npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@openchildsafety/bundle

v0.1.0

Published

OCSS v4 §8.5 machine-readable companion bundle: OpenAPI 3.1 + JSON Schemas + CDDL + frozen golden vectors + suite-entry schemas + per-profile MUST checklists. FROZEN — vectors are immutable; a Go/TS split is a spec defect via the errata rail, never a vect

Readme

@openchildsafety/bundle — OCSS v4 §8.5 machine-readable companion bundle

The §8.5 deliverable of OCSS v4: a machine-readable companion to the Open Child Safety Specification. This is the independence boundary for @openchildsafety/ocss — the TypeScript reference implementation is built ONLY from the spec + this frozen bundle, NEVER importing the Go reference.

FROZEN. Once published, the golden vectors are immutable. A Go/TS byte split is a spec defect filed on the errata rail (POST /api/v1/spec/errata, census row 14), never a vector edit.

What's in it

  • openapi.yaml — OpenAPI 3.1 for every census operation (24 rows) + the §11.10 determination companion (x-ocss-companion) + HEAD twins + the two aliases + the relocated push + the RFC 9421 security scheme.
  • schemas/ — closed JSON Schemas (draft 2020-12) for the §4.2 envelope (+ envelope.cddl), the 5 typed payloads + the directive/audit-attestation honest-absence marker, the Receipt + its 10 bodies, every signed-read document grammar, and the 10 closed vocab enums.
  • vectors/ — the 9 frozen golden-vector files: the 4 Go testdata files copied byte-for-byte (canon-vectors.json, envelope-vectors.json, rail-vectors.json, familyhash-vectors.json) + the 3 net-new files (digest-vectors.json, census-request-vectors.json, trust-list-vectors.json) + the jwe-interop/ triple.
  • suite/entries/*.json — the §5.8/§5.9 suite-entry schemas (schemas only; the full enumerated served set + the runnable harness are P4).
  • profiles/*.checklist.json — the 5 per-profile flattened MUST checklists.
  • deviations.json + DEVIATIONS.md — the P1/P2/P3 §8.5 filing register.
  • scripts/check-census-bidirectional.mjs — the bidirectional build-check.

The freeze rule

After this bundle release, the vectors are immutable. A Go↔TS byte split discovered downstream is a spec defect filed on the errata rail (POST /api/v1/spec/errata, census row 14) — never a vector edit. The 4 copied vector files are diff-checked byte-for-byte against the Go testdata; the build-check fails on any drift.

⚠ Two base64 alphabets in one bundle (deviation 36)

Read carefully when porting a verifier:

  • base64url-RAW (-_, unpadded): envelope D-3 sender_signature, the receipt sig/row_sig/checkpoint_sig, the nonce, JWK x/y, the trust-list root sig.
  • STD base64 (+/, padded): the RFC 9421 census Signature header AND Content-Digest.

Mixing them silently breaks verification — they decode to different bytes.

Commands

npm --workspace=@openchildsafety/bundle run check   # the bidirectional build-check + freeze/schema gates
npm --workspace=@openchildsafety/bundle run test    # vitest: schemas valid (2020-12), vectors copied byte-clean