openapi3-ts
27
Versions
—
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
pjmolina
Keywords
openapi3tstypescript
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | dormant-publish | AI (publish-pattern): Long-standing maintainer with established track record on this package; dormancy is normal. | ai | |
| source-diff | obfuscated-file:dist/oas32.js | AI (source-diff): Vite build output; readable OpenAPI builder code, not obfuscated. Stable for this package. | ai | |
| source-diff | obfuscated-file:dist/oas30-14584a9c.js | AI (source-diff): Content is standard Rollup/Vite minified bundle output for OpenAPI builder code — no obfuscation or malicious patterns present. Hash-named chunks are normal for this build toolchain. | ai | |
| source-diff | obfuscated-file:dist/oas31-ebde447c.js | AI (source-diff): Content is standard Rollup/Vite minified bundle output for OpenAPI builder code — no obfuscation or malicious patterns present. Hash-named chunks are normal for this build toolchain. | ai | |
| source-diff | obfuscated-file:dist/oas31-Dtl9zIuV.js | AI (source-diff): Minified Vite/Rollup build artifact of the openapi3-ts library. Content is recognizable OpenAPI builder logic with no malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/oas30-CAmzubQd.js | AI (source-diff): Minified Vite/Rollup build artifact of the openapi3-ts library. Content is recognizable OpenAPI builder logic with no malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/oas30-zGY2VGOJ.js | AI (source-diff): Content is standard minified Rollup/Vite bundle output for OpenAPI builder logic; no malicious patterns. Reject is for wrong-package reason, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/oas31-2ULMvMLl.js | AI (source-diff): Content is standard minified Rollup/Vite bundle output for OpenAPI builder logic; no malicious patterns. Reject is for wrong-package reason, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/oas30-E9r1WxRR.js | AI (source-diff): Vite-bundled output for the oas30 module; hash-suffixed filenames are standard Vite chunk naming. Content is readable minified OpenAPI builder code with no malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/oas31-Bx381qKf.js | AI (source-diff): Vite-bundled output for the oas31 module; same pattern as oas30 chunk. Content is readable minified OpenAPI builder code with no malicious patterns. | ai |
Versions (showing 27 of 27)
| Version | Deps | Published |
|---|---|---|
| 4.6.1 | 1 / 16 | |
| 4.6.0 | 1 / 16 | |
| 4.5.0 | 1 / 16 | |
| 4.4.0 | 1 / 16 | |
| 4.3.3 | 1 / 14 | |
| 4.3.2 | 1 / 14 | |
| 4.3.1 | 1 / 14 | |
| 4.3.0 | 1 / 14 | |
| 4.2.2 | 1 / 14 | |
| 4.2.1 | 1 / 14 | |
| 4.2.0 | 1 / 15 | |
| 4.1.2 | 1 / 15 | |
| 4.1.1 | 1 / 14 | |
| 4.1.0 | 1 / 14 | |
| 4.0.4 | 1 / 14 | |
| 4.0.3 | 1 / 14 | |
| 4.0.2 | 1 / 14 | |
| 4.0.1 | 1 / 14 | |
| 4.0.0 | 1 / 14 | |
| 3.2.0 | 1 / 14 | |
| 3.1.2 | 1 / 14 | |
| 3.1.1 | 1 / 14 | |
| 3.1.0 | 1 / 14 | |
| 3.0.3 | 1 / 14 | |
| 3.0.2 | 1 / 13 | |
| 3.0.1 | 1 / 13 | |
| 3.0.0 | 1 / 13 |
v4.6.1
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.