npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@gpzhang2001/sharpkit-reporting

v0.2.2

Published

Vulnerability/dependency reporting tools + sharpkit_runs artifacts (run.json, vuln markdown, csv/json, SARIF 2.1.0)

Readme

@gpzhang2001/sharpkit-reporting

漏洞/依赖报告五工具 + sharpkit_runs/ 产物体系(run.json、SARIF 2.1.0、逐漏洞 Markdown)。

工具

  • create_vulnerability_report:23 参数全量移植;severity/CVSS 由 8 指标 cvss_breakdown 计算(v3.1 公式与 Python cvss 包对拍:6.42×ISC / Scope C 7.52 公式 + 1.08 总分乘数、Roundup1);code_locations 规范化 + fix_verification/上下文依赖校验;broad CWE 拒绝
  • create_dependency_report:CVE×package 一报告;advisory/contextual 双评分(contextual 缺一即弃,strix 语义);manifest_path/reachability 证据运行时强制
  • update_vulnerability_report:白名单 + 依赖字段丢弃(confidence→rationale 等 4 对)+ update_history(含 previous_* 捕获)+ 跨类字段拒绝 + 依赖重评级需 contextual reasoning
  • list_reports:过滤器 AND 组合、severity rank 排序、compact 摘要(280 字符预览)/全量两种
  • get_report:vuln-NNNN 精确查找

产物体系

每次增改触发全量落盘(state.py _save_artifacts 顺序):vulnerabilities/*.md(增量渲染)→ vulnerabilities.csv(\r\n、大写 severity、公式注入防护、rank+时间排序)→ vulnerabilities.json → findings.sarif(空结果也写,覆盖陈旧文件)→ run.json(最后写)。全部原子写(同目录临时文件 + rename,无 fsync,strix 语义)。

SARIF 2.1.0:CWE→CVE→id→slug 规则 ID、GitHub security-severity、STRIDE 标签(CWE 映射全量移植)、物理+SECURITY.md 合成位置、PR 建议 fixes、确定性 sha256 partialFingerprints、strix 命名空间属性(PoC 脚本体永不出境,只带 description + script_available 标志)。

去重

依赖发现走确定性快路径(CVE×package×ecosystem、不同 manifest=两个发现、legacy 词边界匹配);动态发现的 LLM judge 为 Config 注入回调,judge 失败/缺席一律判非重复。

Golden 测试

tests/golden/ 存放原版 strix 代码(uv run)对同一输入生成的产物;golden.test.ts 断言 TS 输出逐字节一致——md×2/csv/json/sarif/run.json 共 6 项。过程捕获并修正了两处偏差:code location 段的 2 空格缩进 + Suggested Fix 空行、元数据行序(dependency 块在 CVE/CWE 之前、Advisory CVSS ≠ CVSS 才显示)。

测试

tests/reporting.test.ts:CVSS 数学(与 Python cvss 包 5 向量对拍:9.8/6.5/4.4/0.0/10.0)、state(字段序/依赖丢弃/history/hydrate)、normalizers、dedupe 快路径。

备注