npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@aaub-software/dsh-sast-contract

v0.1.0

Published

Versioned, scanner-neutral SAST result contract for DeepSeek Harness security plugins.

Readme

@aaub-software/dsh-sast-contract

Versioned, scanner-neutral SAST result contract for DeepSeek Harness security plugins.

The package gives Semgrep, ESLint Security, and future scanner plugins a common model-facing result shape while preserving bounded scanner-specific evidence.

Scope

This package defines the scanner fact layer:

  • scanner and component versions;
  • normalized rule metadata and severity;
  • workspace-relative source locations;
  • findings and scanner-provided evidence;
  • diagnostics that affect scan completeness;
  • result counts, truncation, and duration.

It does not define model verdicts, false-positive decisions, remediation text, cross-tool grouping, or final report formatting. Those belong to later Agent review layers.

Install

npm install @aaub-software/dsh-sast-contract

The package requires Node.js 24 or newer.

TypeScript usage

import {
  SAST_SCHEMA_VERSION,
  type SastScanResult,
} from '@aaub-software/dsh-sast-contract'

const result = {
  schemaVersion: SAST_SCHEMA_VERSION,
  status: 'completed',
  scanner: {
    name: 'example-scanner',
    version: '1.0.0',
    configuration: 'security-default',
  },
  scannedPaths: ['src'],
  findings: [
    {
      id: 'example-scanner:rule-id:src/server.js:2:18',
      scanner: 'example-scanner',
      rule: {
        id: 'rule-id',
        severity: 'error',
        cwe: ['CWE-95'],
      },
      message: 'A dynamic expression reaches an eval call.',
      location: {
        path: 'src/server.js',
        startLine: 2,
        startColumn: 18,
        endLine: 2,
        endColumn: 44,
      },
      evidence: [],
    },
  ],
  diagnostics: [],
  summary: {
    scannedFiles: 1,
    totalFindings: 1,
    returnedFindings: 1,
    truncated: false,
    durationMs: 125,
  },
} satisfies SastScanResult

The generated declaration files let an editor complete contract fields and let TypeScript reject incompatible values before the scanner plugin is published.

Scanner-specific evidence

Plugins may extend SastEvidence with typed evidence that the scanner actually emitted:

import type {
  SastEvidence,
  SastScanResult,
} from '@aaub-software/dsh-sast-contract'

interface MetavariableEvidence extends SastEvidence {
  type: 'semgrep.metavariables'
  data: {
    [name: string]: string
  }
}

type SemgrepScanResult = SastScanResult<MetavariableEvidence>

Evidence types should be stable and namespaced. Plugins must not copy complete native scanner output into data.

Normalization rules

A scanner adapter should:

  1. convert native severities to info, warning, or error;
  2. convert host paths to forward-slash workspace-relative paths;
  3. retain accurate rules, messages, locations, fingerprints, and useful evidence;
  4. separate security findings from scan diagnostics;
  5. report truncation and partial coverage explicitly;
  6. omit progress logs, cache details, host paths, and unrelated runtime internals.

Optional CWE, OWASP, reference, fingerprint, and evidence fields must come from scanner output or an explicitly maintained deterministic mapping. Adapters must not guess them.

JSON Schema

The Draft 2020-12 runtime schema is exported as:

@aaub-software/dsh-sast-contract/schema

Its schema identifier is:

urn:aaub-software:ssc-sast:v1

TypeScript declarations provide compile-time checks. The JSON Schema supports runtime validation and plugins implemented in other languages.

Versioning

Every result carries schemaVersion: "ssc-sast/v1". Additive optional fields remain compatible with v1. Removing fields, changing required fields, or changing field meaning requires a new protocol version.

License

MIT