npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@beyondwork/groundworks

v0.29.0

Published

GroundWorks: the procurement application design system for the Beyond Work platform. Typed React components, one compiled stylesheet, contracts as data.

Readme

GroundWorks

GroundWorks is the procurement-domain derivative hosted inside Chassis. It supplies the shared application frame, procurement vocabulary, operational states, evidence and freshness rules, and governed machine-work patterns. Chassis keeps the global shell.

Status

The system is experimental; system.json states the current version and releases/released.json states every sealed one, so this file recounts neither. The desk language is implemented and testable: the operational frame is DeskFrame with one identity line above the matter, one matter sits on the desk with the chain that produced it, and every public component ships with a contract entry and a Mat specimen. Every card renders in both themes and three pilot desks run in the harness. Six feels ship, a deep violet default labelled Electric and five scoped alternatives, and data colour is a measured ladder of twenty rungs per theme, walked as a ramp of each feel's own colour from 0.18.0. The verifier states its own check and selftest counts in its output. It does not claim that every component named in the proposal has shipped.

Brand and legal approval remain open for the GroundWorks name, datum mark, Accenture relationship, and signal value. The supplied Accenture asset is preserved byte for byte and is not treated as an approved palette source.

Build

cd derivatives/groundworks
npm ci
npm run build
npm test
npm run verify

The build emits:

  • dist/styles.css, the only component stylesheet;
  • dist/index.js, the ESM package entry;
  • dist/contracts.js, the contract entry;
  • dist/types/, the declaration surface;
  • _ds_bundle.js, the gallery and reference-app bundle;
  • harness/app.js, the reference-app runtime;
  • cards/app.js, the local runtime shared by the component cards; _ds_manifest.json cards[] states the set.

The public package

@beyondwork/groundworks on the public npm registry is the same surface the sealed archive carries, packed from the same files[] list gate E8 holds to the cutter's payload: the typed components, the compiled stylesheet, the contracts as data, the vendored OFL faces and the doctrine that binds them. MIT, with no trademark rights granted; the GroundWorks name and datum mark clearance remains open and is recorded in assets/brand-provenance.json. React 19 and ReactDOM are peer dependencies.

npm install @beyondwork/groundworks

Fonts

GroundWorks ships the two families its roles name. theme/fonts.css declares four @font-face rules, two Archivo faces at weight 100 900 and stretch 62% 125%, and two JetBrains Mono faces at weight 100 800, each with font-display: swap. It is imported first from theme/index.css, so the faces are declared before anything asks for them, and the compiled dist/styles.css carries all four rules.

The Archivo width axis is load bearing. The display voice sets wdth to --gw-display-width, and a face declared without the stretch range clamps to 100% and loses the condensed voice without reporting an error.

foundations/fonts/ stays canonical. assets/fonts/ holds four byte-identical vendored copies, recorded with their sha256 in _ds_manifest.json under fonts[].files and sourced in assets/readme.md. Edit the canonical file and resync. Never edit a vendored copy. Gate G20 checks that the four rules reach the compiled stylesheet and that the vendored hashes still match the manifest.

Theme

Chassis decides the theme, light or dark. GroundWorks follows the attribute it is given. Theme is not posture: a posture is the working stance of a surface, work or ledger, and it is the app's own state rather than the host's.

The value layer defines every role twice: once under :root, [data-gw-theme='light'] and once under :is(.dark, [data-bx-theme='dark'], [data-gw-theme='dark']). Both blocks define the same set of roles, which gate G18 recomputes and counts on every run, so data-gw-theme='dark' flips the whole theme rather than part of it. Neutrals are plain colour literals rather than chains into a host colour variable, so a theme resolves identically hosted and standalone. Setting data-gw-theme on any ancestor of the GroundWorks canvas is enough; the .dark and data-bx-theme selectors let a Chassis host drive the same roles without a second attribute.

Density is a third axis: [data-gw-density='compact'] tightens spacing and hit targets without touching colour.

Use inside Chassis

Load the Chassis Platform stylesheet first, then GroundWorks. Render GroundWorks only inside the Chassis canvas. The package uses host-compatible fallback values so a specimen can render alone, but a product must supply Chassis theme and routing contracts.

import { DeskFrame } from '@beyondwork/groundworks/app';
import '@beyondwork/groundworks/styles.css';

<DeskFrame
  posture={posture}
  onPostureChange={setPosture}
  appLabel="Sourcing"
  lineCount={5}
  scope={{ primary: 'Europe, Middle East and Africa · Indirect', view: 'My decisions', dataCut: 'Data cut 12 Aug 2026 · 09:14 UTC · current' }}
  line={<WorkLine heading="Needs you" orderRule="5 matters · ordered by consequence, then due" entries={entries} quiet={quiet} onSelect={seat} />}
  desk={matter}
  shelf={<ReferenceShelf sheets={summoned} onDismiss={dismiss} />}
  ledger={<LedgerSurface lenses={lenses} activeLens={lens} onLensChange={setLens} columns={columns} rows={rows} empty={empty} footnote={footnote} />}
/>;

DeskFrame is the operational frame. The four-section GroundworksAppFrame and AppMarker were removed in 0.5.0; a consumer still on them builds against the 0.4.0 archive.

The frame does not render global search, notifications, identity, theme controls, or account controls.

Authoring rules

  1. Render semantic gw- block, element, and modifier classes.
  2. Bind component appearance to --gw- roles.
  3. Use the pinned glyph meaning registry. Do not draw a functional SVG.
  4. Use words and structure before colour for selection and state.
  5. Keep proposals, approvals, execution, and commitment distinct.
  6. Keep a relevant blocked action focusable when its explanation provides a route out.
  7. Let Chassis own global place, theme, account, and portal roots.

