npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@colineapp/app-runtime

v0.5.1

Published

The Coline App sandbox bridge: typed postMessage protocol between tier-2 app guests and the Coline host.

Readme

@colineapp/app-runtime

The Coline App sandbox bridge — the typed postMessage protocol connecting tier-2 (React) Coline Apps running in a sandboxed iframe to the Coline host.

Most app developers never import this directly: @colineapp/ui's ColineAppProvider wires the guest side for you, and Coline runs the host side. It is a published low-level package for custom hosts and advanced integrations; import it only when you need control below the UI provider.

What it does

  • Guest (connectGuestBridge): runs inside the sandbox. Exposes the full coline.* capability API, receives theme tokens and context, and emits navigation/toast/picker intents. The guest holds zero credentials — every call crosses the bridge and is authorized host-side.
  • Host (createHostBridge): runs in the Coline web app. Verifies message sources, gate-checks every capability call against the install's grants and the surface's effect ceiling before relaying, and pushes live theme + context updates into the frame.
  • Protocol (protocol.ts): zod-validated message schemas shared by both halves — version-checked, so mismatched guest/host fail loudly instead of strangely.
sandboxed iframe (your React app)
  └─ connectGuestBridge()  →  postMessage  →  createHostBridge()
       coline.files.create(...)                gate-check → capability API

Docs

Full guides at coline.app/developers/docs.

MIT © Coline

SDK 0.4 / CLI 2.4 workflow

Run coline-app check before pushing: it checks types, the manifest, hosted logic, and the React bundle without uploading. dev --internal updates one development version; install it in the workspace and reload after changes. The CLI bundles from the app's installed dependencies and preserves imported CSS and inline assets. CLI 2.5 compiles app-specific Tailwind v4 and ordinary CSS automatically. Import UI styles followed by app.css. The scaffold includes experimental UI skills, screen examples, and a credential-free coline-app preview command.

The starter includes a React home and editor, tree mobile fallback, and a tool. Use coline.tools.invoke or actions.invokeTool to run the same declared tool from UI that Kairo runs. Save with expectedVersion to detect concurrent edits. Homes/editors can write within grants; previews and server render handlers cannot. createTestWorkspace(app).client() tests the interactive contract and grantedPermissions simulates revoked consent.

New tasks, calendar, messages, and references capabilities require their explicit manifest permissions and retain the invoking user's workspace access. Use files.list({ scope: "workspace" }) for shared files; document writes stay with the owning app. Collections are install-private. Code integration and a native mobile React runtime are separate work.

Version 0.5 carries the SDK's ai.models, ai.run, ai.images.generate, ai.jobs.get/list/events/cancel and files.readUrl operations through the existing bridge. Long provider work runs in Coline's persistent worker; each bridge call only starts or observes a durable job and keeps the normal timeout.