@twsxtd/hapi
App for agentic coding - access coding agent anywhere
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@hapi/protocol | AI (phantom-deps): Monorepo workspace package; not directly imported in this sub-package. | ai | |
| phantom-deps | phantom-dep:yaml | AI (phantom-deps): Monorepo workspace package; deps declared at root level. | ai | |
| phantom-deps | phantom-dep:tar | AI (phantom-deps): Referenced in config; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:zod | AI (phantom-deps): Schema validation loaded by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:axios | AI (phantom-deps): HTTP client referenced in config; stable false positive. | ai | |
| phantom-deps | phantom-dep:chalk | AI (phantom-deps): CLI styling loaded by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:react | AI (phantom-deps): Framework loaded by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:fastify | AI (phantom-deps): Web framework referenced in config; stable false positive. | ai | |
| phantom-deps | phantom-dep:ps-list | AI (phantom-deps): Process listing referenced in config; stable false positive. | ai | |
| phantom-deps | phantom-dep:cross-spawn | AI (phantom-deps): Process spawning referenced in config; stable false positive. | ai | |
| phantom-deps | phantom-dep:@types/react | AI (phantom-deps): Type definitions loaded by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:@types/ps-list | AI (phantom-deps): Type definitions loaded by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:socket.io-client | AI (phantom-deps): WebSocket client referenced in config; stable false positive. | ai | |
| phantom-deps | phantom-dep:@types/cross-spawn | AI (phantom-deps): Type definitions loaded by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:react-devtools-core | AI (phantom-deps): DevTools referenced in config; stable false positive. | ai | |
| phantom-deps | phantom-dep:@modelcontextprotocol/sdk | AI (phantom-deps): SDK referenced in config; stable false positive. | ai | |
| phantom-deps | phantom-dep:fastify-type-provider-zod | AI (phantom-deps): Type provider referenced in config; stable false positive. | ai | |
| phantom-deps | phantom-dep:@types/tmp | AI (phantom-deps): Type definitions loaded by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:ink | AI (phantom-deps): UI framework loaded by convention in config; stable false positive. | ai | |
| provenance | no-provenance | AI (provenance): Package lacks Sigstore provenance but has a public GitHub repo and 46 published versions; absence of provenance is common and not a disqualifier here. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): bin/hapi.cjs is a CLI wrapper that uses execFileSync to dispatch to platform-specific prebuilt binaries via optional deps — standard pattern for native binary distribution, not a threat. | ai |
Versions (showing 51 of 65)
| Version | Deps | Published |
|---|---|---|
| 0.23.4 | 0 / 0 | |
| 0.23.3 | 0 / 0 | |
| 0.23.2 | 0 / 0 | |
| 0.23.1 | 0 / 0 | |
| 0.23.0 | 0 / 0 | |
| 0.22.3 | 0 / 0 | |
| 0.21.1 | 0 / 0 | |
| 0.21.0 | 0 / 0 | |
| 0.20.2 | 0 / 0 | |
| 0.20.1 | 0 / 0 | |
| 0.20.0 | 0 / 0 | |
| 0.19.0 | 0 / 0 | |
| 0.18.4 | 0 / 0 | |
| 0.18.3 | 0 / 0 | |
| 0.18.2 | 0 / 0 | |
| 0.18.1 | 0 / 0 | |
| 0.18.0 | 0 / 0 | |
| 0.17.4 | 0 / 0 | |
| 0.17.3 | 0 / 0 | |
| 0.17.2 | 0 / 0 | |
| 0.17.1 | 0 / 0 | |
| 0.17.0 | 0 / 0 | |
| 0.16.8 | 0 / 0 | |
| 0.16.7 | 0 / 0 | |
| 0.16.6 | 0 / 0 | |
| 0.16.5 | 0 / 0 | |
| 0.16.4 | 0 / 0 | |
| 0.16.3 | 0 / 0 | |
| 0.16.2 | 0 / 0 | |
| 0.16.1 | 0 / 0 | |
| 0.16.0 | 0 / 0 | |
| 0.15.4 | 0 / 0 | |
| 0.15.3 | 0 / 0 | |
| 0.15.2 | 0 / 0 | |
| 0.15.1 | 0 / 0 | |
| 0.15.0 | 0 / 0 | |
| 0.14.0 | 0 / 0 | |
| 0.13.0 | 0 / 0 | |
| 0.12.1 | 0 / 0 | |
| 0.12.0 | 0 / 0 | |
| 0.11.1 | 0 / 0 | |
| 0.11.0 | 0 / 0 | |
| 0.10.0 | 0 / 0 | |
| 0.9.2 | 0 / 0 | |
| 0.9.0 | 0 / 0 | |
| 0.8.2 | 0 / 0 | |
| 0.8.1 | 0 / 0 | |
| 0.8.0 | 0 / 0 | |
| 0.7.3 | 0 / 0 | |
| 0.7.2 | 0 / 0 | |
| 0.7.1 | 0 / 0 |
v0.23.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.23.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.23.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.23.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.23.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.22.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.21.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.21.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.