{"openapi":"3.1.0","info":{"title":"DepVet","version":"1.0.0","contact":{"name":"DepVet","url":"https://github.com/Imac2014Ville/depvet"},"description":"NPM supply chain attack and malicious package check for npm and PyPI: typosquat detection, dependency vulnerability scan (CVE/OSV), license check, OpenSSF Scorecard. OK/REVIEW/AVOID verdict before you install. No API key: pay USDC on Base per call via x402.","x-guidance":"Pre-install npm supply chain attack and malicious package check for agents, paid per call in USDC on Base via x402. POST /report {ecosystem: npm|pypi, name, version?} ($0.02) returns an OK/REVIEW/AVOID verdict with reasons: CVE/OSV vulnerabilities with severity and fixed versions, malware advisories, typosquat hints, license check (SPDX risk class), dependency counts, OpenSSF Scorecard, maintenance signals. POST /check {ecosystem, name, version?} ($0.005) is the light version. POST /batch {ecosystem, packages:[{name, version?}] up to 20} ($0.05) is a dependency vulnerability scan for a whole lockfile. Bad input returns 400 and unknown packages 404, neither charged. GET with query params also works."},"servers":[{"url":"https://depvet.imac2014ville.workers.dev"}],"paths":{"/report":{"get":{"operationId":"reportGet","summary":"NPM supply chain attack check: full package risk report","description":"NPM supply chain attack and malicious package check before you install an npm or PyPI package: dependency vulnerability scan (CVE/OSV, severity, fixed versions), malware advisories, typosquat hint, license check (SPDX), OpenSSF Scorecard. Verdict OK/REVIEW/AVOID.","tags":["supply-chain","malicious-package","typosquat","cve","license-check"],"x-payment-info":{"price":{"mode":"fixed","currency":"USD","amount":"0.02"},"protocols":[{"x402":{}}]},"responses":{"200":{"description":"Successful response","content":{"application/json":{"schema":{"type":"object"},"example":{"ok":true,"ecosystem":"npm","name":"lodash","version":"4.17.20","verdict":"REVIEW","reasons":[{"level":"REVIEW","code":"high-vuln","message":"3 high-severity vulnerability advisory(ies) affect this version."}],"license":{"spdx":"MIT","riskClass":"permissive"},"vulnerabilities":{"count":4,"maxSeverity":"HIGH"},"dependencies":{"direct":0,"transitive":0},"typosquat":{"suspect":false}}}}},"400":{"description":"Invalid input (not charged)"},"402":{"description":"Payment Required"},"404":{"description":"Package not found (not charged)"}},"parameters":[{"name":"ecosystem","in":"query","required":true,"schema":{"type":"string","enum":["npm","pypi"],"description":"Package ecosystem"},"description":"Package ecosystem"},{"name":"name","in":"query","required":true,"schema":{"type":"string","description":"Package name, e.g. express, @types/node, requests"},"description":"Package name, e.g. express, @types/node, requests"},{"name":"version","in":"query","required":false,"schema":{"type":"string","description":"Exact version (default: latest)"},"description":"Exact version (default: latest)"}]},"post":{"operationId":"reportPost","summary":"NPM supply chain attack check: full package risk report","description":"NPM supply chain attack and malicious package check before you install an npm or PyPI package: dependency vulnerability scan (CVE/OSV, severity, fixed versions), malware advisories, typosquat hint, license check (SPDX), OpenSSF Scorecard. Verdict OK/REVIEW/AVOID.","tags":["supply-chain","malicious-package","typosquat","cve","license-check"],"x-payment-info":{"price":{"mode":"fixed","currency":"USD","amount":"0.02"},"protocols":[{"x402":{}}]},"responses":{"200":{"description":"Successful response","content":{"application/json":{"schema":{"type":"object"},"example":{"ok":true,"ecosystem":"npm","name":"lodash","version":"4.17.20","verdict":"REVIEW","reasons":[{"level":"REVIEW","code":"high-vuln","message":"3 high-severity vulnerability advisory(ies) affect this version."}],"license":{"spdx":"MIT","riskClass":"permissive"},"vulnerabilities":{"count":4,"maxSeverity":"HIGH"},"dependencies":{"direct":0,"transitive":0},"typosquat":{"suspect":false}}}}},"400":{"description":"Invalid input (not charged)"},"402":{"description":"Payment Required"},"404":{"description":"Package not found (not charged)"}},"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"ecosystem":{"type":"string","enum":["npm","pypi"],"description":"Package ecosystem"},"name":{"type":"string","description":"Package name, e.g. express, @types/node, requests"},"version":{"type":"string","description":"Exact version (default: latest)"}},"required":["ecosystem","name"]}}}}}},"/check":{"get":{"operationId":"checkGet","summary":"Malicious package / typosquat / CVE pre-install check","description":"Cheap pre-install check for an npm or PyPI package: malicious package/malware flag, typosquat, CVE count and max severity, license check, deprecated. OK/REVIEW/AVOID verdict. Cheap enough to run on every install.","tags":["supply-chain","malicious-package","typosquat","cve","npm"],"x-payment-info":{"price":{"mode":"fixed","currency":"USD","amount":"0.005"},"protocols":[{"x402":{}}]},"responses":{"200":{"description":"Successful