npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@jdylanmc/topo-archify

v0.1.0

Published

Pristine pinned Archify runtime for Topocode, packaged without install hooks.

Downloads

60

Readme

@jdylanmc/topo-archify

Packaging-first downstream distribution of Archify, not an upstream-endorsed SDK. Node 22+, no dependencies, install hooks, downloads, or model invocation. All 104 runtime files, fonts, templates, schemas and notices are pristine upstream v3.0.0. Package version 0.1.0 is independent of upstream version 3.0.0. release.json records the commit and official ZIP hash; runtime-integrity.json records every runtime byte.

import { cliPath, verifyRuntime } from '@jdylanmc/topo-archify';
import { execFileSync } from 'node:child_process';
verifyRuntime(); // throws on changed/missing/extra files or symbolic links
execFileSync(process.execPath, [cliPath, 'render', 'architecture', 'diagram.json', 'diagram.html']);

The narrow API supplies runtimeDirectory, cliPath, architectureRendererPath, outputCheckerPath and verifyRuntime(). These are filesystem entrypoints for native execution, not a broad renderer object API. Invoke the native CLI with --help for its contract. Keep v3 meta.output resolution inside an owned working directory. Rendering is local; do not infer upstream deliver/finalize certification for adapted outputs.

Build and regression

From the fork root, with Git, unzip, npm and Node 22+:

node integrations/topo-npm/pack.mjs dist
node --test integrations/topo-npm/package.test.mjs

The builder extracts the selected commit's official ZIP (already produced by upstream's clean Skill stager), not the current fork runtime. It verifies the committed ZIP hash and every extracted file against the original integration inventory. No runtime is rewritten. Untracked files and current upstream edits cannot enter the runtime. The test installs the tarball in a disposable consumer, checks the public entrypoints, all five native families, notices, inventory and tamper rejection.

The package test is not the complete upstream development suite. To test upstream itself, use a separate checkout of the selected revision, then run cd archify && npm ci && npm test and the browser/WebM gates declared there. Current fork main is not evidence for the selected older revision.

Updating and publishing

Topocode ships the context-loading topo-archify-maintenance skill. Load its context before changing this integration. Preview a deliberate pristine upstream candidate with node integrations/topo-npm/update-pin.mjs <full-commit>. After the required approval, repeat with --write to update release.json and upstream-integrity.json from that commit's official archive (never working-tree runtime bytes). Inspect the metadata diff and choose the downstream package version; run this package test and Topocode's full regression plus installed-package consumer test. Record upstream release notes, byte provenance and visual results. No generated runtime belongs in this Git repository.

Initial v3.0.1 adoption is not authorized by this package: it adds automatic update-check/reminder behavior to deliver/finalize, requiring deliberate local-first compatibility assessment. Do not mistake a patch number for unchanged behavior.

Passing packaging patches and behavior-compatible upstream patches are eligible for agent releases under the owner's policy. Minor/major upgrades, renderer patches and changed contracts or behavior require human approval. No scheduler or auto-merge runs here. Publication is GitHub Actions only: .github/workflows/publish-npm.yml builds/tests on GitHub-hosted Ubuntu and uploads a candidate. Separate jobs verify the same tarball's SHA-256 and publish to public npm. Normal publication uses OIDC (id-token: write), Node 24 and npm >=11.5.1. No local npm login or publish command is used.

After independent review and npm-side trust setup, run Publish renderer to npm from GitHub Actions on main, with the exact committed package version. The mode input defaults to verify; oidc explicitly publishes after gates. Configure npm's trusted publisher as GitHub user jdylanmc, repository topo-archify, workflow filename publish-npm.yml, Environment name blank, and explicitly allow direct npm publish (not only staged publication).

GitHub ownership does not establish npm ownership. First publication is a separate authorized owner action. npm's documented trust setup starts from an existing package's settings; this does not prove tokenless bootstrap of a nonexistent package. First-package bootstrap is a separate explicit path using the human's UI-managed GitHub secret NPM_BOOTSTRAP_TOKEN only in its publish step. It has no OIDC permission or provenance claim. The parent may push a protected, newly created tag npm-bootstrap/v0.1.0-<reviewed-full-40-character-commit> at that exact commit, even before the workflow reaches the default branch. Version/commit mismatches, tag updates and existing public packages are rejected before publication. No arbitrary branch/PR push publishes, and bootstrap does not skip package gates. Revoke the token in npm and delete the GitHub secret after the first versions. The bootstrap publishing step runs npm whoami first, reporting only the authenticated account name. This does not prove package-creation/write grants; only the authorized real publish exercises those rights. No token value is logged.

Fork CI retains upstream validation without impersonating upstream: Windows evidence fixtures derive the actual checkout's origin and revision, while the upstream notifier manifest is checked against canonical tt-a1i/archify release assets and tags. The selected npm runtime remains pristine 3.0.0. See the coordinated release walkthrough and npm's current trusted-publisher requirements. Retain upstream MIT, third-party, embedded font, brand attribution and trademark notices verbatim.