npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@dreamyoungs/ncp-external-access

v0.1.0

Published

Unofficial NCP External Access X.509 client for Node.js

Readme

@dreamyoungs/ncp-external-access

Node.js 24+용 비공식 NCP External Access 클라이언트. MIT, ESM, 런타임 외부 의존성 없음.

공개 배경·NAVER Cloud 미승인·공개 중단 가능성은 저장소 README를 확인하세요.

사용하던 공식 helper 배포본의 구형 런타임 관련 취약점 경고와 업데이트 대기 부담을 줄이고, 개발자가 소스·런타임을 직접 관리하기 위해 만들었습니다. 현재의 모든 공식 배포본에 동일한 문제가 있다는 뜻은 아닙니다.

NAVER Cloud의 승인·공인·후원을 받지 않았습니다. 향후 연락이나 요청 내용에 따라 공개 중단·비공개 전환·저장소 삭제가 있을 수 있습니다. 이는 이미 적법하게 MIT로 제공된 사본의 이용 허락을 철회한다는 의미는 아닙니다. 이 패키지 자체의 검증은 로컬 합성 테스트이며, 기반 앱의 실환경 성공을 분리 패키지의 실환경 검증으로 간주하지 않습니다.

설치

npm install @dreamyoungs/ncp-external-access

사용 예시

인증서·개인키는 호출자가 안전하게 읽거나 복호화해 전달합니다.

import {readFile} from 'node:fs/promises';
import {createSession} from '@dreamyoungs/ncp-external-access';

const privateKey = await readFile('/secure/private-key.pem');
try {
  const credential = await createSession({
    certificate: await readFile('/secure/certificate.pem', 'utf8'),
    privateKey,
    trustAnchorNrn: 'YOUR_TRUST_ANCHOR_NRN',
    profileNrn: 'YOUR_PROFILE_NRN',
    roleNrn: 'YOUR_ROLE_NRN'
  });
  // credential.accessKey/keySecret을 NCP API 서명에 사용하세요. 로그에 출력하지 마세요.
  // credential.expireTime 이전에 갱신하고 인증서 만료시간도 고려하세요.
} finally {
  privateKey.fill(0); // 다른 문자열·런타임 복사본의 완전 삭제를 보장하지 않습니다.
}

createSessionRequest(options, timestamp?)는 네트워크 없이 서명된 요청을 구성합니다. createSession(options)는 고정 Public endpoint에 한 번 요청합니다. 실패 시 ExternalAccessError.code는 invalid_input, request_failed, invalid_response 중 하나이며 원문 provider 오류를 포함하지 않습니다.

단일 PEM leaf 인증서, 암호화되지 않은 PEM RSA/EC 개인키, 600초 요청만 지원합니다. 캐시·갱신·재시도·CLI·KMS는 없습니다. 브라우저에서 사용하지 마세요. 인증서·키·서명 요청·반환 credential을 기록하지 마세요.

npm ci
npm test
npm pack --dry-run

테스트는 OpenSSL로 합성 인증서를 생성하며 NCP를 호출하지 않습니다.