response","content":{"application/json":{"schema":{"type":"object"},"example":{"ok":true,"ecosystem":"pypi","name":"requests","version":"2.32.3","verdict":"OK","license":"Apache-2.0","licenseRisk":"permissive","vulnerabilities":{"count":0,"maxSeverity":"NONE","malware":false},"deprecated":false,"typosquatSuspect":false}}}},"400":{"description":"Invalid input (not charged)"},"402":{"description":"Payment Required"},"404":{"description":"Package not found (not charged)"}},"parameters":[{"name":"ecosystem","in":"query","required":true,"schema":{"type":"string","enum":["npm","pypi"],"description":"Package ecosystem"},"description":"Package ecosystem"},{"name":"name","in":"query","required":true,"schema":{"type":"string","description":"Package name, e.g. express, @types/node, requests"},"description":"Package name, e.g. express, @types/node, requests"},{"name":"version","in":"query","required":false,"schema":{"type":"string","description":"Exact version (default: latest)"},"description":"Exact version (default: latest)"}]},"post":{"operationId":"checkPost","summary":"Malicious package / typosquat / CVE pre-install check","description":"Cheap pre-install check for an npm or PyPI package: malicious package/malware flag, typosquat, CVE count and max severity, license check, deprecated. OK/REVIEW/AVOID verdict. Cheap enough to run on every install.","tags":["supply-chain","malicious-package","typosquat","cve","npm"],"x-payment-info":{"price":{"mode":"fixed","currency":"USD","amount":"0.005"},"protocols":[{"x402":{}}]},"responses":{"200":{"description":"Successful response","content":{"application/json":{"schema":{"type":"object"},"example":{"ok":true,"ecosystem":"pypi","name":"requests","version":"2.32.3","verdict":"OK","license":"Apache-2.0","licenseRisk":"permissive","vulnerabilities":{"count":0,"maxSeverity":"NONE","malware":false},"deprecated":false,"typosquatSuspect":false}}}},"400":{"description":"Invalid input (not charged)"},"402":{"description":"Payment Required"},"404":{"description":"Package not found (not charged)"}},"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"ecosystem":{"type":"string","enum":["npm","pypi"],"description":"Package ecosystem"},"name":{"type":"string","description":"Package name, e.g. express, @types/node, requests"},"version":{"type":"string","description":"Exact version (default: latest)"}},"required":["ecosystem","name"]}}}}}},"/batch":{"get":{"operationId":"batchGet","summary":"Dependency vulnerability scan for a lockfile (20 packages)","description":"Dependency vulnerability scan for a whole lockfile: check up to 20 npm or PyPI packages per call for CVEs, malicious packages, typosquats, license risk and deprecation. Per-package verdicts plus overall verdict. GET form: packages=name@version,name2.","tags":["dependency-scan","lockfile","cve","supply-chain","pypi"],"x-payment-info":{"price":{"mode":"fixed","currency":"USD","amount":"0.05"},"protocols":[{"x402":{}}]},"responses":{"200":{"description":"Successful response","content":{"application/json":{"schema":{"type":"object"},"example":{"ok":true,"ecosystem":"npm","count":3,"overallVerdict":"AVOID","summary":{"OK":1,"REVIEW":1,"AVOID":1,"errors":0},"results":[{"name":"express","verdict":"OK"}]}}}},"400":{"description":"Invalid input (not charged)"},"402":{"description":"Payment Required"},"404":{"description":"Package not found (not charged)"}},"parameters":[{"name":"ecosystem","in":"query","required":true,"schema":{"type":"string","enum":["npm","pypi"],"description":"Package ecosystem"},"description":"Package ecosystem"},{"name":"packages","in":"query","required":true,"schema":{"type":"string","description":"Comma-separated name or name@version, max 20"},"description":"Comma-separated name or name@version, max 20"}]},"post":{"operationId":"batchPost","summary":"Dependency vulnerability scan for a lockfile (20 packages)","description":"Dependency vulnerability scan for a whole lockfile: check up to 20 npm or PyPI packages per call for CVEs, malicious packages, typosquats, license risk and deprecation. Per-package verdicts plus overall verdict. GET form: packages=name@version,name2.","tags":["dependency-scan","lockfile","cve","supply-chain","pypi"],"x-payment-info":{"price":{"mode":"fixed","currency":"USD","amount":"0.05"},"protocols":[{"x402":{}}]},"responses":{"200":{"description":"Successful response","content":{"application/json":{"schema":{"type":"object"},"example":{"ok":true,"ecosystem":"npm","count":3,"overallVerdict":"AVOID","summary":{"OK":1,"REVIEW":1,"AVOID":1,"errors":0},"results":[{"name":"express","verdict":"OK"}]}}}},"400":{"description":"Invalid input (not charged)"},"402":{"description":"Payment Required"},"404":{"description":"Package not found (not charged)"}},"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"ecosystem":{"type":"string","enum":["npm","pypi"],"description":"Package ecosystem"},"packages":{"type":"array","maxItems":20,"items":{"type":"object","properties":{"name":{"type":"string","description":"Package name, e.g. express, @types/node, requests"},"version":{"type":"string","description":"Exact version (default: latest)"}},"required":["name"]}}},"required":["ecosystem","packages"]}}}}}}},"x-discovery":{"ownershipProofs":["0x846fc9efb76b88e891a2a154460b8227031565790f9eb09881ad6a3d3ffe35e2633152e9dcdf1b7f7bb7bfbafc3ab0878b7cca16714db0f9a94ffa2001cfc84a1b"]}}