@hapi/address
Email address and domain validation
16
Versions
BSD-3-Clause
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
cjihrigmarsupnlfdevinivywyattlloydbensonnargonath
Keywords
emaildomainaddressvalidation
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| maintainer-change | maintainer-takeover | AI (maintainer-change): Legitimate hapi.js org governance transition; hueniverse stepped back from hapi ecosystem, replaced by known long-standing hapi contributors. Not a hijack. | ai | |
| provenance | publisher-changed | AI (provenance): marsup is a trusted, long-standing hapi.js contributor (1891 approved packages, 12+ years on npm). Publisher change reflects documented org transition. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): New maintainers are all known hapi.js org contributors; legitimate org-level governance change. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): hueniverse (Eran Hammer) is known to have stepped back from hapi.js; removal is part of documented org transition. | ai | |
| source-diff | large-new-source-files | AI (source-diff): New files are TypeScript source and compiled output (dist/esm dirs) consistent with TypeScript migration visible in package.json scripts and devDependencies. | ai |