← Home

swagger-typescript-api

Generate the API client for Fetch or Axios from an OpenAPI Specification

51
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

acacodesmorimoto

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:swagger-schema-official AI (phantom-deps): Schema package used indirectly; stable for this package. ai
phantom-deps phantom-dep:nanoid AI (phantom-deps): ID generation used indirectly; stable for this package. ai
phantom-deps phantom-dep:js-yaml AI (phantom-deps): YAML parsing used indirectly by CLI; stable for this package. ai
phantom-deps phantom-dep:prettier AI (phantom-deps): Code formatter used indirectly by build; stable for this package. ai
phantom-deps phantom-dep:didyoumean AI (phantom-deps): CLI utility used indirectly; stable for this package. ai
phantom-deps phantom-dep:node-emoji AI (phantom-deps): CLI output formatting used indirectly; stable for this package. ai
phantom-deps phantom-dep:typescript AI (phantom-deps): Build tool used indirectly; stable for this package. ai
phantom-deps phantom-dep:cosmiconfig AI (phantom-deps): Config loader used indirectly; stable for this package. ai
phantom-deps phantom-dep:swagger2openapi AI (phantom-deps): Schema conversion used indirectly; stable for this package. ai
phantom-deps phantom-dep:eta AI (phantom-deps): Template engine used indirectly by build system; stable pattern for this package. ai
phantom-deps phantom-dep:lodash AI (phantom-deps): Utility library used indirectly; stable dependency for this package. ai
semgrep semgrep:dynamic-require AI (semgrep): Loads user-supplied local config path via CLI flag; documented feature, not exfil/RCE. ai
provenance publisher-changed AI (provenance): Shift to GitHub Actions CI publish with SLSA attestation; legitimate transition, not compromise. ai
publish-pattern new-deps-added AI (publish-pattern): @types/lodash and openapi-types are standard type/spec deps for an OpenAPI codegen tool. ai
phantom-deps phantom-dep:@types/lodash AI (phantom-deps): @types/lodash is a type-only dep used by TypeScript tooling; stable false positive for this package. ai
publish-pattern dormant-publish AI (publish-pattern): SLSA provenance attestation via Sigstore confirms CI/CD publish; mitigates account-takeover concern for this established package. ai
dependencies unvetted-dep:swagger-schema-official AI (dependencies): swagger-schema-official is a known companion schema package; stable dependency for this tool across versions. ai
phantom-deps phantom-dep:@biomejs/wasm-nodejs AI (phantom-deps): Wasm runtime loaded indirectly via @biomejs/js-api; not directly imported by convention. ai
phantom-deps phantom-dep:@types/swagger-schema-official AI (phantom-deps): Type-only package; not directly imported at runtime by design. ai

Versions (showing 51 of 87)

View all versions
Version Deps Published
13.12.6 17 / 12
13.12.5 17 / 12
13.12.4 17 / 12
13.12.3 17 / 12
13.12.2 17 / 12
13.12.1 17 / 12
13.12.0 17 / 11
13.11.2 17 / 11
13.11.1 17 / 11
13.11.0 17 / 11
13.10.0 17 / 11
13.9.3 17 / 11
13.9.2 17 / 11
13.9.1 17 / 11
13.9.0 17 / 11
13.8.0 17 / 11
13.7.2 17 / 11
13.7.1 17 / 11
13.7.0 17 / 11
13.6.11 17 / 11
13.6.10 17 / 11
13.6.9 17 / 11
13.6.8 17 / 11
13.6.7 17 / 11
13.6.6 17 / 11
13.6.5 17 / 11
13.6.4 17 / 11
13.6.3 17 / 11
13.6.2 17 / 11
13.6.1 17 / 11
13.6.0 17 / 11
13.5.0 17 / 11
13.4.0 17 / 11
13.3.1 17 / 11
13.3.0 17 / 11
13.2.18 15 / 11
13.2.17 14 / 11
13.2.16 15 / 11
13.2.15 15 / 11
13.2.14 15 / 11
13.2.13 15 / 11
13.2.12 15 / 12
13.2.11 13 / 14
13.2.10 13 / 14
13.2.9 13 / 14
13.2.8 13 / 14
13.2.7 13 / 14
13.2.6 13 / 14
13.2.5 13 / 14
13.2.4 13 / 14
13.2.3 13 / 14

v13.12.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v13.12.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v13.12.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v13.12.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v13.12.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v13.12.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v13.12.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v13.11.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v13.11.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v13.10.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v13.9.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v13.9.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v13.9.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v13.9.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v13.8.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v13.6.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v13.6.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v13.6.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v13.6.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v13.6.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v13.6.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v13.6.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v13.5.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v13.2.16

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v13.2.14

2 findings
HIGH Publisher changed: smorimoto → GitHub Actions (on 2025-10-04) provenance

This version was published by a different npm account than previous versions on 2025-10-04. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v13.2.13

2 findings
HIGH Publisher changed: smorimoto → GitHub Actions (on 2025-09-18) provenance

This version was published by a different npm account than previous versions on 2025-09-18. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v13.2.12

2 findings
HIGH Publisher changed: smorimoto → GitHub Actions (on 2025-09-18) provenance

This version was published by a different npm account than previous versions on 2025-09-18. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v13.2.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v13.2.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v13.2.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v13.2.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v13.2.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v13.2.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v13.2.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v13.2.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v13.2.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.