@redocly/openapi-docs
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Publisher shifted to GitHub Actions CI, consistent with legitimate CI/CD publishing. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Established Redocly package; missing README/repo metadata is a packaging quirk, not spam. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Publisher has strong track record; consistent with legitimate Redocly team transition. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): web-vitals is a well-known, benign Google metrics library. | ai | |
| phantom-deps | phantom-dep:prismjs | AI (phantom-deps): Used via config/highlighting, not direct import; long-standing pattern. | ai | |
| source-diff | obfuscated-file:lib/services/code-samples/httpsnippet/helpers/device-auth-snippets.js | AI (source-diff): Minified but fully readable OAuth2 device-flow code generation; no malicious patterns present. | ai | |
| source-diff | encoded-string-file:dist/redocly-openapi-docs.min.js | AI (source-diff): Minified bundle; encoded strings are normal build output for this package. | ai | |
| phantom-deps | phantom-dep:tslib | AI (phantom-deps): Known implicit runtime dependency; stable for this package. | ai | |
| phantom-deps | phantom-dep:path-browserify | AI (phantom-deps): Config-referenced dependency; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:jstoxml | AI (phantom-deps): Config-referenced dependency; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:swagger2openapi | AI (phantom-deps): Declared dep; phantom-dep heuristic misfires on bundled output. | ai | |
| semgrep | semgrep:shady-links-raw-ip | AI (semgrep): False positive on minified JSX bundle; no actual raw IP URL present in the sample. | ai | |
| phantom-deps | phantom-dep:@redocly/openapi-core | AI (phantom-deps): Same-org scoped package; phantom-dep heuristic misfires on bundled output. | ai | |
| phantom-deps | phantom-dep:stringify-object | AI (phantom-deps): Declared dep; phantom-dep heuristic misfires on bundled output. | ai | |
| phantom-deps | phantom-dep:util | AI (phantom-deps): Declared dep used in config/build context; phantom-dep heuristic misfires on bundled output. | ai | |
| phantom-deps | phantom-dep:slugify | AI (phantom-deps): Declared dep; phantom-dep heuristic misfires on bundled output. | ai | |
| phantom-deps | phantom-dep:deepmerge | AI (phantom-deps): Declared dep; phantom-dep heuristic misfires on bundled output. | ai | |
| phantom-deps | phantom-dep:dompurify | AI (phantom-deps): Declared dep; phantom-dep heuristic misfires on bundled output. | ai | |
| phantom-deps | phantom-dep:web-vitals | AI (phantom-deps): Declared dep; phantom-dep heuristic misfires on bundled output. | ai | |
| phantom-deps | phantom-dep:json-pointer | AI (phantom-deps): Declared dep; phantom-dep heuristic misfires on bundled output. | ai | |
| phantom-deps | phantom-dep:url-template | AI (phantom-deps): Declared dep; phantom-dep heuristic misfires on bundled output. | ai | |
| phantom-deps | phantom-dep:fast-deep-equal | AI (phantom-deps): Declared dep; phantom-dep heuristic misfires on bundled output. | ai | |
| phantom-deps | phantom-dep:fast-xml-parser | AI (phantom-deps): Declared dep; phantom-dep heuristic misfires on bundled output. | ai |
Versions (showing 100 of 125)
| Version | Deps | Published |
|---|---|---|
| 3.23.0 | 22 / 28 | |
| 3.22.1 | 22 / 28 | |
| 3.22.0 | 22 / 28 | |
| 3.21.0 | 21 / 30 | |
| 3.20.1 | 21 / 30 | |
| 3.20.0 | 21 / 30 | |
| 3.19.1 | 20 / 30 | |
| 3.19.0 | 20 / 30 | |
| 3.18.2 | 20 / 31 | |
| 3.18.1 | 20 / 31 | |
| 3.18.0 | 20 / 31 | |
| 3.17.1 | 20 / 31 | |
| 3.17.0 | 20 / 31 | |
| 3.16.1 | 18 / 37 | |
| 3.16.0 | 18 / 37 | |
| 3.15.0 | 18 / 36 | |
| 3.12.3 | 18 / 35 | |
| 3.12.2 | 18 / 35 | |
| 3.12.1 | 18 / 35 | |
| 3.12.0 | 18 / 35 | |
| 3.11.0 | 18 / 35 | |
| 3.10.3 | 24 / 44 | |
| 3.10.2 | 24 / 44 | |
| 3.10.1 | 24 / 44 | |
| 3.10.0 | 24 / 44 | |
| 3.9.1 | 24 / 44 | |
| 3.9.0 | 24 / 44 | |
| 3.8.0 | 22 / 46 | |
| 3.7.0 | 23 / 49 | |
| 3.6.3 | 22 / 49 | |
| 3.6.2 | 22 / 49 | |
| 3.6.1 | 22 / 49 | |
| 3.6.0 | 22 / 49 | |
| 3.5.20 | 22 / 49 | |
| 3.5.19 | 22 / 49 | |
| 3.5.18 | 22 / 49 | |
| 3.5.17 | 23 / 49 | |
| 3.5.16 | 23 / 49 | |
| 3.5.15 | 23 / 49 | |
| 3.5.14 | 23 / 49 | |
| 3.5.13 | 23 / 49 | |
| 3.5.12 | 23 / 49 | |
| 3.5.11 | 23 / 49 | |
| 3.5.10 | 23 / 49 | |
| 3.5.9 | 23 / 49 | |
| 3.5.8 | 23 / 49 | |
| 3.5.7 | 23 / 49 | |
| 3.5.6 | 23 / 46 | |
| 3.5.5 | 23 / 46 | |
| 3.5.4 | 23 / 46 | |
| 3.5.3 | 23 / 46 | |
| 3.5.2 | 23 / 46 | |
| 3.5.1 | 23 / 46 | |
| 3.5.0 | 23 / 46 | |
| 3.4.20 | 23 / 46 | |
| 3.4.19 | 23 / 46 | |
| 3.4.18 | 23 / 46 | |
| 3.4.17 | 23 / 46 | |
| 3.4.16 | 23 / 46 | |
| 3.4.15 | 23 / 46 | |
| 3.4.14 | 23 / 46 | |
| 3.4.13 | 23 / 46 | |
| 3.4.12 | 24 / 46 | |
| 3.4.11 | 24 / 46 | |
| 3.4.10 | 24 / 46 | |
| 3.4.9 | 24 / 46 | |
| 3.4.8 | 24 / 46 | |
| 3.4.7 | 24 / 46 | |
| 3.4.6 | 24 / 46 | |
| 3.4.5 | 24 / 46 | |
| 3.4.4 | 24 / 46 | |
| 3.4.3 | 24 / 45 | |
