
Research
TeamPCP-Linked Supply Chain Attack Hits SAP CAP and Cloud MTA npm Packages
Compromised SAP CAP npm packages download and execute unverified binaries, creating urgent supply chain risk for affected developers and CI/CD environments.
@blockfrost/openapi
Advanced tools
Open Source OpenAPI specification for Blockfrost.io backend API.
The development version is available in the master branch.
The latest active release can be found under GitHub Releases.
For the published documentation, visit docs.blockfrost.io.
Blockfrost OpenAPI blockfrost-openapi.yaml specification is generated from all yaml files in src directory.
Then there is Mithril Aggregator API spec mithril.yaml which can be downloaded from Mithril Github.
These two specs are then merged together via openapi-merge-cli (configuration is inside openapi-merge.json).
Only the Mithril endpoints with a tag Cardano » Mithril are included into the final spec.
Tag
Cardano » Mithrilneeds to be added manually to each relevant endpoint in Mithril OpenAPI spec.
If you add a new file then don't forget to add it to paths in src/definitions.yaml.
Edit the source yaml files and build the package:
yarn build
Feel free to open PR against the master branch. It is a great place to start any discussion for new features and changes to the Blockfrost API.
When you push a new commit, the documentation for your branch is automatically generated on Vercel and added to your PR as a deployment.
You can download openapi.yaml directly from the repository or use this project as a dependency in your JavaScript/TypeScript project.
Install @blockfrost/openapi:
yarn add @blockfrost/openapi
or
npm install @blockfrost/openapi
Now you can use TypeScript types generated from the OpenAPI specification:
import { components } from '@blockfrost/openapi';
type Block = components['schemas']['block_content'];
type Address = components['schemas']['address_content'];
type UtxoAsset = components['schemas']['address_utxo_content'];
FAQs
OpenAPI specifications for blockfrost.io
We found that @blockfrost/openapi demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 3 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Compromised SAP CAP npm packages download and execute unverified binaries, creating urgent supply chain risk for affected developers and CI/CD environments.

Company News
Socket has acquired Secure Annex to expand extension security across browsers, IDEs, and AI tools.

Research
/Security News
Socket is tracking cloned Open VSX extensions tied to GlassWorm, with several updated from benign-looking sleepers into malware delivery vehicles.