npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@getbourdon/federation

v0.1.3

Published

Bourdon L6 federation — the cross-machine trust boundary (BUSL-1.1). In-memory L6Store (visibility-filtered query primitives, async-mutex commitL5, base64url cursors, Promise.allSettled peer fan-out), the single-operator trust registry (bdn_ tokens, sha25

Downloads

755

Readme

@getbourdon/federation

Bourdon L6 — the cross-machine trust boundary (BUSL-1.1). The TypeScript mirror of the Python core/l6_store.py + l6_remote.py + federation_{registry,audit,staging}.py. Python (pip install bourdon) is the oracle; this package asserts against the @getbourdon/conformance fed_seed_library / tier_matrix / on_disk fixtures.

Security-critical. Every invariant below is enforced in code, not by trust — a single missed clamp leaks PRIVATE memory across machines.

What's inside

  • L6Store — in-memory aggregator over <library>/agents/*.l5.yaml. Visibility-filtered query primitives (listAgents, findEntity, listRecentWork, getCrossAgentSummary, getAgentManifest, buildRecognitionManifest), base64url pagination cursors with a stable (date desc, agent desc) total order, exportAgents with the egress visibility clamp + credential redaction, and the *Federated peer fan-outs (Promise.allSettled — a dead peer never fails the local answer; peer rows tagged peer:<name>:<agent>).
  • commitL5 runs behind an async mutex (the Node analogue of Python's threading.RLock): Node interleaves at every await, so a read-modify-write-RELOAD without serialization is the P1-3 lost-update race.
  • FederationRegistry — single-operator trust registry at ~/.bourdon/federation.yaml. bdn_ + 24-byte-hex tokens, SHA-256 hash-only at rest, crypto.timingSafeEqual against ALL rows (constant-time, no early exit), trust tiers, an empty Bearer authenticates nowhere, (mtimeNs, size) hot-reload staleness key, and fail-closed parse (a corrupt registry authenticates no one).
  • AgentIdentity + AsyncLocalStorage caller propagation (runWithCaller / getCaller) — Python's ContextVar. Fail-closed: an unbound caller is OPERATOR (stdio); an unknown HTTP caller is quarantined.
  • FederationAudit — append-only JSONL, never token material, write-failure non-fatal, microsecond-padded timestamps, Python-json.dumps default-separator byte parity.
  • Quarantined staging — quarantined writes land under <library>/staging/<caller>/, invisible to every read tool until promoted.
  • enforceToolAccess + clampPeerAccess — the tier-matrix decision logic and the ingress/egress PRIVATE clamps.
  • RemoteL6Client — depth-1 peer client: federation_hop: 1 on every fan-out (#139), access_level capped to ("public","team"), never include_private: true, per-call timeout 5.0s / recognition 0.2s, and a never-raise wrapper so one dead peer never breaks the merge.

License

BUSL-1.1 — see LICENSE and LICENSE_FAQ.md.