npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@lastshotlabs/slingshot

v3.1.7

Published

Config-driven TypeScript backend framework for typed APIs, entities, events, workflows, and production operations.

Readme

Slingshot

Build a typed backend by declaring packages, entities, routes, and infrastructure—not by assembling the same plumbing for every service.

Slingshot is a TypeScript backend framework built on Hono. One app.config.ts can produce:

  • typed routes and generated OpenAPI documentation;
  • entity CRUD, validation, operations, and migrations;
  • swappable Memory, SQLite, PostgreSQL, MongoDB, and Redis-backed infrastructure;
  • events, permissions, realtime, jobs, workflows, webhooks, and observability;
  • production startup checks, health/readiness endpoints, and operational tooling.

The root framework, core contracts, and entity system are stable and published on npm's latest channel. Package maturity is declared and checked per package—see Package maturity.

Documentation · Quick start · Examples · npm packages

Start in one minute

Slingshot supports Bun and Node.js 20 or newer. The examples use Bun.

mkdir my-api && cd my-api
bun init -y
bun add @lastshotlabs/slingshot hono zod

Create app.config.ts:

import { defineApp, definePackage, domain, route } from '@lastshotlabs/slingshot';

const api = definePackage({
  name: 'api',
  domains: [
    domain({
      name: 'health',
      basePath: '/health',
      routes: [
        route.get({
          path: '/',
          summary: 'Health check',
          handler: ({ respond }) => respond.json({ ok: true }),
        }),
      ],
    }),
  ],
});

export default defineApp({
  port: 3000,
  packages: [api],
});

Start it:

bunx slingshot start
curl http://localhost:3000/health
# {"ok":true}

The OpenAPI UI is available at http://localhost:3000/docs.

From here:

You can also run slingshot init my-api for the interactive application scaffold.

The authoring model

app.config.ts
└── defineApp(...)
    ├── runtime, databases, security, tenancy, observability
    └── definePackage(...)
        ├── entities      → CRUD, operations, validation, storage
        ├── routes        → typed domain endpoints
        ├── events        → governed, versioned messages
        └── contracts     → typed capabilities shared between packages

The framework validates and orders the graph at startup, builds a per-app context, mounts middleware and routes, connects infrastructure, and freezes registries before serving traffic. Package boundaries remain explicit:

  • Contracts and capabilities expose typed services without reaching into another package's internals.
  • Governed events carry versioned envelopes and support transactional outbox/inbox delivery.
  • Entities provide a backend-neutral authoring model with conformance-tested adapters.
  • Request and execution context carries actor, tenant, correlation, causation, and idempotency identity across supported boundaries.

Define data once

import { defineEntity, field } from '@lastshotlabs/slingshot';

export const Task = defineEntity('Task', {
  namespace: 'app',
  fields: {
    id: field.string({ primary: true, default: 'uuid' }),
    title: field.string(),
    done: field.boolean({ default: false }),
  },
});

Mounting this entity in a package generates create, list, read, update, and delete routes with request validation and OpenAPI schemas. Add domain operations when CRUD is not the right abstraction.

Entity guide · Operations · Backend support

Production capabilities

Slingshot includes production-oriented contracts beyond route generation:

  • Migration engine v2 — deterministic risk plans, explicit rename intent, approval digests, deployment locks, checksums, resumable execution, and verification.
  • Transactional events — PostgreSQL and SQLite outbox/inbox persistence, acknowledged BullMQ/Kafka delivery, bounded retries, retention, replay validation, and authenticated operator routes.
  • Tenant boundaries — explicit single- or multi-tenant modes, immutable execution snapshots, boundary conformance evidence, and optional PostgreSQL row-level security.
  • Operational safety — startup validation, liveness/readiness, metrics, tracing, audit logging, rate limiting, secrets providers, graceful shutdown, and packed-artifact checks.
  • Runtime choice — Bun, Node.js, and edge runtime packages with explicit capability boundaries.

