenapi-response-validatoropenapi-validatoropenapi3request-validatorresponse-validatorschemaswaggerswagger-validatorvalidationvalidatoryaml

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@aahoughton/oav-stream-validator AI (dependencies): Author's own scoped sibling package pinned at 1.0.0; consistent with monorepo. ai
provenance publisher-changed AI (provenance): Change is to GitHub Actions CI publisher with SLSA provenance, not an account handoff. ai
publish-pattern new-deps-added AI (publish-pattern): New dep is a same-org sibling package (@aahoughton/oav-stream-validator), not a third-party addition. ai
typosquat typosquat.levenshtein:koa AI (typosquat): oav is an OpenAPI validator acronym, not a typosquat of koa; scoped package with legitimate purpose. ai
typosquat typosquat.levenshtein:ajv AI (typosquat): oav is an OpenAPI validator acronym, not a typosquat of ajv; scoped package with legitimate purpose. ai

Versions (showing 18 of 18)

Version Deps Published
3.8.0 4 / 0
3.7.0 4 / 0
3.6.0 4 / 0
3.5.0 3 / 0
3.4.0 3 / 0
3.3.0 3 / 0
3.2.0 3 / 0
3.1.0 3 / 0
3.0.0 3 / 0
2.4.0 3 / 0
2.3.0 3 / 0
2.2.1 4 / 10
2.2.0 4 / 10
2.1.0 4 / 9
2.0.0 4 / 9
1.1.1 4 / 9
1.1.0 4 / 9
1.0.0 4 / 9

v3.8.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.7.0

2 findings
HIGH Publisher changed: aahoughton → GitHub Actions (on 2026-06-25) provenance

This version was published by a different npm account than previous versions on 2026-06-25. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.