npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@globiguard/contracts

v1.0.1

Published

Shared public contracts for GlobiGuard distribution-layer packages.

Readme

@globiguard/contracts

This package is the shared contract foundation for the GlobiGuard open distribution layer.

Current scope

This bootstrap slice includes the early contract surfaces that are safe to lock before the full canonical public spec is generated:

  • action authorization, approval state, evidence reference, destination system, and data-class contracts
  • decision enums
  • environment identity
  • credential shapes
  • service target shape, including optional action sidecar/gateway targets
  • install registration and heartbeat shapes
  • audit event and evidence export shapes
  • queue entry, lookup, and approval decision shapes
  • metadata-safe evidence package summaries with checksums, source refs, redaction mode, and artifact delivery hints
  • versioned incident replay timelines with explicit missing/redacted/unverified segments
  • trust webhook envelopes, signature header names, delivery IDs, timestamps, and replay-window verification inputs
  • authority-boundary markers that distinguish browser-readable display contracts from server-secret authority contracts
  • workflow management and run shapes
  • realtime subscription auth, channel, and event-envelope shapes
  • policy management shapes
  • org and API-key management shapes

It does not claim to be the full public API spec for GlobiGuard.

The canonical machine-readable spec remains owned by the main globiguard repository. Later slices should generate or validate richer public contracts from that source of truth.

Authority boundaries

Browser-safe contracts use GLOBIGUARD_BROWSER_READ_BOUNDARY; they are metadata surfaces for status, summaries, evidence links, and replay timelines. They never include server secrets, approval/resume authority, bypass controls, or raw customer payloads.

Server-authority contracts use GLOBIGUARD_SERVER_AUTHORITY_BOUNDARY; SDKs and integrations must keep those behind server-only package entrypoints and runtime guards. Trust webhook verification signs the canonical body plus delivery ID, event type, and timestamp, then receivers enforce a replay window and duplicate delivery detection.