npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@liveshops/host-sdk

v0.3.6

Published

LiveShop Host handshake, HTTP client, iframe/remote contribution protocol, and Gateway Host runtime entries.

Downloads

186

Readme

@liveshops/host-sdk 0.3.6

本次是公开 0.3.5 的最小 SDK 热修,新增 navigateHost、setHostPagePresentation 和 HostRouteContext。0.4.x 现代开发线独立保留,没有覆盖或回退其源码。

import { connectToHost, navigateHost, setHostPagePresentation, type HostRouteContext } from '@liveshops/host-sdk'
const context = await connectToHost()
const route: HostRouteContext | undefined = context.route
setHostPagePresentation({ summary: 'module' })
navigateHost('/live/123/console')

导航只允许不超过 2048 字符、不含空格/控制符/反斜线/query/hash 的站内绝对路径;拒绝外部 URL 和 //。呈现只接受 host / module,选择当前页说明区域所有者,不创建跨页遮罩。两个命令都必须在 iframe 已完成 parent/source/origin/protocol 握手后调用;等待握手、超时或独立顶层运行时拒绝。超时接收器被移除,迟到握手不能激活已失败连接。

Host 接收端需实现现行 LIVESHOP_HOST_NAVIGATE 与 LIVESHOP_HOST_PAGE_PRESENTATION 协议,并继续执行自己的 source/origin/protocol、目录与权限校验。SDK 不代替 Host 身份与路由裁决。

既有 /runtime、/runtime/console、/host.css 从公开 @liveshops/[email protected] 固定 SHA512 输入中逐字节保留;此次不升级 Host Runtime,也不引入未发布的 design-tokens 1.6.0。bundle-host-runtime.mjs 校验官方 tarball,缓存后只复制其 runtime 子目录;校验失败则停止,不采用替代来源。

源码基线 b7d371a 的 SDK 目录与明确发布 0.3.5 的干净作者 eaf7d97 相同。npm 0.3.5 的 gitHead 指向更早 af9b315,因此发布证据同时核对实际公开 tarball,而不只信版本元数据。

隔离容器验收:npm test、npm run prepublishOnly、npm pack;源码与实际安装的 tarball 都执行导航安全测试,全部 runtime 文件比对 SHA256。Live 仍使用公开 design-tokens 1.5.3;正式 npm 发布成功后才固定依赖 0.3.6。