npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@aegiskit/policy-diff

v0.1.0

Published

Semantic access diff for Supabase RLS migrations: turns two migration states into a plain-English access delta (who can newly read/write what), fail-safe by design — for PR review, CI gating, and change-management evidence.

Readme

@aegiskit/policy-diff

Semantic access diff for Supabase RLS migrations: compare the access-control surface (policies, RLS state, table grants) of two migration states and get, in plain language, who can newly read or write what — for PR review, CI gating, and change-management evidence.

Install

pnpm add @aegiskit/policy-diff @aegiskit/scanner

@aegiskit/scanner is a peer — it supplies buildRlsModel and SqlSource. Most users get this wired for free via the aegis diff CLI and the GitHub Action; import this package directly only to build a custom gate.

import { buildRlsModel } from '@aegiskit/scanner';
import { diffAccess, renderDeltaMarkdown, summarizeDeltas } from '@aegiskit/policy-diff';

const base = buildRlsModel(baseSources); // supabase/migrations/**.sql at the base ref
const head = buildRlsModel(headSources); // …at the head ref

const deltas = diffAccess(base, head, { trustedFunctions: ['public.is_member'] });
console.log(renderDeltaMarkdown(deltas, { baseRef: 'main', headRef: 'feat/x' }));
summarizeDeltas(deltas).conclusion; // 'no-change' | 'neutral' | 'attention' | 'action-required'

Trust contract

  • widening is claimed only when the after-rows are a superset-or-equal of the before-rows under the class lattice (none ⊂ own/state/delegated ⊂ all).
  • narrowing only when they are a subset-or-equal — a "safe" verdict never papers over a possible widening.
  • Everything unverifiable — custom functions off the trustedFunctions allowlist, incomparable class moves (owner-scope ↔ row-state ↔ membership check), statements the model recorded as uninterpreted (NO FORCE, partial REVOKE, policies on unmodeled schemas, exotic quoting) — is requires-review. The diff fails closed: it may ask a human to look, it never says "no change" when it cannot know.

Honest scope

This reasons about the shape of predicates over repo-managed SQL. It does not know your data model or business rules, does not see policies changed outside migrations (e.g. via the Supabase dashboard), and a clean diff means "no access-relevant change detected in the modeled surface" — never "this migration is safe". It complements review; it does not replace it.