npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@epoch-agent/vendor-ripgrep-win32-x64

v14.2.1

Published

ripgrep 官方二进制(Windows x64,arm64 走系统自带的 x64 模拟)—— epoch-agent 的 file_search 用它,随平台按需安装

Readme

@epoch-agent/vendor-ripgrep-win32-x64

ripgrep 14.1.1 的官方二进制,Windows x64 那一份(bin/rg.exe,MSVC 构建)。 没有任何代码。

  • ✅ 做:把 bin/rg.exe 交付到用户机器上
  • ❌ 不做:解析、探测、降级 —— 那些在 infra 的 resolveRipgrep(),它的文件头写了三级解析为什么长这样
  • 依赖:无(叶子包,连 protocol 都不依赖)

装法是 cli 的 optionalDependencies + 本包的 os / cpu 字段:npm / pnpm 只装与当前平台匹配的那一个,另外两个静默跳过。装不上不影响 epoch 可用 —— resolveRipgrep() 会退回「没有 ripgrep」的老行为。

取 MSVC 构建而不是 GNU 构建:上游把 MSVC 那份当 Windows 的首选产物, 而 GNU 那份要用户机器上有 mingw 运行时。

二进制是入库的,不是装时下的

bin/rg.exe 直接在 git 里,没有 postinstall 下载步骤(那正是 @vscode/ripgrep 的做法,它在内网和 --ignore-scripts 下会挂)。

代价是这几个字节得有据可查,那份账在 scripts/fetch-ripgrep.mjs:版本号、下载地址、 SHA-256 全在里面钉死,升级流程写在文件头。别手工替换 bin/ 里的文件。

bin 字段:那是二进制带不带执行位的唯一开关

package.json 里有一条

"bin": { "epoch-rg": "bin/rg.exe" }

它不是为了给谁提供一个命令,是为了让打包器别把这个文件的权限位抹掉。 2026-09-01 逐条实测出来的账:

| pack 方式 | tarball 里 bin/rg.exe 的 mode | | ---------------------------- | ------------------------------- | | pnpm pack,没有 bin 字段 | 644 ← 装到用户手里跑不动 | | npm pack | 755 | | pnpm pack,有 bin 指着它 | 755 |

也就是说 pnpm 归一的是非 bin 文件。发布走的是 changeset publish → pnpm publish, 所以少了这个字段,用户装下来的就是一个没有执行位的 4 MB 文件。

⚠️ 名字必须带前缀,不许叫 rg

| 场景 | 用户 PATH({prefix}/bin) | 宿主工程根 node_modules/.bin | | ------------------------------- | --------------------------- | --------------------------------------------- | | npm i -g,bin 叫 rg | 只有 epoch,没有 rg | — | | 本地 npm i,bin 叫 rg | — | 有 rg ← 会盖掉宿主 npm 脚本里的 ripgrep | | 本地 npm i,bin 叫 epoch-rg | — | 只有 epoch-rg ✅ |

npm 只把顶层包的 bin 链进用户 PATH,所以全局装 epoch 不会污染 PATH; 但本地安装会把这个包提升到宿主工程根,那儿的 .bin/rg 是真会盖人的。 带前缀的名字拿到同样的 chmod,而谁都盖不到。

守这两条的是 __tests__/ripgrep-ownership.test.ts 第 4 组(进 CI)和 verify-pack.mjs(发版前的人工闸门)。

ripgrepVersion:诊断印的版本号读的是它,不是 version

包自己的 version 要为打包问题升(加上面那个 bin 字段就是一次), 而那种升级一个字节的二进制都没换。两者曾经被当成一回事,结果是 version 已经是 14.2.0 而二进制还是 14.1.1,屏幕上那句 「用内置的 rg 14.2.0」从落地起就是假的。

所以版本号分两格:version 是这个 npm 包的,ripgrepVersion 是二进制的, 后者跟着 scripts/fetch-ripgrep.mjs 的 RIPGREP_VERSION 走(那份是二进制怎么来的唯一真源)。

许可证

包本身(package.json / 这份 README)是 Apache-2.0,跟全仓一致。

bin/rg.exe 是第三方作品:ripgrep 由 Andrew Gallant 编写,采用 MIT OR Unlicense 双许可。两份许可文本随包分发(LICENSE-MIT / UNLICENSE), 署名在根 NOTICE 里。

本包里那份 LICENSE(我们的 Apache-2.0 全文)是显式拷进来的,别当成冗余 删掉。其余包不用管这件事,因为 pnpm 打包时会自动把仓库根的 LICENSE 拷进 tarball —— 但它只在包目录里没有许可文件时才拷,而这里有 ripgrep 的那两份, 正好命中「已经有了」。不拷的后果是:包发出去 license 字段写着 Apache-2.0, 却找不到对应的许可文本。

本包没有 SPDX-License-Identifier 头,是刻意的:那个头在本仓库的含义是 「这个源文件抄自竞品」(CLAUDE.md 铁律 12),而这里是「我们分发了一个第三方 二进制」。所以 ripgrep 在 NOTICE 里出现却没有对应的带头源文件 —— 全仓第一处 两者不一一对应的地方,verify-pack.mjs 的注释里点了名。