@mintlify/validation
Validates mint.json files
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Transition from human publisher to GitHub Actions CI is a documented legitimate pattern for this established Mintlify package. | ai | |
| phantom-deps | phantom-dep:js-yaml | AI (phantom-deps): js-yaml is explicitly declared as a direct dependency in package.json; the phantom-dep finding is a false positive for this package. | ai | |
| dependencies | unvetted-dep:lcm | AI (dependencies): lcm is a small math utility pinned at 0.0.3 with @types/lcm in devDeps; intentional, typed usage with no malware signals. | ai | |
| typosquat | typosquat.levenshtein:validator | AI (typosquat): Scoped @mintlify/validation package is clearly named for its purpose (validating mint.json files), not impersonating the 'validator' package. False positive for this namespace. | ai | |
| dependencies | unvetted-dep:@mintlify/mdx | AI (dependencies): First-party Mintlify package within the same organization; not a third-party unvetted dependency. | ai | |
| dependencies | unvetted-dep:@mintlify/models | AI (dependencies): First-party Mintlify package within the same organization; not a third-party unvetted dependency. | ai |
Versions (showing 51 of 386)
| Version | Deps | Published |
|---|---|---|
| 0.1.743 | 13 / 16 | |
| 0.1.742 | 13 / 16 | |
| 0.1.741 | 13 / 16 | |
| 0.1.740 | 13 / 16 | |
| 0.1.739 | 12 / 16 | |
| 0.1.738 | 12 / 16 | |
| 0.1.737 | 12 / 16 | |
| 0.1.736 | 12 / 16 | |
| 0.1.735 | 12 / 16 | |
| 0.1.734 | 12 / 16 | |
| 0.1.733 | 12 / 16 | |
| 0.1.732 | 12 / 16 | |
| 0.1.731 | 12 / 16 | |
| 0.1.729 | 12 / 16 | |
| 0.1.728 | 12 / 16 | |
| 0.1.727 | 12 / 16 | |
| 0.1.726 | 12 / 16 | |
| 0.1.725 | 12 / 16 | |
| 0.1.724 | 12 / 16 | |
| 0.1.723 | 12 / 16 | |
| 0.1.722 | 12 / 16 | |
| 0.1.721 | 12 / 16 | |
| 0.1.720 | 12 / 16 | |
| 0.1.719 | 12 / 16 | |
| 0.1.718 | 12 / 16 | |
| 0.1.717 | 12 / 16 | |
| 0.1.716 | 12 / 14 | |
| 0.1.715 | 12 / 14 | |
| 0.1.714 | 12 / 14 | |
| 0.1.713 | 12 / 14 | |
| 0.1.712 | 12 / 14 | |
| 0.1.711 | 12 / 14 | |
| 0.1.710 | 12 / 14 | |
| 0.1.709 | 12 / 16 | |
| 0.1.708 | 12 / 16 | |
| 0.1.707 | 12 / 16 | |
| 0.1.706 | 12 / 16 | |
| 0.1.705 | 12 / 16 | |
| 0.1.704 | 12 / 16 | |
| 0.1.703 | 12 / 16 | |
| 0.1.702 | 12 / 16 | |
| 0.1.701 | 12 / 16 | |
| 0.1.700 | 12 / 16 | |
| 0.1.699 | 12 / 16 | |
| 0.1.698 | 12 / 16 | |
| 0.1.697 | 12 / 16 | |
| 0.1.696 | 12 / 16 | |
| 0.1.695 | 12 / 16 | |
| 0.1.694 | 12 / 16 | |
| 0.1.693 | 12 / 16 | |
| 0.1.692 | 12 / 16 |
v0.1.743
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.742
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.741
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.740
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.739
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.738
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.737
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.736
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.735
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.734
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.733
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.732
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.731
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.729
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.728
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.727
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.726
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.725
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.724
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.723
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.722
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.721
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.720
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.719
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.718
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.717
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.716
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.715
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.714
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.713
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.712
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.711
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.710
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.709
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.708
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.707
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.706
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.705
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.704
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.703
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.702
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.701
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.700
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.699
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.698
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.697
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.696
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.695
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.694
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.693
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.692
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.