Sign inSign up

getreadystack/openapi-security-contract-lint

By getreadystack

Updated 4 days ago

Finds the lines in an OpenAPI file that publish an endpoint with no authentication, an API key in th

Image
0

91

getreadystack/openapi-security-contract-lint repository overview

OpenAPI Security Contract Lint

Finds the lines in an OpenAPI file that publish an endpoint with no authentication, an API key in the query string, or an OAuth grant RFC 9700 forbids.

Run

docker run --rm -v "$PWD":/work getreadystack/openapi-security-contract-lint /work/file

The same 18 rules as the VS Code extension, in a container. Mount a folder on /work.

Free

  • Audit the OpenAPI file open in the editor against all 18 rules - every finding, every line number, every rule reference, nothing withheld
  • --rules lists every rule

With a licence ($29 once)

  • Sweep every OpenAPI document in the workspace, not just the open tab, and write a dated CSV/JSON/HTML report you keep with the release as evidence
docker run --rm -e READYSTACK_LICENSE=<key> -v "$PWD":/work getreadystack/openapi-security-contract-lint --dir /work --ci

An application-security consultant reading the same contract by hand bills $150-$250 an hour

Use from an AI agent (MCP)

Claude Code · Cursor · Windsurf · any MCP client - add to your MCP config:

{ "mcpServers": { "openapi-security-contract-lint": { "command": "npx", "args": ["-y", "@readystack/openapi-security-contract-lint", "--mcp"] } } }

Tools: check_text and check_file (free) · check_dir (licence; the full sweep is free for 7 days). The agent gets every finding with the line number.

Use in CI

- name: OpenAPI Security Contract Lint
  run: npx -y @readystack/openapi-security-contract-lint --dir . --ci

(container: docker run --rm -v "$PWD:/work" getreadystack/openapi-security-contract-lint --dir /work --ci)

Try the full run free for 7 days — no key needed. Then one licence, 7-day refund, no questions. Set READYSTACK_LICENSE=<key> or run --license <key> once.

Get a licence

Tag summary

Content type

Image

Digest

sha256:565c8a6f0

Size

46.1 MB

Last updated

4 days ago

docker pull getreadystack/openapi-security-contract-lint