@mintlify/validation
Validates mint.json files
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Transition from human publisher to GitHub Actions CI is a documented legitimate pattern for this established Mintlify package. | ai | |
| phantom-deps | phantom-dep:js-yaml | AI (phantom-deps): js-yaml is explicitly declared as a direct dependency in package.json; the phantom-dep finding is a false positive for this package. | ai | |
| dependencies | unvetted-dep:lcm | AI (dependencies): lcm is a small math utility pinned at 0.0.3 with @types/lcm in devDeps; intentional, typed usage with no malware signals. | ai | |
| typosquat | typosquat.levenshtein:validator | AI (typosquat): Scoped @mintlify/validation package is clearly named for its purpose (validating mint.json files), not impersonating the 'validator' package. False positive for this namespace. | ai | |
| dependencies | unvetted-dep:@mintlify/mdx | AI (dependencies): First-party Mintlify package within the same organization; not a third-party unvetted dependency. | ai | |
| dependencies | unvetted-dep:@mintlify/models | AI (dependencies): First-party Mintlify package within the same organization; not a third-party unvetted dependency. | ai |
Versions (showing 100 of 360)
| Version | Deps | Published |
|---|---|---|
| 0.1.513 | 11 / 16 | |
| 0.1.512 | 11 / 16 | |
| 0.1.511 | 11 / 16 | |
| 0.1.510 | 11 / 16 | |
| 0.1.509 | 11 / 16 | |
| 0.1.508 | 11 / 16 | |
| 0.1.507 | 11 / 16 | |
| 0.1.506 | 11 / 16 | |
| 0.1.505 | 11 / 16 | |
| 0.1.504 | 11 / 16 | |
| 0.1.503 | 11 / 16 | |
| 0.1.502 | 11 / 16 | |
| 0.1.501 | 11 / 16 | |
| 0.1.500 | 11 / 16 | |
| 0.1.499 | 11 / 16 | |
| 0.1.498 | 11 / 16 | |
| 0.1.497 | 11 / 16 | |
| 0.1.496 | 11 / 16 | |
| 0.1.495 | 11 / 16 | |
| 0.1.494 | 11 / 16 | |
| 0.1.493 | 11 / 16 | |
| 0.1.492 | 11 / 16 | |
| 0.1.491 | 11 / 16 | |
| 0.1.490 | 11 / 16 | |
| 0.1.489 | 11 / 16 | |
| 0.1.488 | 11 / 16 | |
| 0.1.487 | 11 / 16 | |
| 0.1.486 | 11 / 16 | |
| 0.1.485 | 11 / 16 | |
| 0.1.484 | 8 / 15 | |
| 0.1.483 | 8 / 15 | |
| 0.1.482 | 8 / 15 | |
| 0.1.481 | 8 / 15 | |
| 0.1.480 | 8 / 15 | |
| 0.1.479 | 8 / 15 | |
| 0.1.478 | 8 / 15 | |
| 0.1.477 | 8 / 15 | |
| 0.1.476 | 8 / 15 | |
| 0.1.475 | 8 / 15 | |
| 0.1.474 | 7 / 15 | |
| 0.1.473 | 7 / 15 | |
| 0.1.472 | 8 / 15 | |
| 0.1.471 | 7 / 15 | |
| 0.1.470 | 7 / 15 | |
| 0.1.469 | 7 / 15 | |
| 0.1.468 | 7 / 15 | |
| 0.1.467 | 7 / 15 | |
| 0.1.466 | 7 / 15 | |
| 0.1.465 | 7 / 15 | |
| 0.1.464 | 7 / 15 | |
| 0.1.463 | 7 / 15 | |
| 0.1.462 | 7 / 15 | |
| 0.1.461 | 7 / 15 | |
| 0.1.460 | 7 / 15 | |
| 0.1.459 | 7 / 15 | |
| 0.1.458 | 7 / 15 | |
| 0.1.457 | 7 / 15 | |
| 0.1.456 | 7 / 15 | |
| 0.1.455 | 7 / 15 | |
| 0.1.454 | 7 / 15 | |
| 0.1.453 | 7 / 15 | |
| 0.1.452 | 7 / 15 | |
| 0.1.451 | 7 / 15 | |
| 0.1.450 | 7 / 15 | |
| 0.1.449 | 7 / 15 | |
| 0.1.448 | 7 / 15 | |
| 0.1.447 | 7 / 15 | |
| 0.1.446 | 7 / 15 | |
| 0.1.445 | 7 / 15 | |
| 0.1.444 | 7 / 15 | |
| 0.1.443 | 7 / 15 | |
| 0.1.442 | 7 / 15 | |
| 0.1.441 | 7 / 15 | |
| 0.1.440 | 7 / 15 | |
| 0.1.439 | 7 / 15 | |
| 0.1.438 | 7 / 15 | |
| 0.1.437 | 7 / 15 | |
| 0.1.436 | 7 / 15 | |
| 0.1.435 | 7 / 15 | |
| 0.1.434 | 7 / 15 | |
| 0.1.433 | 7 / 15 | |
| 0.1.432 | 7 / 15 | |
| 0.1.431 | 7 / 15 | |
| 0.1.430 | 7 / 15 | |
| 0.1.429 | 7 / 15 | |
| 0.1.428 | 7 / 15 | |
| 0.1.427 | 7 / 15 | |
| 0.1.426 | 6 / 15 | |
| 0.1.425 | 6 / 15 | |
| 0.1.424 | 6 / 15 | |
| 0.1.423 | 6 / 15 | |
| 0.1.422 | 6 / 15 | |
| 0.1.421 | 6 / 15 | |
| 0.1.420 | 6 / 15 | |
| 0.1.419 | 6 / 15 | |
| 0.1.418 | 6 / 15 | |
| 0.1.417 | 6 / 15 | |
| 0.1.416 | 6 / 15 | |
| 0.1.415 | 6 / 15 | |
| 0.1.414 | 6 / 15 |
v0.1.513
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.512
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.511
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.510
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.509
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.508
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.507
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.506
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.505
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.504
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.503
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.502
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.501
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.500
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.499
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.498
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.497
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.496
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.495
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.494
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.493
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.492
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.491
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.490
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.489
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.488
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.487
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.486
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.485
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.484
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.483
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.482
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.481
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.480
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.479
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.478
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.477
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.476
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.475
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.474
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.473
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.472
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.471
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.470
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.469
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.468
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.467
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.466
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.465
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.464
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.463
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.462
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.461
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.460
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.459
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.458
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.457
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.456
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.455
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.454
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.453
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.452
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.451
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.450
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.449
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.448
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.447
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.446
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.445
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.444
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.443
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.442
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.441
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.440
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.439
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.438
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.437
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.436
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.435
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.434
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.433
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.432
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.431
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.430
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.429
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.428
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.427
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.426
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.425
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.424
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.423
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.422
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.421
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.420
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.419
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.418
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.417
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.416
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.415
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.414
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.