npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@abdoknbgit/tau-installer

v0.1.3

Published

Install Tau globally with its reviewed npm lifecycle scripts allowed for this install only.

Readme

Tau Installer

@abdoknbgit/tau-installer installs Tau globally. On npm 11.16 and newer, it allows only Tau's reviewed npm lifecycle scripts for that single install command. Older npm versions use npm's normal lifecycle-script behavior because they do not support the command-scoped policy.

Node.js 20.18.1 or newer is required.

Install or update to the latest Tau

npx -y @abdoknbgit/tau-installer@latest

Install an exact Tau version

Tau's updater can pin the release it already selected:

npx -y @abdoknbgit/tau-installer@latest --tau-version 0.92.15

--tau-version accepts an exact semantic version only. Tags and ranges such as latest, ^0.92.15, and 0.92.x are rejected.

Inspect without installing

npx -y @abdoknbgit/tau-installer@latest --dry-run

The installer has no dependencies and no lifecycle scripts of its own. It runs the invoking npm CLI with shell: false. On npm 11.16 and newer, it passes the reviewed list through a command-line --allow-scripts option. It never runs npm config set and never changes the user's persistent npm configuration.

For this command only, the installer also disables inherited ignore-scripts and dangerously-allow-all-scripts settings, disables inherited npm dry-run and package-lock-only modes, forces executable bin links, includes supported optional dependencies, and, where supported, enables strict script policy. On npm 11.16 and newer, required reviewed scripts can run while an unreviewed dependency script stops the install.

The installer checks the invoking npm version first. npm 11.16 and newer receive the command-only --allow-scripts list. Older npm versions omit that unsupported option because they run lifecycle scripts normally.

Tau's release tests derive the reviewed list from package-lock.json and fail when a production dependency adds or removes an install script. This keeps the installer policy explicit without changing users' persistent npm configuration.