npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@agentic-research/depgraph-core

v0.2.0

Published

Portable dependency-map contract, derivation and gate. One dependency (zod), no filesystem, no network — runs in workerd.

Readme

@agentic-research/depgraph-core

The portable half of a derived dependency map: the contract, the derivation, and the gate. No filesystem, no network, no process — its only dependencies are zod and smol-toml, so it runs in workerd, a Durable Object or a browser as readily as in Node.

Reading repositories is @agentic-research/depgraph-collect, which is Node-only and depends on this.

Why the split is here and not somewhere convenient

The derivation is the part that has to be reproducible. The design rests on one gate — re-derive from the same sources and compare byte-for-byte — and that gate is only meaningful if deriving cannot reach the network. If it could, "the artifact matches its sources" would quietly become "the artifact matches whatever the network returned this time".

So the boundary is not stylistic. It is what makes the guarantee checkable.

What it produces

A document splitting authored statements (a maintainer's judgment: status, membership, editorial relationships) from derived facts (read from a repository's own manifests). Every edge carries how it was resolved:

  • edges — the target was named outright, or named an identifier that repository declares publishing.
  • weak_edges — the target could only be matched by name. Kept, because deleting a real coupling is its own distortion, but never folded into edges.
  • unresolved — parsed, and resolved to no repository, with the reason.

Scope, stated plainly

unresolved records resolution gaps. A coupling declared in a format the collector has no parser for is never attempted, so it is absent rather than recorded. Read sources_read for which formats were actually read, and treat everything outside that list as unexamined rather than empty.

Usage

import { derive, checkGraph, schemaUrl } from "@agentic-research/depgraph-core";

const graph = derive(lock, projects, { origin: "https://example.com" });

const result = checkGraph({
  lockText,
  graphText,
  projects,
  origin: "https://example.com",
});
if (!result.ok) throw new Error(result.message);

origin is required and deliberately not defaulted: it becomes the document's $schema, and a default would have every deployment publish an artifact pointing at somebody else's contract — a link that resolves, returns a plausible document, and is wrong.

License

Apache-2.0