npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@a2amesh/runtime

v0.18.2

Published

A2A Mesh runtime, client, server, storage, auth, telemetry, and testing infrastructure for A2A-native agents.

Readme

@a2amesh/runtime

Core runtime, client APIs, auth, telemetry, storage, and middleware for A2A Mesh.

See Compatibility for supported Node.js, protocol, transport, package, and peer ranges.

TaskManager keeps the synchronous ITaskStorage API. AsyncTaskManager uses AsyncTaskStorage for promise-based stores and transactional task updates.

AsyncTaskStorage.transaction(callback) is optional but recommended for read/modify/write operations. Implementations should serialize the callback, commit on resolve, and roll back on throw or rejection. Keep external network or timer waits outside the transaction callback.

Use SyncTaskStorageAdapter to run an existing ITaskStorage implementation behind AsyncTaskManager.

SQLite storage is optional. Install better-sqlite3 in the application workspace before constructing SqliteTaskStorage or AsyncSqliteTaskStorage.

Installation

The supported stable channel is latest.

npm install @a2amesh/runtime

Outbound HTTP policy

A2AClient and AgentRegistryClient use the shared outbound policy by default. An explicit loopback URL enables loopback access for local development; private networks and public-to-loopback redirects remain blocked unless narrowly allowed. A hostname allowlist is restrictive and never bypasses private-address validation. Fetch operations also reject unresolved names because they cannot bind the connection to a validated address. A custom fetchImplementation is an explicit trusted integration and test escape hatch; it must honor the supplied AbortSignal and Undici dispatcher.

Use validateAndFetch or createOutboundPolicyFetch for additional outbound surfaces. Every redirect hop is revalidated and connected through the exact DNS address set that was validated. HTTPS-to-HTTP redirects are blocked by default. The total deadline covers DNS, connect, headers, retries, and complete body or SSE consumption. OIDC discovery and JWKS retrieval use this same path.

Default response limits are 10 MiB total, 10,000 SSE events, 64 KiB per SSE line, 1 MiB per SSE event buffer, and a 30-second SSE idle interval. Override these through OutboundPolicyOptions when the protocol contract requires a smaller bound. Callers that inspect only status or headers must cancel the response body.

Retries are enabled only for idempotent methods, replayable request bodies, or requests carrying an Idempotency-Key. URLs and sensitive headers are redacted from logs and spans. See SSRF Policy.

Idempotency reservations

A2AServer reserves supported Idempotency-Key requests before method dispatch. The default InMemoryIdempotencyStore coordinates one Node.js process. Multi-replica deployments must inject a shared RedisIdempotencyStore; its atomic owner-token transitions prevent concurrent replicas from executing the same scoped request twice. Configure idempotencyLeaseMs for the renewable owner lease and idempotencyTtlMs for terminal response replay. See Idempotency Reservations.