@mintlify/validation
Validates mint.json files
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Transition from human publisher to GitHub Actions CI is a documented legitimate pattern for this established Mintlify package. | ai | |
| phantom-deps | phantom-dep:js-yaml | AI (phantom-deps): js-yaml is explicitly declared as a direct dependency in package.json; the phantom-dep finding is a false positive for this package. | ai | |
| dependencies | unvetted-dep:lcm | AI (dependencies): lcm is a small math utility pinned at 0.0.3 with @types/lcm in devDeps; intentional, typed usage with no malware signals. | ai | |
| typosquat | typosquat.levenshtein:validator | AI (typosquat): Scoped @mintlify/validation package is clearly named for its purpose (validating mint.json files), not impersonating the 'validator' package. False positive for this namespace. | ai | |
| dependencies | unvetted-dep:@mintlify/mdx | AI (dependencies): First-party Mintlify package within the same organization; not a third-party unvetted dependency. | ai | |
| dependencies | unvetted-dep:@mintlify/models | AI (dependencies): First-party Mintlify package within the same organization; not a third-party unvetted dependency. | ai |
Versions (showing 59 of 360)
| Version | Deps | Published |
|---|---|---|
| 0.1.413 | 6 / 15 | |
| 0.1.412 | 6 / 15 | |
| 0.1.411 | 6 / 15 | |
| 0.1.410 | 6 / 15 | |
| 0.1.409 | 6 / 15 | |
| 0.1.408 | 6 / 15 | |
| 0.1.407 | 6 / 15 | |
| 0.1.406 | 6 / 15 | |
| 0.1.405 | 6 / 15 | |
| 0.1.404 | 6 / 15 | |
| 0.1.403 | 6 / 15 | |
| 0.1.402 | 6 / 15 | |
| 0.1.401 | 6 / 15 | |
| 0.1.400 | 6 / 15 | |
| 0.1.399 | 6 / 15 | |
| 0.1.398 | 6 / 15 | |
| 0.1.397 | 6 / 15 | |
| 0.1.396 | 6 / 15 | |
| 0.1.395 | 6 / 15 | |
| 0.1.394 | 6 / 15 | |
| 0.1.393 | 6 / 15 | |
| 0.1.392 | 6 / 15 | |
| 0.1.391 | 6 / 15 | |
| 0.1.390 | 6 / 15 | |
| 0.1.389 | 6 / 15 | |
| 0.1.388 | 6 / 15 | |
| 0.1.387 | 6 / 15 | |
| 0.1.386 | 6 / 15 | |
| 0.1.385 | 6 / 15 | |
| 0.1.384 | 6 / 15 | |
| 0.1.383 | 6 / 15 | |
| 0.1.382 | 6 / 15 | |
| 0.1.381 | 6 / 15 | |
| 0.1.380 | 6 / 15 | |
| 0.1.379 | 6 / 15 | |
| 0.1.378 | 6 / 15 | |
| 0.1.377 | 6 / 15 | |
| 0.1.376 | 6 / 15 | |
| 0.1.375 | 6 / 15 | |
| 0.1.374 | 6 / 15 | |
| 0.1.373 | 6 / 15 | |
| 0.1.372 | 6 / 15 | |
| 0.1.371 | 6 / 15 | |
| 0.1.370 | 6 / 15 | |
| 0.1.369 | 7 / 15 | |
| 0.1.368 | 7 / 15 | |
| 0.1.367 | 7 / 15 | |
| 0.1.366 | 7 / 15 | |
| 0.1.365 | 7 / 15 | |
| 0.1.364 | 7 / 15 | |
| 0.1.363 | 7 / 15 | |
| 0.1.362 | 7 / 15 | |
| 0.1.361 | 7 / 15 | |
| 0.1.360 | 7 / 15 | |
| 0.1.359 | 7 / 15 | |
| 0.1.358 | 7 / 15 | |
| 0.1.357 | 7 / 15 | |
| 0.1.356 | 7 / 15 | |
| 0.1.355 | 7 / 15 |
v0.1.413
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.412
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.411
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.410
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.409
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.408
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.407
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.406
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.405
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.404
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.403
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.402
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.401
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.400
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.399
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.398
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.397
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.396
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.395
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.394
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.393
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.392
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.391
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.390
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.389
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.388
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.387
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.386
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.385
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.384
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.383
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.382
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.381
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.380
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.379
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.378
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.377
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.376
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.375
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.374
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.373
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.372
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.371
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.370
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.369
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.368
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.367
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.366
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.365
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.364
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.363
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.362
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.361
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.360
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.359
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.358
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.357
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.356
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.355
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.