
Security News
Rust RFC Proposes a Security Tab on crates.io for RustSec Advisories
Rust’s crates.io team is advancing an RFC to add a Security tab that surfaces RustSec vulnerability and unsoundness advisories directly on crate pages.
@samchon/openapi
Advanced tools
@samchon/openapiOpenAPI definitions and converters (for typia and nestia).
@samchon/openapi is a collection of OpenAPI definitions of below versions. Those type definitions does not contain every properties of OpenAPI specification, but just have only some features essentially required for typia and nestia (especially @nestia/editor).
Also, @samchon/openapi provides emended OpenAPI v3.1 definition and its converter/inverter from above versions for convenient development. The keyword "emended" means that OpenApi is not a direct OpenAPI v3.1 specification (OpenApiV3_1), but a little bit shrinked to remove ambiguous and duplicated expressions of OpenAPI v3.1 for the convenience of typia and nestia
For example, when representing nullable type, OpenAPI v3.1 supports three ways. In that case, OpenApi remains only the third way, so that makes typia and nestia (especially @nestia/editor) to be simple and easy to implement.
{ type: ["string", "null"] }{ type: "string", nullable: true }{ oneOf: [{ type: "string" }, { type: "null" }] }Here is the entire list of differences between OpenAPI v3.1 and emended OpenApi.
OpenApiV3_1.IPathItem.parameters to OpenApi.IOperation.parametersOpenApiV3_1.IOperation membersOpenApiV3_1.IJsonSchema.IMixedOpenApiV3_1.IJsonSchema.__ISignificant.nullableOpenAPI.IJsonSchema.IArray.itemsOpenApi.IJsonSchema.ITuple.prefixItemsOpenApiV3_1.IJsonSchema.IAnyOf to OpenApi.IJsonSchema.IOneOfOpenApiV3_1.IJsonSchema.IRecursiveReference to OpenApi.IJsonSchema.IReferenceOpenApiV3_1.IJsonSchema.IAllOf to OpenApi.IJsonSchema.IObjectnpm install @samchon/openapi
import { OpenApi, SwaggerV2, OpenApiV3, OpenApiV3_1 } from "@samchon/openapi";
// original Swagger/OpenAPI document
const input:
| SwaggerV2.IDocument
| OpenApiV3.IDocument
| OpenApiV3_1.IDocument
| OpenApi.IDocument = { ... };
// you can convert it to emended OpenAPI v3.1
const output: OpenApi.IDocument = OpenApi.convert(input);
// it is possible to downgrade to Swagger v2 or OpenAPI v3
const v2: SwaggerV2 = OpenApi.downgrade(output, "2.0");
const v3: OpenApiV3 = OpenApi.downgrade(output, "3.0");
// you can utilize it like below
OpenApi.downgrade(OpenApi.convert(v2), "3.0");
OpenApi.downgrade(OpenApi.convert(v3), "2.0");
typia: https://github.com/samchon/typianestia: https://github.com/samchon/nestia@nestia/editor: https://nestia.io/docs/editorFAQs
OpenAPI definitions and converters for 'typia' and 'nestia'.
The npm package @samchon/openapi receives a total of 196,125 weekly downloads. As such, @samchon/openapi popularity was classified as popular.
We found that @samchon/openapi demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Rust’s crates.io team is advancing an RFC to add a Security tab that surfaces RustSec vulnerability and unsoundness advisories directly on crate pages.

Security News
/Research
Socket found a Rust typosquat (finch-rust) that loads sha-rust to steal credentials, using impersonation and an unpinned dependency to auto-deliver updates.

Research
/Security Fundamentals
A pair of typosquatted Go packages posing as Google’s UUID library quietly turn helper functions into encrypted exfiltration channels to a paste site, putting developer and CI data at risk.