{"uid":"cap_OPjMLuRFLRWletETNOZid","slug":"preflight-stack-dependency-preflight-api-11f52487","name":"Preflight Stack Dependency Preflight API","description":"Evaluate up to 10 exact npm or PyPI package versions in one $0.02 paid batch immediately before installation or an exact-version change. Returns deterministic allow, review, or block guidance with known-vulnerability, lifecycle, declared-license, release-age, and npm install-lifecycle evidence. Reuse a current result for unchanged inputs instead of purchasing a duplicate check for an installation retry.","url":"https://api.preflightstack.com/v1/dependency-preflight","method":"POST","headers":{},"bodySchema":null,"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.02","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"registry","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.02/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_cREkrBQqHtdKSm2vULz8G","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.02","costPer":"request","priority":0,"asset":null,"unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Screens up to 10 npm or PyPI package versions against security, lifecycle, license, and release-age policies to return a deterministic allow/review/block decision before installation.","exampleAgentPrompt":"Before I install these packages, screen them for me: check numpy 1.24.0 and requests 2.28.1 on PyPI — tell me if they're safe to install, flagging any known vulnerabilities, license issues, or suspicious install scripts.","exampleUseCases":[{"title":"CI pipeline dependency gate","prompt":"Before merging this PR, screen all the new npm packages it adds — specifically express 4.18.2 and lodash 4.17.21 — and block the merge if any of them get a 'block' decision for vulnerabilities or risky install scripts."},{"title":"Python ML project safety check","prompt":"I'm about to add tensorflow 2.12.0 and scikit-learn 1.2.2 to my PyPI requirements — can you check both against your security policy and tell me if either should be reviewed or blocked before I commit the changes?"},{"title":"Open source license compliance audit","prompt":"We have a strict no-GPL policy. Screen these npm packages for me — chalk 5.3.0, moment 2.29.4, and uuid 9.0.0 — and flag any that have license issues or are past their support lifecycle."}],"resultDescription":"Returns a per-package deterministic decision of 'allow', 'review', or 'block' under the current policy, along with supporting evidence including known CVEs, lifecycle status (e.g. deprecated, unmaintained), declared SPDX license, release age in days, and whether npm install-lifecycle scripts (preinstall/postinstall) are present.","failureModes":["Unsupported ecosystem or package format returns validation error","Package version not found in registry returns not-found error","More than 10 packages submitted in a single call returns payload-too-large error","Network timeout if upstream registry is unavailable","Payment not included or insufficient USDC returns 402 Payment Required"],"whenToPreferThis":"Choose this endpoint when you need a fast, policy-driven, deterministic allow/review/block verdict on specific npm or PyPI package versions before installation — especially in automated CI/CD pipelines or agentic workflows where you need structured evidence (CVEs, license, lifecycle, install scripts) rather than raw advisory data. Prefer it over generic vulnerability databases when you want a single actionable decision rather than raw advisory lists, and when you need to screen up to 10 packages in one call with a clear policy-based outcome.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T06:38:20.493Z","isFirstParty":false}