npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@adjudicate/runtime

v0.4.0

Published

Runtime-side framework helpers for adjudicate. Two concerns live here:

Downloads

286

Readme

@adjudicate/runtime

Runtime-side framework helpers for adjudicate. Two concerns live here:

  1. Deferred-intent park/resume — the kernel returns DEFER when an intent is valid but awaits an external signal (a payment webhook confirming a pending charge, a manager approving a request, an inventory restock unblocking an order). This package handles both halves of that flow with content-addressed deduplication, so duplicate signal deliveries fold into exactly one resume.
  2. Deadline helpers — small primitives for racing async generators against a hard wall-clock deadline; useful for orchestrators wrapping LLM streams.

The Redis client and key-builder are always injected — this package has no transport or namespacing assumptions of its own.

Public surface

import {
  // resume side (defer-resume.ts)
  resumeDeferredIntent,
  deferResumeHash,
  verifyParkedEnvelopeHash,
  DEFAULT_MAX_RESUME_CYCLES,        // 3
  DEFER_PENDING_TTL_GRACE_SECONDS,  // 14 days
  type DeferRedis,
  type DeferLogger,
  type DeferResumeResult,
  type ParkVerificationResult,
  type ParkedEnvelope,
  type ResumeDeferredIntentArgs,

  // park side (defer-park.ts)
  parkDeferredIntent,
  decrementDeferCounter,
  deferParkKey,
  deferCounterKey,
  DEFAULT_DEFER_QUOTA_PER_SESSION,  // 16
  type ParkRedis,
  type CounterRedis,
  type ParkDeferredIntentArgs,
  type ParkDeferredIntentResult,
  type ParkLogger,

  // deadline helpers (with-deadlines.ts)
  deadlinePromise,
  DEADLINE_HIT,
} from "@adjudicate/runtime";

How it works

Park. When the kernel returns DEFER, the adopter calls parkDeferredIntent, which enforces a per-session quota (DEFAULT_DEFER_QUOTA_PER_SESSION = 16, tunable) before writing the envelope to rk("defer:pending:${sessionId}") with EX: ttlSeconds. The caller sets ttlSeconds (typically signal.timeoutMs / 1000 + grace). Quota overflow returns { parked: false, reason: "quota_exceeded" } and emits a recordResourceLimit event. Park the envelope with its hash-verification fields (version, nonce, taint, actorPrincipal) so resume-time tamper detection works; legacy blobs lacking them fail closed under the default strict policy.

Resume. When the awaited signal lands, the adopter calls resumeDeferredIntent, which:

  1. Reads the parked envelope (no_parked_envelope / malformed_envelope / signal_mismatch short-circuit early).
  2. Verifies the blob hash (verifyHash, default "strict"): re-derives intentHash via sha256Canonical from the stored fields and asserts byte-equality. Mismatch → park_blob_tampered; legacy blob missing the fields → park_blob_unverifiable (under "warn" it logs and proceeds; "off" skips the check entirely). Guards against an attacker with Redis write access mutating the parked payload between park and resume.
  3. Enforces the resume-cycle cap (maxResumeCycles, default DEFAULT_MAX_RESUME_CYCLES = 3): bounds a DEFER → resume → re-adjudicate → DEFER oscillation driven by a misbehaving signal source. Over the cap → cycle_cap_exceeded. Requires redis.incr; silently skipped without it. Set to 0 to disable.
  4. Acquires a resume token at rk("defer:resumed:${deferResumeHash(intentHash, signal)}") via SET NX — first writer wins. Loser → duplicate_resume_suppressed.
  5. On success, deletes the parked key, best-effort DECRs the per-session counter (if redis.decr is wired), and returns the envelope so the adopter can re-adjudicate it.

DEFER_PENDING_TTL_GRACE_SECONDS (14 days) is the retention applied to the resume-token and cycle-counter keys created on the resume side — not the parked-envelope TTL, which the adopter controls via parkDeferredIntent's ttlSeconds.

Adapter contract

interface DeferRedis {
  get(key: string): Promise<string | null>;
  set(
    key: string,
    value: string,
    options: { NX: true; EX: number },
  ): Promise<string | null>; // "OK" on success, null on collision
  del(key: string): Promise<unknown>;

  // Optional. Absence degrades gracefully:
  incr?(key: string): Promise<number>;        // required for the resume-cycle cap
  decr?(key: string): Promise<number>;        // keeps the per-session quota counter live
  expire?(key: string, seconds: number): Promise<unknown>; // bounds the cycle-counter key
}

The shape matches node-redis v4+; ioredis users need a thin wrapper. parkDeferredIntent takes a separate ParkRedis (atomic incr/decr/expire plus an optional evalIncrCheck Lua hook for a race-free quota check) — see defer-park.ts.

Second-domain example

examples/clinic/clinic-policies.ts is a minimal PolicyBundle showing how to author a domain against @adjudicate/core (top-level types) and @adjudicate/core/kernel (adjudicate, PolicyBundle, combinators) without forking the framework — useful for verifying the kernel handles your domain shape before wiring up the park/resume flow above.