These features have configuration and deployment requirements. Do not treat a memory adapter or an omitted production setting as a durable default. Follow the production-readiness guide before deploying.

Package maturity

Slingshot publishes 44 public packages. Their category, stability, required npm channel, and evidence gates come from the repository's versioned package-maturity.json; CI and the publish workflow reject drift.

Core

| Package | Purpose | | -------------------------------- | ---------------------------------------------------- | | @lastshotlabs/slingshot | App assembly, configuration, server lifecycle, CLI | | @lastshotlabs/slingshot-core | Neutral contracts, context, events, transactions | | @lastshotlabs/slingshot-entity | Entity authoring, adapters, CRUD, migration planning |

Production path

| Area | Packages | | ------------------------- | ---------------------------------------------------------------------------------------------------- | | Access and administration | slingshot-admin, slingshot-organizations, slingshot-permissions | | Data and delivery | slingshot-assets, slingshot-postgres, slingshot-search, slingshot-webhooks | | Messaging | slingshot-bullmq, slingshot-kafka, slingshot-mail, slingshot-notifications, slingshot-push | | Orchestration | slingshot-orchestration, -engine, -bullmq, -temporal | | Rendering and runtimes | slingshot-ssg, slingshot-ssr, slingshot-runtime-bun, -node, -edge |

Core and production-path packages are stable and use the latest dist-tag.

Experimental

Authentication and identity packages currently use the next channel:

bun add \
  @lastshotlabs/slingshot-auth@next \
  @lastshotlabs/slingshot-oauth@next

slingshot-auth, slingshot-m2m, slingshot-oauth, slingshot-oidc, and slingshot-scim emit a warning when their factory is used. Their APIs may change while the identity surface is hardened.

Deferred

Deferred packages remain published and independently pack-verified, but are not the default production recommendation. They include AI, billing, community/chat features, media and interaction helpers, the game engine, infrastructure helpers, slingshot-events, and slingshot-ssr-tanstack.

Read the generated maturity table before choosing a package. A package's version number alone is not its maturity claim.

CLI

The package installs the slingshot executable.

slingshot init my-api          # scaffold an application
slingshot dev                  # run the development server
slingshot start                # boot app.config.ts
slingshot generate             # regenerate entity artifacts

slingshot migrate generate     # generate migrations
slingshot migrate plan         # inspect deterministic risk and approval plan
slingshot migrate apply        # apply pending migrations
slingshot migrate verify       # verify history, checksums, and plan invariants
slingshot migrate status       # report applied and pending migrations

slingshot events outbox status # inspect event delivery health
slingshot events outbox list   # list bounded operational projections
slingshot events outbox retry  # audited break-glass replay
slingshot infra check          # audit deployment infrastructure
slingshot secrets check        # validate required secrets

Run slingshot <command> --help for command-specific flags.

Install only what you use

The root package provides the application framework and CLI. Feature packages and provider SDKs are installed separately so an app controls its runtime surface.

# Durable PostgreSQL support
bun add @lastshotlabs/slingshot-postgres pg

# Permissions and organizations
bun add @lastshotlabs/slingshot-permissions @lastshotlabs/slingshot-organizations

# Durable jobs and workflows
bun add @lastshotlabs/slingshot-orchestration \
  @lastshotlabs/slingshot-orchestration-bullmq bullmq

# Node runtime
bun add @lastshotlabs/slingshot-runtime-node

See the complete installation matrix for optional peers and provider packages.

Published package surface

@lastshotlabs/slingshot publishes:

  • the compiled framework and TypeScript declarations;
  • the slingshot CLI and its command manifest;
  • entry points for the default framework, mongo, redis, queue, and testing;
  • this README, the license, and package metadata.

Repository examples and documentation sources are intentionally not part of the npm tarball. Use the absolute links in this README when viewing it on npm.

Documentation and support

Contributing

Contributions should include focused tests, public API documentation, and any generated evidence affected by the change. Run the relevant package tests during development and bun run hardening:core before submitting broad framework changes.

License

MIT