npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@intentface/latch-net

v0.11.0

Published

Network-safety primitives for Latch — SSRF guards (private-IP blocklist + DNS-rebinding backstop) and a DNS-pinned egress fetch, shared by every host that opens an outbound connection.

Readme

@intentface/latch-net

Network-safety primitives for Latch — SSRF guards and a DNS-pinned egress fetch, shared by every host that opens an outbound connection on a model's behalf.

The root export has zero third-party dependencies (Node built-ins only), so any package can depend on it without pulling weight in. The pinned fetch, which needs undici, sits behind the /pinned subpath.

What it does

  • assertPublicUrl — the front-line check. Parses the URL and rejects any host that is, or resolves to, a private, loopback, link-local or otherwise internal address. Returns the parsed URL so the caller can keep using it.
  • isBlockedHost / isBlockedResolved / isPrivateV4 — the predicates behind it. The string-level one is deliberately conservative, covering .localhost and .local names, IPv6 literals in any spelling, and the integer and hex encodings of an IPv4 address. The resolving one is the rebinding backstop.
  • isHostAllowed — positive allowlist matching (an exact host, or .suffix for subdomains), used to bound which hosts a tenant may reach at all. It complements the blocklist rather than replacing it.
  • createPinnedFetch / pinnedFetch (@intentface/latch-net/pinned) — a fetch that vets addresses inside the lookup the connection itself uses.

Why the pinned fetch exists

Checking a hostname and then handing it to fetch leaves a gap: fetch performs its own second DNS lookup, so a name that resolves public during the check and private when the socket opens defeats the guard. That is DNS rebinding, and it is a time-of-check/time-of-use bug, not a weak blocklist.

createPinnedFetch closes the gap by validating in the undici connector's lookup, so there is no distance between validating and connecting. TLS is untouched: SNI and certificate validation stay against the original hostname, and redirect hops dispatch through the same agent, so every hop is connect-vetted too.

import { assertPublicUrl } from "@intentface/latch-net";
import { createPinnedFetch } from "@intentface/latch-net/pinned";

await assertPublicUrl(url); // throws on private / non-public targets
const fetch = createPinnedFetch();
const response = await fetch(url, { redirect: "follow" });

Where it fits

An optional peer of @intentface/latch-core, required by its web_fetch harness tool. latch-mcp uses the allowlist to bound MCP server hosts, and any host tool that fetches a user-supplied URL should route through it.