{"uid":"cap_9d0t6ACIYLWRN56tGHtmw","slug":"preflight-package-version-check-83435ee9","name":"Preflight Package Version Check","description":"Call before pinning or installing a specific package version in npm, PyPI or crates.io. Returns whether that exact version exists in the official registry, its publication timestamp, whether it is deprecated or yanked, its published artifact hashes, and whether an expected SRI/hex digest matches. Compares registry metadata only and never returns a safety verdict.","url":"https://preflight402.com/v1/deps/version-check?utm_source=zero.xyz","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"name":{"type":"string","maxLength":214,"minLength":1},"version":{"type":"string","maxLength":128,"minLength":1},"filename":{"type":"string","maxLength":255,"minLength":1},"ecosystem":{"enum":["npm","pypi","crates"],"type":"string"},"expected_integrity":{"type":"string","maxLength":255,"minLength":1}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.05","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.05/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.05","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.05","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_KnbPiUGYy7opMoMq5gyfn","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.05","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Verifies that a specific package version exists in npm, PyPI, or crates.io, returning its publication timestamp, deprecation/yanked status, artifact hashes, and optional SRI/hex digest comparison.","exampleAgentPrompt":"Before we pin it, check whether lodash version 4.17.20 exists in the npm registry, confirm it isn't deprecated, and verify its integrity hash matches sha512-abc123xyz.","exampleUseCases":[{"title":"Validate npm dependency before pinning","prompt":"I'm about to lock lodash at version 4.17.21 in our npm project — can you confirm that exact version actually exists in the registry, that it's not deprecated, and tell me when it was published?"},{"title":"Verify yanked PyPI package before install","prompt":"Check if requests version 2.28.0 is available and not yanked on PyPI before our build pipeline tries to install it."},{"title":"Confirm crate integrity hash before signing off","prompt":"We're pinning serde at version 1.0.163 for our Rust project — verify it exists on crates.io and check whether our expected hex digest d3a7f0c1b2e94a55 matches the real artifact hash."}],"resultDescription":"Returns a structured response indicating whether the exact package version exists in the specified registry, its publication timestamp, whether it is deprecated or yanked, the published artifact hashes for that version, and whether a provided expected SRI or hex digest matches the registry-recorded hash. Does not return a security safety verdict.","failureModes":["Package name or version not found in specified registry — returns existence: false","Invalid ecosystem value — validation error on input","Malformed version string — parsing error returned","Expected integrity hash format unrecognized — mismatch or format error","Registry temporarily unavailable — upstream timeout error","Rate limiting or payment failure — 402 or 429 response"],"whenToPreferThis":"Use this endpoint when an AI agent is about to install, pin, or lock a specific dependency version and needs to confirm that exact version exists in the official registry, check its deprecation status, and optionally verify a known artifact hash — especially in automated pipelines where hallucinated or misremembered version numbers could introduce supply-chain risk. Prefer this over general package search endpoints when you have an exact name+version and need ground-truth registry confirmation rather than discovery.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-02T01:24:54.842Z","isFirstParty":false,"canonicalSlug":"preflight-package-version-check-83435ee9"}