npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@caisson-sh/audit-worm

v2.2.5

Published

Write-once (WORM) artifact store with an S3 Object-Lock backend, a SHA-256 append-only audit chain with a trusted WORM anchor, and an append-only locked-version database with a derived current version.

Readme

@caisson-sh/audit-worm

The Compliance edition's evidentiary primitive: a write-once (WORM) artifact store, a SHA-256 append-only audit chain anchored into WORM, and an append-only locked-version DB with a derived current. A primitive (ADR-0020) that composes the @caisson-sh/kernel integrity algebra over @caisson-sh/tenancy-rls tenant scoping — down-only, never depending on an edition (ADR-0003).

  • License: Apache-2.0

Install

bun add @caisson-sh/audit-worm

Surface

  • ArtifactStore — local, S3 Object-Lock, GCS Bucket Lock, R2, and Azure Blob version-level WORM backends behind injected clients (no live cloud in CI). Version-capable backends return an immutable object version id and target it on reads/retention extensions. S3 GOVERNANCE remains the default; COMPLIANCE requires the typed irreversibleComplianceOptIn guard. assertSafeKey / buildArtifactKey enforce the {account_id}/… prefix; retainUntilFrom is the 6–7yr HIPAA/SEC retention floor.
  • AuditChainStore — append-only per-tenant chain; every append mints a fresh length-keyed, write-once WORM anchor, so tamper, tail-truncation, and wholesale rewrite are all evident (verify runs verifyChain(entries, anchor)).
  • LockedVersionStore — append-only locked versions; "current" is a derived no-successor predicate cross-checked against the kernel model (never a stored column).
  • External anchoring (v1, trusted-timestamped grade) — TrustedTimestampLog/TsaAnchorLog, the durable AnchorOutbox, the per-tenant checkpoint handler, and verifyExternal periodically attest the chain's WORM anchor to an RFC-3161 TSA (SPEC external-anchoring, ADR-0332/0346). Trust grades, the honest-limit language, and the TSA egress note: docs/security/external-anchoring.md.

Golden

src/__golden__/anchor.json pins the canonical {length, tipHash, genesisHash} anchor (ADR-0013); update only via BLESS=1 bun test.