@zuplo/openapi-tools
Tooling for OpenAPI files
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | new-deps-added | AI (publish-pattern): zod, semver, and jsonpath-plus are all well-established, widely-trusted packages appropriate for an OpenAPI tooling library. No malicious signal. | ai | |
| dependencies | unvetted-dep:jsonpath-plus | AI (dependencies): jsonpath-plus is a well-known JSONPath library; its use in an OpenAPI tooling package is expected and appropriate across all versions. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Established @zuplo scoped package with 589 versions and 4.5k weekly downloads; cosmetic README/keyword signals are not indicative of spam. | ai |
Versions (showing 100 of 506)
| Version | Deps | Published |
|---|---|---|
| 6.51.84 | 5 / 6 | |
| 6.51.83 | 5 / 6 | |
| 6.51.81 | 5 / 6 | |
| 6.51.80 | 5 / 6 | |
| 6.51.79 | 5 / 6 | |
| 6.51.78 | 5 / 6 | |
| 6.51.77 | 5 / 6 | |
| 6.51.76 | 5 / 6 | |
| 6.51.75 | 5 / 6 | |
| 6.51.74 | 5 / 6 | |
| 6.51.72 | 5 / 6 | |
| 6.51.71 | 5 / 6 | |
| 6.51.70 | 5 / 6 | |
| 6.51.69 | 5 / 6 | |
| 6.51.68 | 5 / 6 | |
| 6.51.67 | 5 / 6 | |
| 6.51.66 | 5 / 6 | |
| 6.51.65 | 5 / 6 | |
| 6.51.64 | 5 / 6 | |
| 6.51.63 | 5 / 6 | |
| 6.51.62 | 5 / 6 | |
| 6.51.61 | 5 / 6 | |
| 6.51.60 | 5 / 6 | |
| 6.51.59 | 5 / 6 | |
| 6.51.58 | 5 / 6 | |
| 6.51.57 | 5 / 6 | |
| 6.51.56 | 5 / 6 | |
| 6.51.55 | 5 / 6 | |
| 6.51.54 | 5 / 6 | |
| 6.51.53 | 5 / 6 | |
| 6.51.52 | 5 / 6 | |
| 6.51.51 | 5 / 6 | |
| 6.51.50 | 5 / 6 | |
| 6.51.49 | 5 / 6 | |
| 6.51.48 | 5 / 6 | |
| 6.51.47 | 5 / 6 | |
| 6.51.46 | 5 / 6 | |
| 6.51.45 | 5 / 6 | |
| 6.51.44 | 5 / 6 | |
| 6.51.41 | 5 / 6 | |
| 6.51.40 | 5 / 6 | |
| 6.51.39 | 5 / 6 | |
| 6.51.38 | 5 / 6 | |
| 6.51.37 | 5 / 6 | |
| 6.51.36 | 5 / 6 | |
| 6.51.35 | 5 / 6 | |
| 6.51.34 | 5 / 6 | |
| 6.51.33 | 5 / 6 | |
| 6.51.32 | 5 / 6 | |
| 6.51.31 | 5 / 6 | |
| 6.51.30 | 5 / 6 | |
| 6.51.29 | 5 / 6 | |
| 6.51.28 | 5 / 6 | |
| 6.51.27 | 5 / 6 | |
| 6.51.26 | 5 / 6 | |
| 6.51.25 | 5 / 6 | |
| 6.51.24 | 5 / 6 | |
| 6.51.23 | 5 / 6 | |
| 6.51.22 | 5 / 6 | |
| 6.51.21 | 5 / 6 | |
| 6.51.20 | 5 / 6 | |
| 6.51.19 | 5 / 6 | |
| 6.51.17 | 5 / 6 | |
| 6.51.16 | 5 / 6 | |
| 6.51.15 | 5 / 6 | |
| 6.51.14 | 5 / 6 | |
| 6.51.13 | 5 / 6 | |
| 6.51.12 | 5 / 6 | |
| 6.51.11 | 5 / 6 | |
| 6.51.10 | 5 / 6 | |
| 6.51.9 | 5 / 6 | |
| 6.51.7 | 5 / 6 | |
| 6.51.6 | 5 / 6 | |
| 6.51.5 | 5 / 6 | |
| 6.51.4 | 5 / 6 | |
| 6.51.3 | 5 / 6 | |
| 6.51.2 | 5 / 6 | |
| 6.51.1 | 5 / 6 | |
| 6.51.0 | 5 / 6 | |
| 6.50.16 | 5 / 6 | |
| 6.50.14 | 5 / 6 | |
| 6.50.13 | 5 / 6 | |
| 6.50.12 | 5 / 6 | |
| 6.50.11 | 5 / 6 | |
| 6.50.10 | 5 / 6 | |
| 6.50.9 | 5 / 6 | |
| 6.50.8 | 5 / 6 | |
| 6.50.7 | 5 / 6 | |
| 6.50.6 | 5 / 6 | |
| 6.50.5 | 5 / 6 | |
| 6.50.4 | 5 / 6 | |
| 6.50.2 | 5 / 6 | |
| 6.50.1 | 5 / 6 | |
| 6.50.0 | 5 / 6 | |
| 6.49.12 | 5 / 6 | |
| 6.49.11 | 5 / 6 | |
| 6.49.9 | 5 / 6 | |
| 6.49.8 | 5 / 6 | |
| 6.49.7 | 5 / 6 | |
| 6.49.6 | 5 / 6 |
v6.51.78
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.51.64
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.51.52
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.51.38
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.51.15
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.51.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.50.13
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.