npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@lssm/integration.osint-managed-runtime

v2.0.2

Published

Managed PostgreSQL and AuthOS adapters for OSINT services.

Readme

@lssm/integration.osint-managed-runtime

Managed infrastructure adapters shared by the OSINT API, worker, and MCP composition packages. It verifies OIDC grants against HTTPS JWKS, obtains a fresh scoped authority decision for every request or effect, and adapts the postgres driver to the FORCE-RLS OSINT store ports.

assertManagedOsintDatabaseRoleV0 verifies the exact PostgreSQL current_user and rejects superuser or BYPASSRLS connections. Runtime compositions use this readiness gate before dedicated rights workers can claim deletion work; application filtering never substitutes for database isolation.

Authority responses must bind the exact actor, requested scope, grants, purpose, request digest, decision evidence, and expiry. The runtime rejects widening, stale decisions, malformed bearer tokens, and credential-bearing endpoints.

createManagedOsintOperationHandlerV0 is the single managed REST/MCP handler: authorized reads use canonical scoped SQL and mutations enter the same durable queue with a canonical digest.

ManagedOsintOutboxStreamBrokerV0 turns the append-only Postgres outbox into scope-isolated SSE/WebSocket delivery. Each subscriber replays strictly after its numeric cursor under transaction-local FORCE-RLS context; malformed rows retain the cursor and surface only a redacted failure code. The API closes the poller before releasing its database pool.

Managed compositions can bind the same fail-closed runtime controls to every surface. Global, per-program, export, and research switches reject requests before SQL reads or durable queue writes. Environment-backed compositions use strict true/false values and default the global kill switch to active.

Fresh worker authority decisions retain their evidence references so downstream provider policy checks bind the exact server-side membership decision rather than treating a decision identifier as an implicit grant.

createManagedOsintTelemetryV0 emits structured lifecycle and bounded HTTP route-class logs without raw paths, entity IDs, tenants, query strings, or credentials. Metrics and traces use OpenTelemetry only when an explicit OTLP endpoint is configured; otherwise the adapter remains structured-log-only and does not activate the console exporter.

The managed self-improvement adapters reuse the same Postgres pool without transferring ownership, construct tenant/workspace-bound durable stores, and resolve a fresh, exact self-improvement authority decision for every HTTP request. Phase execution and review/evidence reads go to a credential-free HTTPS control plane with a bounded workload token and bounded response bodies. The control plane must return immutable decision/evidence receipts; malformed or denied responses fail closed. A readiness probe verifies all four durable tables and deliberately does not run migrations from a runtime role.