
Security News
GPT-6 Astra Attempts Supply Chain Attacks Against Open Source Maintainers in Testing
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.
@grantex/conformance
Advanced tools
Conformance test suite for the Grantex protocol. Validates that a server implementation correctly implements the Grantex specification by running black-box HTTP tests against a live endpoint.
npx @grantex/conformance --base-url http://localhost:3001 --api-key YOUR_API_KEY
npm install -g @grantex/conformance
grantex-conformance --base-url URL --api-key KEY [options]
Options:
--base-url <url> Base URL of the Grantex auth service (required)
--api-key <key> API key for authentication (required)
--suite <name> Run a specific suite only
--include <ext,...> Include optional extensions (comma-separated)
--format <format> Output format: text or json (default: text)
--bail Stop on first failure
-h, --help Display help
grantex-conformance --base-url http://localhost:3001 --api-key sk_test_xxx
grantex-conformance --base-url http://localhost:3001 --api-key sk_test_xxx --suite health
grantex-conformance --base-url http://localhost:3001 --api-key sk_test_xxx \
--include policies,webhooks,scim
grantex-conformance --base-url http://localhost:3001 --api-key sk_test_xxx --format json
| Suite | Tests | Description |
|---|---|---|
health | 2 | Health check endpoint and JWKS key validation |
agents | 5 | Agent registration, listing, retrieval, update, deletion |
authorize | 4 | Authorization request creation and consent flow |
token | 3 | Token exchange, invalid code rejection, code reuse prevention |
tokens | 4 | Token verification, revocation, post-revoke verification |
grants | 4 | Grant listing, retrieval, revocation, status validation |
delegation | 5 | Grant delegation, JWT claims, scope enforcement, depth limits, cascade revocation |
audit | 5 | Audit log creation, hash chain integrity, entry retrieval |
security | 5 | Auth enforcement, JWKS algorithm, scope escalation prevention, audit immutability |
| Suite | Tests | Description |
|---|---|---|
policies | 5 | Policy CRUD operations |
webhooks | 3 | Webhook registration and management |
scim | 6 | SCIM 2.0 provisioning endpoints |
sso | 4 | SSO configuration and flow |
anomalies | 3 | Anomaly detection and acknowledgement |
compliance | 4 | Compliance reporting and evidence export |
import { runConformanceTests } from '@grantex/conformance/runner';
import { reportJson } from '@grantex/conformance/reporter';
const report = await runConformanceTests({
baseUrl: 'http://localhost:3001',
apiKey: 'sk_test_xxx',
format: 'json',
bail: false,
});
console.log(reportJson(report));
/v1/consent/:id/approve endpoint must be available| Code | Meaning |
|---|---|
0 | All tests passed |
1 | One or more tests failed |
2 | Configuration or runtime error |
Apache-2.0
FAQs
Conformance test suite for the Grantex protocol
The npm package @grantex/conformance receives a total of 152 weekly downloads. As such, @grantex/conformance popularity was classified as not popular.
We found that @grantex/conformance demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.

Product
Socket can now send alerts and supply chain attack notifications to Microsoft Teams, with filters that route the right updates to each channel.

Security News
pnpm 12 rewrites the package manager in Rust, cutting install times by up to 90% while preserving pnpm 11 workflows and lockfiles.