npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@josephyulei/summon-foundation

v0.1.18

Published

Prepare a verified Foundation release for an explicitly confirmed Codex installation

Readme

summon foundation

当前用户共用一份程序与一份可选对话功能。安装仅选择软件位置,不选择业务项目。各项目随后单独接入,资料各自保管;旧安装不自动迁移或覆盖。

保留真实下载状态与独立确认。基础环境不能安全启动页面时,由 Codex 对话先披露并取得独立批准,再准备专用环境;页面启动后全程同页。具体方法见仓库 docs/install-with-codex.md,不能先运行 npx 来准备缺失的 Node。不修改共享 PATH;获取器专用环境及其回执按缓存保留,程序另用随包运行时。发行发现仅需 curl,获取还需 tar;已验证载荷的确认、恢复和卸载不依赖下载工具。

0.1.12 单页试用入口与 Foundation 0.2.17 的运行引擎共同支持当前用户共用安装及清晰的完成、取消和部分完成反馈。同一页面内保留目录选择、程序和 Skill 独立确认。真实安装、新任务发现和主动告知仍需独立验收。

首次 URL 持续显示本次流程;确认仅转交本次受控子进程的当前计划,不新开manager页。--acquire仍只读获取;--resume仅在用户明确要求后恢复未完成Skill,不重放程序安装。

Foundation 的薄获取入口,不包含完整运行包,没有 npm 安装生命周期脚本。 只有明确执行才查询/获取;安装和 Skill 注册继续各自需要用户确认。

可用性以 npm registry 的实际版本和公共 GitHub Release 为准;本目录或说明存在不是发布回执。只使用本项目已核验的包名,缺包时不换同名来源。

确认 registry 中存在本版本及对应不可变 Release 后,在具备安装权限的新 Codex 对话粘贴:

npx --yes --package @josephyulei/[email protected] summon foundation

旧版退出推荐入口;支持边界见现行支持策略。旧不可变版本不修改,不自动迁移或清除旧安装。

Codex 需要打开返回的内置浏览器网址,并分段等待同次操作结果。npm 不能自行操控或唤醒 Codex,对话主动告知不是程序退出码保证;新对话接续仍待真人验收。系统浏览器只是明确告知后的备用,不自动打开。

联网前建立操作记录,网络失败保留脱敏类别和退出码;--status只读恢复同次结果,不重试或重放。程序健康核验后结果留在本页,工作台由用户另行打开。工具yield不是任务完成,Codex须继续分段观察;HTML不能唤醒已结束任务。

显式 --inspect 只查询发行。默认命令先在页面选择目录与Skill意向,再下载核验;最终精确计划仍需本人确认。--prepare传入的目录只是意向;--acquire只准备更新输入。更新/卸载仅使用支持单页的已安装稳定入口,不回退旧页面。

需要 macOS arm64、Node.js 22.9+ 与 npm。无 TTY 不会卡在终端提问;目录选择在页面进行,关闭页面不算确认或取消。 固定版本准备阶段校验 GitHub 仓库身份、不可变 Release、签名证明、时间戳、源码提交和资产字节,随后使用随包运行时进入现有 Foundation 确认页面。 不关闭 Gatekeeper、不清除隔离属性,不冒充 Apple 签名或公证。遇到权限问题安全停止。

尚无 Foundation / Skill 的缓存说明:公开清理指南。当前 README 不是安装完成回执。

可选 GitHub 认证

以下选项需要支持可选认证的获取器版本;npm 0.1.15 不支持。支持该选项的入口可使用:

summon foundation --inspect --github-auth gh
summon foundation --github-auth gh
summon foundation --acquire --version 0.2.33 --github-auth gh
summon foundation --update --root /absolute/installed-folder --github-auth gh
summon foundation --inspect --github-auth anonymous

默认 --github-auth auto 优先读取 GH_TOKEN,其次 GITHUB_TOKEN;均无值则匿名,不读取 gh 登录。gh 模式只在明确选择时读取 gh auth token --hostname github.com,忽略这两个环境变量;anonymous 强制匿名。不要把 Token 写入命令参数、聊天或项目文件。gh 缺失或未登录时自行安装 CLI / 执行 gh auth login --hostname github.com,入口不会代为登录。401 提示修复所选凭证,不静默回退;普通403提示核实权限,主/次级限流按响应头等待。自动重试最多两次、累计等待最多五秒,超过预算则提示服务要求的等待时间,不提前重试。

认证头仅用于 HTTPS api.github.com 的本产品仓库 API;每跳检查,跨域后不再携带认证。下载资产、信任数据、安装/更新及 Skill 子进程不接收 Token。Token 不改变发行证明和完整性要求。