npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@clementprevot/pi-package-manager-guard

v0.1.2

Published

Pi extension that gates Node package manager commands to the repo's manager

Readme

@clementprevot/pi-package-manager-guard

A Pi extension that keeps the coding agent honest about package managers: when the agent runs a Node package manager command that does not match the manager your repo's lockfile declares, the command is paused and you decide.

Why

Agents mix up package managers constantly. In a Yarn repo they reach for npm install, in a pnpm repo they run bun add, and suddenly your lockfile has two managers in it and CI is red. This guard catches the mismatch before the command runs.

Install

pi install npm:@clementprevot/pi-package-manager-guard

Updates ship with pi update --extensions. The extension applies to your next session (quit and relaunch or issue a /reload command).

How it works

On every bash tool call, the extension:

  1. Walks up from the session's working directory to find the nearest lockfile (yarn.lock, pnpm-lock.yaml, bun.lockb, bun.lock, package-lock.json). It stops at the git root, so a stray lockfile in an enclosing folder does not leak in.
  2. Splits the command chain into subcommands (respecting quotes, so echo "use npm here" never trips the gate) and checks each one's package manager.
  3. Asks you what to do on a mismatch:
This repo uses yarn (lockfile) but the command uses npm. Allow?
> Yes, allow once
  Yes, allow for this session
  No, use yarn instead
  No, with a reason
  Stop

"No, with a reason" sends your free-text reason back to the agent, which is usually enough for it to correct itself without another round trip.

Exemptions

Commands that never touch the repo's dependencies are allowed through:

  • npx and bunx (runners)
  • yarn dlx and pnpm dlx
  • npm exec
  • Any command that is not a Node package manager (git, brew, ...)
  • Environment-variable prefixes are stripped first, so CI=1 npm install still gets gated

Outside a repo with a lockfile, the guard does nothing.

Configuration

None. The lockfile is the source of truth, by design.

Local development

npm install
npm test
npm run typecheck

To try the extension in a live session without installing it:

pi -e /path/to/this/repo

License

MIT