npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@network-harness/artifacts-git

v0.2.0

Published

Part of the network harness: @network-harness/artifacts-git.

Downloads

293

Readme

@network-harness/artifacts-git

The artifact store two peers negotiate over, claiming ctx.artifacts: one history per resource, each revision attributed to the node that authored it, and agreement recorded as a mark on a revision.

git is used for what it is good at -- content-addressed history, a diff, and a bundle that moves a revision between two repositories that share no remote -- and trusted for nothing else:

  • Authorship is recorded here, not read from git. A commit is authored as this node; an import is authored as the peer on the session the caller named, read from the adapter's session record. The author field inside a peer's bundle is not evidence, so the store keeps its own record beside the repository, where a commit cannot rewrite it and a bundle cannot reach it.
  • The session is read through the caller's own context, so the store holds no ambient access to sessions -- only to the ones the protocol calling it already owns. A protocol cannot attribute a revision to a peer it is not talking to.
  • Verify before applying. A bundle's size and hash are checked, then git's own bundle verify, and only then may it near a ref. It must also continue the history it claims to: the head it names has to be the current head, and the revision has to descend from it.
  • A workspace is a copy, not a checkout. A run writes into a plain directory, so nothing it does can reach the repository's objects, and it is bounded by file size, file count, total size, and count per protocol, with a TTL: it is scratch space, not storage.

Resources are scoped to the calling protocol, which is half of the path they live under, so one protocol cannot reach another's by name.

The conformance suite both this and @network-harness/artifacts-memory must satisfy lives in core/network/tests/artifactSuite.ts.