
Research
2025 Report: Destructive Malware in Open Source Packages
Destructive malware is rising across open source registries, using delays and kill switches to wipe code, break builds, and disrupt CI/CD.
@mintlify/validation
Advanced tools
@mintlify/validation is a small package to validate docs.json files.
npm install @mintlify/validation
import mintValidation from "@mintlify/validation"
const configObject = { name: "Site Name", navigation: [] }
mintValidation.validateMintConfig(configObject)
mintValidation.validateDocsConfig(configObject)
This package assumes you have already loaded a config object into a JavaScript object.
The package returns an object with the properties status, warnings, and errors.
status can be one of: "success", "error".
warnings is a string array with warnings the user should know but are not expected to break the site.
errors is a string array of errors that will likely break the site.
When status === "error" you should stop trying to build mint, your docs.json file is invalid and the site will crash when building.
{
"status": "error",
"warnings": ["Navigation is an empty array, no pages will be shown"],
"errors": ["Mintlify does not support .ico favicons, use .svg or .png instead."]
}
Additional documentation on docs.json is available on Mintlify's website.
Join our Discord community if you have questions or just want to chat:
Built with 💚 by the Mintlify community.
FAQs
Validates mint.json files
The npm package @mintlify/validation receives a total of 32,982 weekly downloads. As such, @mintlify/validation popularity was classified as popular.
We found that @mintlify/validation demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 10 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Destructive malware is rising across open source registries, using delays and kill switches to wipe code, break builds, and disrupt CI/CD.

Security News
Socket CTO Ahmad Nassri shares practical AI coding techniques, tools, and team workflows, plus what still feels noisy and why shipping remains human-led.

Research
/Security News
A five-month operation turned 27 npm packages into durable hosting for browser-run lures that mimic document-sharing portals and Microsoft sign-in, targeting 25 organizations across manufacturing, industrial automation, plastics, and healthcare for credential theft.