| 3.4.2 | 24 / 45 | |
| 3.4.1 | 24 / 45 | |
| 3.4.0 | 24 / 45 | |
| 3.3.24 | 24 / 45 | |
| 3.3.23 | 24 / 45 | |
| 3.3.22 | 24 / 45 | |
| 3.3.21 | 24 / 45 | |
| 3.3.20 | 24 / 45 | |
| 3.3.19 | 24 / 45 | |
| 3.3.18 | 24 / 45 | |
| 3.3.17 | 24 / 45 | |
| 3.3.16 | 24 / 45 | |
| 3.3.15 | 23 / 45 | |
| 3.3.14 | 23 / 45 | |
| 3.3.13 | 23 / 45 | |
| 3.3.12 | 23 / 45 | |
| 3.3.11 | 23 / 45 | |
| 3.3.10 | 23 / 45 | |
| 3.3.9 | 23 / 45 | |
| 3.3.8 | 23 / 45 | |
| 3.3.7 | 23 / 45 | |
| 3.3.6 | 23 / 45 | |
| 3.3.5 | 23 / 45 | |
| 3.3.4 | 23 / 45 | |
| 3.3.3 | 23 / 45 | |
| 3.3.2 | 23 / 45 | |
| 3.3.1 | 23 / 45 | |
| 3.3.0 | 23 / 45 |
v3.23.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.19.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.19.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.18.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.18.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.18.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.17.1
2 findingsThis version was published by a different npm account than previous versions on 2026-01-13. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.17.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.16.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.16.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.15.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.8.0
2 findingsThis version was published by a different npm account than previous versions on 2025-04-02. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.7.0
2 findingsThis version was published by a different npm account than previous versions on 2025-03-05. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.6.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.6.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.6.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.6.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.20
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.19
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.18
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.17
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.16
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.15
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.14
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.13
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.4.20
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.4.19
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.4.18
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.4.17
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.4.16
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.4.15
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.4.14
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.4.13
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.4.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.4.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.4.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.4.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.4.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.4.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.4.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.4.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.4.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.4.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.4.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.4.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.4.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.3.24
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.3.23
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.3.22
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.3.21
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.3.20
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.3.19
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.3.18
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.3.17
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.3.16
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.3.15
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.3.14
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.3.13
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.3.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.3.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.3.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.3.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.3.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.3.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.3.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.3.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.3.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.3.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.3.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.3.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.3.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.