npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@create-cmp/receipts

v0.1.0

Published

Validate create-cmp evidence receipts: inputs-hash recompute, receipt-vs-tree binding, freshness, and execution-plausibility. Dependency-free ESM — the single source of truth vendored into every generated project's qa/lib/ and consumed by the hosted recei

Readme

@create-cmp/receipts

Validate create-cmp evidence receipts. Plain ESM, zero dependencies, Node ≥ 18, fully offline.

The idea

When an AI coding agent (or a person) claims a change is verified, that claim is usually just text. A create-cmp project makes it a checkable artifact: its verify lane writes qa/evidence/latest.json — the verdict, every step's PASS/FAIL/SKIP with durations, and an inputs.hash: a sha256 over the content of every file that could have changed the verdict. The surface is fixed and public (VERIFIED_SURFACE): the app sources, the specs, the lane itself, and the Gradle build files.

Binding to content instead of a commit SHA buys two properties at once:

  • Robust where it's honest. Rebase, squash, or merge without touching a verified byte and the receipt still attests the tree — history moved, the content didn't.
  • Fragile where it's forged. Change one verified byte and the recomputed hash stops matching. Hand-edit the receipt's verdict and the same thing happens — the receipt is inside its own attested world.

This package is the predicate for that check, published standalone so anything — a CI job, a bot reviewing a PR, a script over a cloned repo — can validate a receipt with the same logic the project itself uses.

Install

npm install @create-cmp/receipts

Generated projects don't install it: they carry byte-identical vendored copies of these two modules in qa/lib/, so node qa/receipt-check.mjs runs air-gapped with no dependencies. This package is the source of truth those copies are synced from (parity is test-pinned in the create-cmp repo).

Use

import {
  readReceipt,
  computeInputsHash,
  evaluateReceipt,
  validateReceiptForTree,
} from "@create-cmp/receipts";

// The local predicate — what a generated project's Stop hook and CI run:
const receipt = readReceipt(projectRoot); // qa/evidence/latest.json, or null
const result = evaluateReceipt(receipt, () => computeInputsHash(projectRoot));
// { valid: true,  reason: "receipt is valid — PASS, attesting profile: local", ... }
// After editing a source file without re-running the lane:
// { valid: false, reason: "source changed since the receipt — re-run the lane (attesting profile: local)" }

// The hosted composite — the same predicate plus service-grade checks, for a
// receipt fetched from somewhere other than your own working tree:
const hosted = validateReceiptForTree({ root: projectRoot });
// hosted.status: "valid" | "invalid" | "missing"

What each layer checks:

  • evaluateReceipt — binding present, verdict not FAIL, recomputed hash matches, verdict is PASS. Its reason strings are the exact refusals a generated project prints. This is deliberately all a project checks against itself: a receipt you just generated is definitionally fresh.
  • validateReceiptForTree adds the hosted-only checks:
    • freshness — generatedAt within a window (default 30 days; checkFreshness);
    • execution plausibility — executed steps must report real durations summing above a floor (default 5 s; checkExecutionPlausibility). A "PASS" that took 0 ms is the tell for a replayed cache or a hand-written verdict.
    • A tree with no receipt returns status: "missing", distinct from "invalid" — not carrying the harness is not a failure.
  • listSkippedSteps — every SKIP with its verbatim reason. SKIPs are surfaced, never hidden and never punished: green-with-gaps must stay visible.
  • DEFAULT_POLICY ({ maxAgeMs, minExecutedMs }) is overridable per call: validateReceiptForTree({ root, policy: { maxAgeMs } }).

Full export list (also importable from the two submodules, @create-cmp/receipts/inputs-hash and @create-cmp/receipts/receipt-validate): computeInputsHash, VERIFIED_SURFACE, RECEIPT_REL_PATH, readReceipt, evaluateReceipt, DEFAULT_POLICY, checkFreshness, checkExecutionPlausibility, listSkippedSteps, validateReceiptForTree.

What this does NOT do

  • Generate receipts. Only the verify lane produces them — see @create-cmp/harness, vendored into every generated project as qa/.
  • Validate arbitrary JSON envelopes. VERIFIED_SURFACE is create-cmp's project shape (composeApp/, specs/, qa/, the root Gradle files). This validates create-cmp receipts specifically.
  • Touch the network or git. Every function takes a root already on disk and reads synchronously. Getting the right tree onto disk (say, a PR's head commit) is the caller's job.
  • Prove correctness. A valid receipt is tamper-evident evidence that the lane executed and passed on exactly these bytes — strong, checkable, and still not a formal proof that the software is right.

The receipt format is open and this validator is MIT so anyone can check any receipt offline. Why binding is by content hash rather than commit SHA: ADR-0005.