Reference app

Serve the repository and open derivatives/groundworks/harness/index.html. The page mounts the three pilot desks of contracts/apps.registry.json, sourcing, buying and invoices, and automation and authority, inside the real Chassis Platform PlatformShell. Each desk carries its own address, #sourcing, #buying and #automation, and the host register's rows are the links to them. Both postures are reachable, every line can be driven to zero and into the resting surface, and the page exercises wide, narrow, light, and dark states.

The frame changed on 15 August 2026. Until then the page composed WorkspaceShell, which Chassis Platform deprecated in August 2026 and removed at 3.0.0; this harness was its one measured caller, so the recomposition is the condition that retirement waited on. What the retired top bar carried moved zone by zone: the desks are the space's own register rows, search is the shell's command access, theme is the register's theme fixture, and the account control is the register's identity row. The plate reading Requests · 2 did not move, because it counted nothing.

Component cards

Mat renders each public React component from cards/*.card.html. Each wrapper names one component and loads the same local cards/app.js runtime. The wrappers do not load React, Babel, or any other dependency from a CDN.

Contracts

  • contracts/components.registry.json records the proof-set component bar.
  • contracts/vocabulary.registry.json is the operational object language.
  • contracts/glyphs.semantic.json maps GroundWorks meanings to registry names.
  • contracts/apps.registry.json declares the three pilot apps and the six awaiting a desk.
  • contracts/registers.json is the two-register doctrine as data: one register per component, and every place the anchor may appear.
  • contracts/decisions.registry.json is the register of settled decisions, D-GW-1 to D-GW-39, each cited by id where it is relied on.
  • contracts/copy-law.json exports the measurable half of the string law: seven rules with the constants a scanner needs, six of them the app register's and the seventh the five charter row labels G36 measures, and the thirty retired terms with their replacements. A consumer wires its own content scanner to it rather than transcribing copy.md, and gate G30 holds the export to what G27 measures.
  • contracts/apps.schema.json and contracts/authority.schema.json define machine-readable inputs.
  • assets/brand-provenance.json records source hashes and approval limits.

Validation

npm run verify runs the system's own checks over provenance, contracts, glyph resolution, build outputs, role use, package claims, visual prohibitions, token resolution, specimen vocabulary, shipped typography, ladder and spectrum containment, anchor variant containment, figure anatomy, register containment, the seat ceremony, the posture and matter vocabulary, the app register's string law, the framework register's string law, composition purity across the two registers, the motion law, the copy-law export, the strata, the host collision, the notice and the counts, the intent line, and contract entrypoint coverage. It counts them in its own last line, which is where to read the number: a count transcribed into this paragraph goes stale on the next check that lands, and this paragraph's did. Run it with --selftest to inject a violation into every check written as a pure function over file contents and confirm that the matching check, and only that check, goes red; that run counts itself in its last line too, and the checks that read the shipped tree directly carry no injection. Repository gates add strict semantic CSS, copy, manifest, ledger, browser accessibility, responsive, theme, and failure-state checks.

Two chains stand beside it. npm run check takes the readings a checkout can take without a browser, cheapest and most portable first: the eleven sites that state this system's version held to system.json, the outside consumer's figures held to the ref they were read at, then typecheck and the suites under test/. npm run proof takes the rest, and every member of it needs an installed tree, a built one and a served one: npm run verify, then card-check.mjs and browser-check.mjs through Chromium at 127.0.0.1:4173, then npm run check:seal last. The seal is last rather than first because it is the one member that is red by record until the next release is cut: releases/released.json stops at 0.20.0 while system.json reads 0.24.0, so --strict reads E6, an unmeasured reading under a flag that refuses one, and any earlier position would hide the three readings above it behind it. package.json _scriptNotes carries the argument for each row, including how to hand check:consumers a clone of the consumer and what the run says when it has none.

Four of these readings also run in node tooling/registry/validate-ledgers.mjs, as groundworks version coherence, groundworks release seal, groundworks consumer shape and groundworks gate wiring. They sit there rather than only here because two of the version sites are ledgers that file generates, because the seal and the consumer register are what an outside pin resolves against, and because a gate this system owns that no chain runs is the defect the fourth row measures: until 2026-08-22 card-check.mjs and browser-check.mjs were referenced by no chain at all, and this package declared no check script, so the suites under test/ ran only when somebody remembered them. That row reads the tools, the chains, the suite roster and the entry script by name, so a gate can no longer leave a chain in silence. The seal row runs the plain mode and echoes the tool's three summary lines on every run, including the one stating that payload currency was not measured, so a green there is not read as a current payload.

The copy gate reads this system's rulings file, and it reads one only when the command names it:

node tooling/copy/verify-copy.mjs --target derivatives/groundworks \
  --exemptions tooling/copy/exemptions-groundworks.json --strict

Clean on 2026-08-13, ten of ten checks passing, with fifteen rulings consumed over sixteen findings and none unused. The file and segment counts are read from the command's own summary line rather than published here, because both move whenever any prose in this target is edited, including this sentence. Fourteen of the rulings are mention-not-use on copy.md, where the recorded vocabulary ruling, its two cited publication titles, its quoted negative example, its buyer's-terms count line and its ship check each name the banned descriptor in order to bound it. The fifteenth is not on copy.md and is not a mention: it is a C5 ruling on cards/app.tsx, where the catalogue fixture renders a real procurement acronym inside the framework's own domain name and the shouting check reads it as shouting. Every ruling is scoped to a line, so the same descriptor used as a product claim anywhere else in this system still fails. Without the file the run is red at sixteen findings, fifteen of them C10 on copy.md and one C5 on the card fixture.