@zuplo/openapi-tools
Tooling for OpenAPI files
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | new-deps-added | AI (publish-pattern): zod, semver, and jsonpath-plus are all well-established, widely-trusted packages appropriate for an OpenAPI tooling library. No malicious signal. | ai | |
| dependencies | unvetted-dep:jsonpath-plus | AI (dependencies): jsonpath-plus is a well-known JSONPath library; its use in an OpenAPI tooling package is expected and appropriate across all versions. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Established @zuplo scoped package with 589 versions and 4.5k weekly downloads; cosmetic README/keyword signals are not indicative of spam. | ai |
Versions (showing 100 of 506)
| Version | Deps | Published |
|---|---|---|
| 6.59.9 | 5 / 6 | |
| 6.59.8 | 5 / 6 | |
| 6.59.7 | 5 / 6 | |
| 6.59.6 | 5 / 6 | |
| 6.59.5 | 5 / 6 | |
| 6.59.4 | 5 / 6 | |
| 6.59.3 | 5 / 6 | |
| 6.59.2 | 5 / 6 | |
| 6.59.1 | 5 / 6 | |
| 6.59.0 | 5 / 6 | |
| 6.58.8 | 5 / 6 | |
| 6.58.7 | 5 / 6 | |
| 6.58.6 | 5 / 6 | |
| 6.58.5 | 5 / 6 | |
| 6.58.4 | 5 / 6 | |
| 6.58.2 | 5 / 6 | |
| 6.58.0 | 5 / 6 | |
| 6.57.19 | 5 / 6 | |
| 6.57.18 | 5 / 6 | |
| 6.57.17 | 5 / 6 | |
| 6.57.16 | 5 / 6 | |
| 6.57.15 | 5 / 6 | |
| 6.57.14 | 5 / 6 | |
| 6.57.13 | 5 / 6 | |
| 6.57.12 | 5 / 6 | |
| 6.57.11 | 5 / 6 | |
| 6.57.10 | 5 / 6 | |
| 6.57.7 | 5 / 6 | |
| 6.57.6 | 5 / 6 | |
| 6.57.5 | 5 / 6 | |
| 6.57.4 | 5 / 6 | |
| 6.57.3 | 5 / 6 | |
| 6.57.2 | 5 / 6 | |
| 6.57.1 | 5 / 6 | |
| 6.57.0 | 5 / 6 | |
| 6.56.8 | 5 / 6 | |
| 6.56.7 | 5 / 6 | |
| 6.56.6 | 5 / 6 | |
| 6.56.5 | 5 / 6 | |
| 6.56.4 | 5 / 6 | |
| 6.56.2 | 5 / 6 | |
| 6.56.1 | 5 / 6 | |
| 6.56.0 | 5 / 6 | |
| 6.55.6 | 5 / 6 | |
| 6.55.5 | 5 / 6 | |
| 6.55.4 | 5 / 6 | |
| 6.55.3 | 5 / 6 | |
| 6.55.2 | 5 / 6 | |
| 6.55.1 | 5 / 6 | |
| 6.55.0 | 5 / 6 | |
| 6.54.29 | 5 / 6 | |
| 6.54.26 | 5 / 6 | |
| 6.54.24 | 5 / 6 | |
| 6.54.23 | 5 / 6 | |
| 6.54.22 | 5 / 6 | |
| 6.54.21 | 5 / 6 | |
| 6.54.20 | 5 / 6 | |
| 6.54.19 | 5 / 6 | |
| 6.54.18 | 5 / 6 | |
| 6.54.17 | 5 / 6 | |
| 6.54.16 | 5 / 6 | |
| 6.54.15 | 5 / 6 | |
| 6.54.14 | 5 / 6 | |
| 6.54.13 | 5 / 6 | |
| 6.54.12 | 5 / 6 | |
| 6.54.9 | 5 / 6 | |
| 6.54.8 | 5 / 6 | |
| 6.54.7 | 5 / 6 | |
| 6.54.6 | 5 / 6 | |
| 6.54.5 | 5 / 6 | |
| 6.54.4 | 5 / 6 | |
| 6.54.3 | 5 / 6 | |
| 6.54.2 | 5 / 6 | |
| 6.54.1 | 5 / 6 | |
| 6.54.0 | 5 / 6 | |
| 6.53.1 | 5 / 6 | |
| 6.53.0 | 5 / 6 | |
| 6.52.25 | 5 / 6 | |
| 6.52.24 | 5 / 6 | |
| 6.52.23 | 5 / 6 | |
| 6.52.22 | 5 / 6 | |
| 6.52.21 | 5 / 6 | |
| 6.52.20 | 5 / 6 | |
| 6.52.19 | 5 / 6 | |
| 6.52.18 | 5 / 6 | |
| 6.52.17 | 5 / 6 | |
| 6.52.16 | 5 / 6 | |
| 6.52.15 | 5 / 6 | |
| 6.52.14 | 5 / 6 | |
| 6.52.13 | 5 / 6 | |
| 6.52.12 | 5 / 6 | |
| 6.52.10 | 5 / 6 | |
| 6.52.7 | 5 / 6 | |
| 6.52.6 | 5 / 6 | |
| 6.52.5 | 5 / 6 | |
| 6.52.4 | 5 / 6 | |
| 6.52.3 | 5 / 6 | |
| 6.52.2 | 5 / 6 | |
| 6.52.1 | 5 / 6 | |
| 6.52.0 | 5 / 6 |
v6.59.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.57.15
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.57.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.55.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.54.21
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.53.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.52.22
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.52.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.