npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@fabricorg/assembly

v0.4.3

Published

Deterministic application assembly: versioned manifests, resolved lockfiles, and a single build gate for capabilities, component packs, and adoption bindings.

Readme

@fabricorg/assembly

Deterministic application assembly for Fabric verticals. It takes a versioned assembly manifest — the capabilities, component packs, adoption bindings, and usage contracts a vertical assembles — resolves dependency ranges deterministically, validates contracts, packs, and bindings as one build gate, and produces a locked, digest-bearing lockfile.

What it does

  • Assembly manifest (AssemblyManifest): a versioned declaration of what a vertical assembles. Capabilities and component packs carry semver ranges; bindings and generated usage-contract documents are supplied inline for validation.
  • Lockfile (AssemblyLockfile): the resolved, deterministic output. Every capability and pack version is locked with its range and artifact digest, generated contracts are tied to the resolved capability manifest, every binding carries a content digest, and the whole resolved document carries a canonical SHA-256 digest.
  • Resolution (resolveAssembly): resolves semver ranges against available versions, rejects unresolved or duplicate capability identities, validates usage contracts, component packs, and adoption bindings, and returns every finding rather than throwing on the first.
  • Build gate (assertAssemblyResolved): throws with every finding listed, for use as a CI step.
  • Runtime verification (assertAssemblyLockfile): validates a stored or transported lockfile and rejects any resolved content that no longer matches its assemblyDigest.
  • Runtime compatibility (assertAssemblyRuntimeCompatible): fails startup unless loaded capability versions and manifest digests exactly match the approved lockfile, including rejection of missing or extra modules.

Semver ranges

The resolver supports the subset of npm range syntax a deterministic lockfile needs: ^ (caret), ~ (tilde), >=, >, <=, <, = (exact), bare exact versions, * (wildcard), and compound ranges (>=1.0.0 <2.0.0). Prerelease versions follow npm semantics: a prerelease only satisfies a range when a comparator in the range declares a prerelease at the same [major, minor, patch] tuple.

Usage

import { assertAssemblyResolved } from "@fabricorg/assembly";

const lockfile = assertAssemblyResolved({
  manifest: {
    formatVersion: 2,
    application: "lending",
    capabilities: [{ namespace: "recovery", range: "^1.0.0" }],
    componentPacks: [{ pack: "lender-components", namespace: "lender", range: "^1.0.0" }],
    bindings: [{ capability: "recovery", binding }],
    contracts: [{ namespace: "recovery", document: usageContractDocument }],
  },
  capabilities: [{ namespace: "recovery", version: "1.1.0", manifestDigest: "…" }],
  componentPacks: [{
    pack: "lender-components",
    namespace: "lender",
    version: "1.1.0",
    artifactDigest: "…",
  }],
  packManifests: [pack],
  coreComponents: ["Card", "List", "DetailLayout"],
});

It does not load live modules, execute handlers, or run inside @fabricorg/platform. The assembly package depends on @fabricorg/adoption-bindings and @fabricorg/gen-capability for contract and binding validation.

The adapter plane

An assembly manifest may declare adapters, each the output of certifyAdapter. Declaring the field, even empty, engages the plane: every port a contract requires must be satisfied by a declared, certified adapter, judged by validatePortRequirements with certification required, and a certification against an older port contract is stale when portDefinitions are supplied. The lockfile records every declared adapter, certified or not, and the assembly digest covers them. assertAssemblyRuntimeCompatible(lockfile, capabilities, registeredAdapters) then checks that what a runtime registered behind each port is what the assembly approved. An assembly that does not declare adapters resolves exactly as before.