# @hapi/bourne

> JSON parse with prototype poisoning protection

Latest version **4.0.1** (published 2026-07-02) · BSD-3-Clause license · 0 weekly downloads

## Install

```sh
npm install @hapi/bourne
pnpm add @hapi/bourne
yarn add @hapi/bourne
bun add @hapi/bourne
```

## Health

**Score 70/100 (B)** — status: active.

Positive: has types; esm support; no vulnerabilities; recently updated; high maintenance score; high quality score.

Warnings: low downloads.

## Facts

| | |
|---|---|
| Version | 4.0.1 |
| Published | 2026-07-02 |
| First published | 2019-03-29 |
| Weekly downloads | 0 |
| License | BSD-3-Clause |
| TypeScript types | bundled |
| Module format | ESM |
| Node | >=22 |
| Dependencies | 0 |
| Unpacked size | 9 KB |
| Known vulnerabilities | 0 |
| Install scripts | no |
| GitHub stars | 180 |
| Maintainers | nlf, devinivy, wyatt, lloydbenson, cjihrig, marsup |
| Keywords | JSON, parse, prototype, safe |

## Links

- npm: https://www.npmjs.com/package/@hapi/bourne
- Repository: https://github.com/hapijs/bourne
- Homepage: https://github.com/hapijs/bourne#readme
- Issues: https://github.com/hapijs/bourne/issues
- npm.io page: https://npm.io/package/@hapi/bourne

## Alternatives

- [@mapbox/jsonlint-lines-primitives](https://npm.io/package/@mapbox/jsonlint-lines-primitives.md) — 5.3M weekly downloads
- [reftools](https://npm.io/package/reftools.md) — 3.5M weekly downloads
- [@hey-api/openapi-ts](https://npm.io/package/@hey-api/openapi-ts.md) — 3.5M weekly downloads
- [@mapbox/geojson-rewind](https://npm.io/package/@mapbox/geojson-rewind.md) — 2.4M weekly downloads
- [turbo-stream](https://npm.io/package/turbo-stream.md) — 1.7M weekly downloads

## Recent versions

- 4.0.1 (latest) — 2026-07-02
- 4.0.0 — 2026-07-01
- 3.0.0 — 2022-05-03
- 2.1.0 — 2022-04-08
- 2.0.0 — 2020-01-04
- 1.3.2 — 2019-04-28
- 1.3.1 — 2019-04-28
- 1.3.0 — 2019-04-27
- 1.2.0 — 2019-03-29

## README

<a href="https://hapi.dev"><img src="https://raw.githubusercontent.com/hapijs/assets/master/images/family.png" width="180px" align="right" /></a>

# @hapi/bourne

#### JSON.parse() drop-in replacement with prototype poisoning protection.

**bourne** is part of the **hapi** ecosystem and was designed to work seamlessly with the [hapi web framework](https://hapi.dev) and its other components (but works great on its own or with other frameworks). If you are using a different web framework and find this module useful, check out [hapi](https://hapi.dev) – they work even better together.

### Visit the [hapi.dev](https://hapi.dev) Developer Portal for tutorials, documentation, and support

## Useful resources

- [Documentation and API](https://hapi.dev/family/bourne/)
- [Version status](https://hapi.dev/resources/status/#bourne) (builds, dependencies, node versions, licenses, eol)
- [Changelog](https://hapi.dev/family/bourne/changelog/)
- [Project policies](https://hapi.dev/policies/)
- [Free and commercial support options](https://hapi.dev/support/)

---
_Source: https://npm.io/package/@hapi/bourne · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
