npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@ibgib/space-gib

v0.0.17

Published

ibgib storage and provider service — SaaS at ibgib.space

Readme

Space-Gib

Space-Gib is the multitenant synchronization peer and hosting environment for the IbGib ecosystem. It features a Node.js Express/serve-gib backend and a dynamic SPA client frontend.

🔒 Intrinsic App Capabilities: Personal Notes & Password Manager

Beyond its role as a provider/sync host for identity networks, Space-Gib is built to serve as a high-security, local-first utility for the user:

  • Personal Organizer: A secure notebook for comments, text, and personal memos.
  • Password Manager: A zero-knowledge vault for credentials, site logins, and secrets.
  • Email Infrastructure: Service-agnostic email sender/receiver architecture supporting AWS SES REST API and local mock drivers (/api/email/inbound, /api/email/send).
  • Zero-Knowledge Architecture: All personal notes and credential vaults are encrypted client-side using strong AES-GCM keys derived deterministically from the user's active Keystone identity secrets. The hosting server and sync peers only see encrypted blobs and can never read the user's notes or credentials.

Local Development Workflow

The local development environment uses a dual-target esbuild watch process and Docker for hosting the Node.js server behind a Traefik reverse proxy.

To run the full development loop, open three separate terminal windows:

Terminal 1: Watch (Client & Server)

Run the watch process to continuously type-check and bundle both client and server source files.

npm run watch:space-gib

Terminal 2: Run (Docker)

Start the Docker environment (Traefik + Node container).

npm run docker:space-gib

Once started, the application is available at https://space-gib.localhost

Terminal 3: Restart (As needed)

Because the Node.js process runs inside Docker, hot-reloading the server code requires restarting the container.

  • Client changes: Auto-reload when you refresh the browser.
  • Server changes: Run this command to load your newly compiled server code.
npm run restart:space-gib

Directory Structure

  • src/client/: The browser SPA frontend. See Client README.
  • src/server/: The Node.js server. See Server README.
  • src/common/: Shared logic, types, and constants used by both client and server.

    [!IMPORTANT] STRICT RULE: src/common MUST NEVER import from src/client or src/server. This ensures the shared layer remains portable and prevents circular dependencies.

  • dist/: The output directory where esbuild writes the bundled client (dist/client/) and server (dist/server/) code.

Debugging the Server

You can attach the VS Code debugger directly to the Node.js process running inside Docker.

  1. The server runs with the --inspect=0.0.0.0:9229 flag.
  2. docker-compose.yml maps port 9229 to your host machine.
  3. Use the VS Code launch configuration Docker: Attach to Space-Gib to attach breakpoints.

🛡️ Long-Term Decentralized Security & Threat Modeling

As space-gib transitions from the V1 single-server model to a fully decentralized, peer-to-peer architecture, the following security threats (inherently mitigated by the centralized nature of V1) must be addressed:

1. The Revocation Sync Gap (Stale Parent State)

  • The Threat: In a multi-peer network, if a user revokes a delegate keystone on Peer A (evolving $K_{\text{domain}}$ to remove the delegate), Peer B may not immediately sync the revocation frame. If an attacker presents the compromised delegate to Peer B before it syncs the parent's latest state, Peer B will accept it.
  • Decentralized Mitigation: Peers must require cryptographic proof of freshness (epochs, sequence checks) or query a quorum of sync space hubs to verify $K_{\text{domain}}$'s latest tip before executing high-value operations.

2. Cross-Origin Identity Federation (Same-Origin Policy Limitations)

  • The Threat: Browser Same-Origin Policy (SOP) isolates IndexedDB and local storage by domain. If a user stores their primary identity keys on space-gib.localhost (Site A), script running on a different client app origin other-ibgib-app.localhost (Site B) cannot access Site A's IndexedDB to sign claims.
  • Relationship to Sync Remotes: While ibgib's sync protocol allows Site B to act as a Git-like remote that we push to and pull from via network requests, the SOP limitation applies to the browser frontend client running on Site B. To boot a local repository on Site B that can interact with the remote, Site B needs its own local delegate keys.
  • Decentralized Mitigation: We must establish a secure cross-origin handshake (e.g., standardizing a redirect/popup or postMessage flow) where Site A authenticates the user and securely transfers a restricted, site-scoped delegate keystone to Site B's local IndexedDB. Once Site B has this delegate, it can sync natively with other peers.

Future Enhancements & Todo

  • Notification Broadcast System: Implement a secure notification broadcast system to alert the user immediately via UI notifications when any challenge pool modification or administrative evolution occurs on their identity keystone.