extends: - spectral:oas rules: carvana-info-title: description: Carvana API info.title SHOULD end with "API". given: $.info severity: warn then: field: title function: pattern functionOptions: match: ".*API$" carvana-info-version: description: Carvana APIs MUST declare a semantic version. given: $.info severity: error then: field: version function: pattern functionOptions: match: "^\\d+\\.\\d+\\.\\d+(-.*)?$" carvana-server-basepath-versioned: description: Carvana API server URL should include a /vN version segment. given: $.servers[*] severity: warn then: field: url function: pattern functionOptions: match: ".*/v\\d+.*" carvana-security-subscription-key: description: Carvana APIs (hosted on Azure APIM) must declare an apiKey security scheme for the subscription key. given: $.components.securitySchemes severity: error then: function: truthy carvana-vin-parameter: description: Carvana inventory endpoints should accept a `vin` path or query parameter. given: $.paths[?(@property.match(/inventory|vehicle/i))][get,put,patch,delete].parameters severity: info then: function: schema functionOptions: schema: type: array contains: type: object properties: name: const: vin carvana-vehicle-schema: description: Carvana APIs that return vehicles should define a reusable Vehicle schema. given: $.components.schemas.Vehicle severity: info then: function: truthy carvana-inventory-schema: description: Carvana APIs that manage inventory should define a reusable InventoryItem schema. given: $.components.schemas.InventoryItem severity: info then: function: truthy carvana-error-response: description: Carvana operations should declare 400 and 401 error responses. given: $.paths[*][*].responses severity: warn then: field: "400" function: truthy carvana-tag-descriptions: description: Each Carvana tag should carry a description. given: $.tags[*] severity: warn then: field: description function: truthy carvana-operation-summary: description: Each Carvana operation should have a summary. given: $.paths[*][get,post,put,delete,patch] severity: warn then: field: summary function: truthy