← Home

@scalar/openapi-parser

100
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

cameronrohanimarclavescalar_geoffhwkrhanspagelamritkbgrcsscalar-machine

Keywords

openapiscalarswaggerparsertypescript

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:yaml AI (phantom-deps): Core parsing dep, likely bundled into dist. ai
phantom-deps phantom-dep:@types/node AI (phantom-deps): Type-only dep, expected phantom pattern. ai
phantom-deps phantom-dep:vite AI (phantom-deps): Build tool config dep, not runtime import. ai
phantom-deps phantom-dep:@hyperjump/json-schema AI (phantom-deps): Likely bundled into dist output. ai
phantom-deps phantom-dep:@hyperjump/browser AI (phantom-deps): Likely bundled into dist output. ai
npm-metadata suspicious-initial-version AI (npm-metadata): 0.0.0 is this monorepo's convention for internal packages, not malicious signal. ai
phantom-deps phantom-dep:chalk AI (phantom-deps): Likely used in CLI/build scripts, false positive. ai
phantom-deps phantom-dep:openapi-types AI (phantom-deps): Type-only dep, false positive. ai
phantom-deps phantom-dep:@humanwhocodes/momoa AI (phantom-deps): AST parsing dep for JSON, false positive on import scan. ai
phantom-deps phantom-dep:leven AI (phantom-deps): Legit small utility dep, false positive on import scan. ai
phantom-deps phantom-dep:glob AI (phantom-deps): Legit runtime dep of OpenAPI parser, false positive on import scan. ai
phantom-deps phantom-dep:jsonpointer AI (phantom-deps): JSON pointer resolution core to OpenAPI parsing, false positive. ai
phantom-deps phantom-dep:json-to-ast AI (phantom-deps): Used for JSON parsing/AST in parser package, false positive. ai
phantom-deps phantom-dep:js-yaml AI (phantom-deps): Core YAML parsing dep for an OpenAPI parser, false positive. ai
phantom-deps phantom-dep:ajv-draft-04 AI (phantom-deps): Schema validation dep, false positive on import scan. ai
provenance publisher-changed AI (provenance): scalar_geoff is an established publisher (36 approved) within the scalar org; SLSA attestation confirms CI/CD build integrity. ai

Versions (showing 100 of 122)

Version Deps Published
0.28.10 10 / 5
0.28.9 10 / 5
0.28.8 10 / 5
0.28.7 10 / 5
0.28.6 10 / 5
0.28.5 10 / 5
0.28.4 10 / 5
0.28.2 10 / 5
0.28.1 10 / 5
0.28.0 10 / 5
0.27.0 10 / 5
0.26.1 10 / 5
0.26.0 10 / 5
0.25.12 10 / 5
0.25.11 10 / 5
0.25.10 10 / 5
0.25.9 10 / 5
0.25.8 10 / 5
0.25.7 10 / 5
0.25.6 10 / 5
0.25.5 10 / 5
0.25.4 10 / 6
0.25.3 10 / 6
0.25.2 10 / 6
0.25.1 10 / 6
0.25.0 10 / 6
0.24.17 10 / 6
0.24.16 10 / 6
0.24.15 10 / 6
0.24.14 10 / 6
0.24.13 10 / 6
0.24.10 10 / 6
0.24.9 10 / 6
0.24.8 10 / 6
0.24.7 10 / 6
0.24.6 10 / 6
0.24.5 9 / 6
0.24.4 9 / 6
0.24.3 9 / 6
0.24.2 9 / 6
0.24.1 9 / 6
0.23.13 9 / 6
0.23.12 9 / 6
0.23.11 9 / 6
0.23.10 9 / 6
0.23.9 9 / 6
0.23.7 9 / 6
0.23.6 9 / 6
0.23.5 9 / 6
0.23.4 9 / 6
0.23.3 9 / 9
0.23.2 9 / 9
0.23.1 9 / 9
0.23.0 9 / 9
0.22.3 9 / 9
0.22.2 9 / 9
0.22.1 9 / 9
0.21.2 9 / 9
0.21.1 9 / 9
0.21.0 9 / 9
0.20.6 8 / 9
0.20.5 8 / 9
0.20.4 8 / 9
0.20.3 8 / 9
0.20.2 8 / 9
0.20.1 8 / 9
0.20.0 8 / 9
0.19.0 7 / 9
0.18.3 7 / 9
0.18.2 6 / 10
0.18.1 6 / 10
0.18.0 6 / 10
0.17.0 6 / 10
0.16.0 6 / 10
0.15.0 6 / 10
0.14.0 6 / 10
0.13.0 6 / 10
0.12.0 6 / 10
0.11.1 6 / 10
0.11.0 6 / 10
0.10.17 6 / 10
0.10.16 6 / 11
0.10.15 6 / 12
0.10.14 6 / 11
0.10.13 6 / 11
0.10.12 6 / 11
0.10.11 6 / 11
0.10.10 6 / 11
0.10.9 6 / 11
0.10.8 6 / 11
0.10.7 6 / 11
0.10.6 6 / 11
0.10.5 6 / 11
0.10.4 6 / 11
0.10.3 6 / 11
0.10.2 6 / 11
0.10.1 6 / 11
0.10.0 6 / 10
0.9.0 6 / 10
0.8.10 6 / 10
Showing 100 of 122 Next page →

v0.28.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.28.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.21.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.10.16

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.10.15

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.10.14

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.10.13

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.10.12

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.10.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.10.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.10.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.10.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.10.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.10.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.10.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.10.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.10.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.10.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.10.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.10.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.9.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.