npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@parmanasystems/signing

v1.98.56

Published

Deterministic runtime signing infrastructure for governed execution authority, KMS abstraction, and independently verifiable trust lineage.

Readme

@parmanasystems/signing

Runtime signing authority for the Parmana server. Reads Ed25519 key material from environment variables at startup, wraps it in a SigningAuthority interface, and provides the authority to the server and execution runtime. This package is the bridge between the deployment's key management strategy and the Signer interface that executeFromSignals and executeDecision require.


Public API

/**
 * Create a SigningAuthority from environment variables.
 * Reads PARMANA_SIGNING_PROVIDER to select the backend.
 * Currently only "local" is supported — reads PEM key files from paths
 * in PARMANA_SIGNING_PRIVATE_KEY_PATH and PARMANA_SIGNING_PUBLIC_KEY_PATH.
 * Throws [SYS-TRUST-002] for unknown providers.
 */
function createSigningAuthority(): SigningAuthority

/**
 * File-backed Ed25519 signer that reads PEM key paths from env vars at construction.
 * Throws [SYS-TRUST-001] if key path env vars are missing.
 */
class EnvPemSigner implements SigningAuthority {
  constructor()                                // reads env vars
  async sign(payload: string): Promise<string> // returns base64 signature
  getPublicKey(): string                       // returns SPKI PEM string
}

/**
 * The signing authority interface. Implemented by EnvPemSigner.
 * Extends the Signer interface with getPublicKey().
 */
interface SigningAuthority {
  sign(payload: string): Promise<string>;
  getPublicKey(): string;
}

Environment variables

| Variable | Required | Description | |---|---|---| | PARMANA_SIGNING_PROVIDER | No | Signing backend. Only local is supported. Default: local. | | PARMANA_SIGNING_PRIVATE_KEY_PATH | Yes (when provider is local) | Absolute path to the Ed25519 PKCS8 private key PEM file. | | PARMANA_SIGNING_PUBLIC_KEY_PATH | Yes (when provider is local) | Absolute path to the Ed25519 SPKI public key PEM file. |

Generate a key pair:

openssl genpkey -algorithm ed25519 -out /secure/parmana/private.pem
openssl pkey -pubout -in /secure/parmana/private.pem -out /secure/parmana/public.pem

Package wiring

@parmanasystems/signing has no internal @parmanasystems dependencies. It is used exclusively by @parmanasystems/server: getRuntimeSecurityContext() calls createSigningAuthority() and passes the resulting SigningAuthority as the signer argument to executeFromSignals. The LocalVerifier in @parmanasystems/execution is constructed with the public key from signer.getPublicKey().