npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@jetci/ir

v0.1.4-alpha.3

Published

Downloads

1,242

Readme

@jetci/ir

Build and discovery layer for JETCI workflows.

@jetci/ir finds workflow files, performs a discovery build using @jetci/runtime-shim, validates registrations, and then emits the final workflow bundle. It provides the baseline server/build capabilities and a host descriptor model for providers.

Baseline Usage

import {build} from "@jetci/ir"

const registrations = await build({
  workflowDir: ".jetci",
  outfile: "./dist/workflows.js",
})

By default this supports the baseline JETCI SDK events and runners, including push and the built-in runsOn values.

Provider Wrappers

Providers should create a wrapper package, such as @jetci/github-ir, that calls build() with a host extension. The provider wrapper supplies the provider SDK package name, additional event schemas, and runner option schemas.

import {build, eventListenerSchema} from "@jetci/ir"
import {z} from "zod"

export function buildGitHubCi(options: {
  workflowDir: string
  outfile: string
}) {
  return build({
    ...options,
    host: {
      sdkPackage: "@jetci/github-sdk",
      allowedRegistrationPackages: ["@jetci/github-sdk"],
      events: {
        "github.pull_request": eventListenerSchema(z.object({
          branches: z.array(z.string()).min(1),
          actions: z.array(z.enum(["opened", "synchronize", "closed"])).optional(),
        })),
      },
      jobOptions: z.object({
        runsOn: z.enum(["ubuntu-latest", "ubuntu-24.04-arm", "self-hosted"]),
      }),
    },
  })
}

Provider SDKs are bundled during discovery so their event definitions can be redirected to the generic runtime shim. Provider SDKs are externalized in the final workflow bundle by default.

Secrets

eventListenerSchema(paramsSchema) validates the shared listener envelope, including secrets. Discovery returns each listener's declared secret names so the host can resolve them before invoking the final bundle's live handler.

Secrets are host/orchestrator metadata only. IR serializes the names, never the values.

SDK Import Security

During discovery, only root .ci.ts files in the configured workflow directory get the active host.sdkPackage public API. Trusted provider SDK internals may use @jetci/sdk/extend to create scoped events/jobs. Other bundled dependencies that import protected SDK packages are routed to isolated runtime-shim islands, so their registrations can exist but are not read by IR.

Each registration carries origin.sdkPackage. allowedRegistrationPackages defaults to [host.sdkPackage], and IR validates discovery output against that allow-list. The final generated bundle also filters live registrars to the same allowed origins.

Registrar Access

SDKs expose live registrations through a stable ./registrar subpath. Discovery and runtime deliberately use different registrars:

  • Discovery entrypoint imports @jetci/runtime-shim/registrar and exports serialized EVENT_REGISTRAR / JOB_REGISTRAR metadata for IR validation.
  • Final bundle entrypoint imports workflows normally, then re-exports live EVENT_REGISTRAR / JOB_REGISTRAR from ${host.sdkPackage}/registrar so the caller can invoke registered event handlers and jobs.

The final bundle externalizes the baseline SDK and host.sdkPackage by default; otherwise workflow imports and the generated registrar export can end up with separate registrar copies. The esbuild security plugin rejects workflow-authored registrar imports, so only the generated entrypoint can touch those paths.

A host that owns the final entrypoint/runtime boundary may set host.includeBaseSdkInBundle: true to bundle the baseline JETCI SDK instead of externalizing it. This only removes the baseline SDK from IR's default externals; provider SDKs remain externalized unless the host configures its bundle behavior separately.

Public Helpers

  • build(options): discover registrations and emit the final workflow bundle.
  • JETCI_HOST_DESCRIPTOR: baseline host descriptor.
  • mergeHostDescriptor(extension): merges provider host extensions with the baseline descriptor.
  • eventListenerSchema(paramsSchema): validates the shared event listener envelope with provider-specific params.
  • BASE_EVENT_LISTENER: base event registration shape.

Build

pnpm --dir packages/ir build