← Home

@twsxtd/hapi

App for agentic coding - access coding agent anywhere

51
Versions
AGPL-3.0-only
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

twsxtd

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@hapi/protocol AI (phantom-deps): Monorepo workspace package; not directly imported in this sub-package. ai
phantom-deps phantom-dep:yaml AI (phantom-deps): Monorepo workspace package; deps declared at root level. ai
phantom-deps phantom-dep:tar AI (phantom-deps): Referenced in config; stable false positive for this package. ai
phantom-deps phantom-dep:zod AI (phantom-deps): Schema validation loaded by convention; stable false positive. ai
phantom-deps phantom-dep:axios AI (phantom-deps): HTTP client referenced in config; stable false positive. ai
phantom-deps phantom-dep:chalk AI (phantom-deps): CLI styling loaded by convention; stable false positive. ai
phantom-deps phantom-dep:react AI (phantom-deps): Framework loaded by convention; stable false positive. ai
phantom-deps phantom-dep:fastify AI (phantom-deps): Web framework referenced in config; stable false positive. ai
phantom-deps phantom-dep:ps-list AI (phantom-deps): Process listing referenced in config; stable false positive. ai
phantom-deps phantom-dep:cross-spawn AI (phantom-deps): Process spawning referenced in config; stable false positive. ai
phantom-deps phantom-dep:@types/react AI (phantom-deps): Type definitions loaded by convention; stable false positive. ai
phantom-deps phantom-dep:@types/ps-list AI (phantom-deps): Type definitions loaded by convention; stable false positive. ai
phantom-deps phantom-dep:socket.io-client AI (phantom-deps): WebSocket client referenced in config; stable false positive. ai
phantom-deps phantom-dep:@types/cross-spawn AI (phantom-deps): Type definitions loaded by convention; stable false positive. ai
phantom-deps phantom-dep:react-devtools-core AI (phantom-deps): DevTools referenced in config; stable false positive. ai
phantom-deps phantom-dep:@modelcontextprotocol/sdk AI (phantom-deps): SDK referenced in config; stable false positive. ai
phantom-deps phantom-dep:fastify-type-provider-zod AI (phantom-deps): Type provider referenced in config; stable false positive. ai
phantom-deps phantom-dep:@types/tmp AI (phantom-deps): Type definitions loaded by convention; stable false positive. ai
phantom-deps phantom-dep:ink AI (phantom-deps): UI framework loaded by convention in config; stable false positive. ai
provenance no-provenance AI (provenance): Package lacks Sigstore provenance but has a public GitHub repo and 46 published versions; absence of provenance is common and not a disqualifier here. ai
semgrep semgrep:child-process-import AI (semgrep): bin/hapi.cjs is a CLI wrapper that uses execFileSync to dispatch to platform-specific prebuilt binaries via optional deps — standard pattern for native binary distribution, not a threat. ai

Versions (showing 51 of 55)

View all versions
Version Deps Published
0.20.0 0 / 0
0.19.0 0 / 0
0.18.4 0 / 0
0.18.3 0 / 0
0.18.2 0 / 0
0.18.1 0 / 0
0.18.0 0 / 0
0.17.4 0 / 0
0.17.3 0 / 0
0.17.2 0 / 0
0.17.1 0 / 0
0.17.0 0 / 0
0.16.8 0 / 0
0.16.7 0 / 0
0.16.6 0 / 0
0.16.5 0 / 0
0.16.4 0 / 0
0.16.3 0 / 0
0.16.2 0 / 0
0.16.1 0 / 0
0.16.0 0 / 0
0.15.4 0 / 0
0.15.3 0 / 0
0.15.2 0 / 0
0.15.1 0 / 0
0.15.0 0 / 0
0.14.0 0 / 0
0.13.0 0 / 0
0.12.1 0 / 0
0.12.0 0 / 0
0.11.1 0 / 0
0.11.0 0 / 0
0.10.0 0 / 0
0.9.2 0 / 0
0.9.0 0 / 0
0.8.2 0 / 0
0.8.1 0 / 0
0.8.0 0 / 0
0.7.3 0 / 0
0.7.2 0 / 0
0.7.1 0 / 0
0.7.0 0 / 0
0.6.0 0 / 0
0.5.0 0 / 0
0.4.1 16 / 5
0.4.0 16 / 5
0.3.3 15 / 5
0.3.2 15 / 5
0.3.1 15 / 5
0.3.0 15 / 5
0.2.2 15 / 5

v0.20.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.19.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.18.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.18.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.18.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.18.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.18.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.17.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.17.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.17.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.17.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.16.8

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.16.7

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.16.6

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.16.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.16.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.16.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.16.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.16.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.16.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.15.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.15.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.15.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.15.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.15.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.14.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.13.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.11.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.11.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.10.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.8.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.8.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.8.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.4.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.4.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.3.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.3.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.3.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.3.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.