← Home

@scalar/openapi-parser

22
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

cameronrohanimarclavescalar_geoffhwkrhanspagelamritkbgrcsscalar-machine

Keywords

openapiscalarswaggerparsertypescript

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:yaml AI (phantom-deps): Core parsing dep, likely bundled into dist. ai
phantom-deps phantom-dep:@types/node AI (phantom-deps): Type-only dep, expected phantom pattern. ai
phantom-deps phantom-dep:vite AI (phantom-deps): Build tool config dep, not runtime import. ai
phantom-deps phantom-dep:@hyperjump/json-schema AI (phantom-deps): Likely bundled into dist output. ai
phantom-deps phantom-dep:@hyperjump/browser AI (phantom-deps): Likely bundled into dist output. ai
npm-metadata suspicious-initial-version AI (npm-metadata): 0.0.0 is this monorepo's convention for internal packages, not malicious signal. ai
phantom-deps phantom-dep:chalk AI (phantom-deps): Likely used in CLI/build scripts, false positive. ai
phantom-deps phantom-dep:openapi-types AI (phantom-deps): Type-only dep, false positive. ai
phantom-deps phantom-dep:@humanwhocodes/momoa AI (phantom-deps): AST parsing dep for JSON, false positive on import scan. ai
phantom-deps phantom-dep:leven AI (phantom-deps): Legit small utility dep, false positive on import scan. ai
phantom-deps phantom-dep:glob AI (phantom-deps): Legit runtime dep of OpenAPI parser, false positive on import scan. ai
phantom-deps phantom-dep:jsonpointer AI (phantom-deps): JSON pointer resolution core to OpenAPI parsing, false positive. ai
phantom-deps phantom-dep:json-to-ast AI (phantom-deps): Used for JSON parsing/AST in parser package, false positive. ai
phantom-deps phantom-dep:js-yaml AI (phantom-deps): Core YAML parsing dep for an OpenAPI parser, false positive. ai
phantom-deps phantom-dep:ajv-draft-04 AI (phantom-deps): Schema validation dep, false positive on import scan. ai
provenance publisher-changed AI (provenance): scalar_geoff is an established publisher (36 approved) within the scalar org; SLSA attestation confirms CI/CD build integrity. ai

Versions (showing 22 of 122)

Version Deps Published
0.8.9 6 / 10
0.8.8 6 / 10
0.8.7 6 / 10
0.8.6 6 / 14
0.8.5 6 / 14
0.8.4 6 / 14
0.8.3 6 / 14
0.8.2 6 / 14
0.8.1 6 / 14
0.7.2 6 / 14
0.7.1 6 / 12
0.7.0 6 / 12
0.6.0 6 / 12
0.5.0 6 / 12
0.4.1 6 / 8
0.4.0 7 / 8
0.3.2 11 / 7
0.3.1 11 / 7
0.3.0 11 / 7
0.2.0 15 / 3
0.1.0 12 / 2
0.0.0 15 / 4

v0.8.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.7.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.7.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.6.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.4.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.4.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.3.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.3.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.