npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@pathos-labs/dacs-jcs

v0.1.0

Published

PATH-OS JCS, SHA-256, and registry-bound Ed25519 toolkit

Readme

@pathos-labs/dacs-jcs

This package exposes the PATH-OS JSON canonicalization, SHA-256, and Ed25519 signing helpers for Node.js 20 or later.

This is not a DACS-Standard publication. This repository does not publish the package to an npm registry; registry publication is a separate operator action.

API

  • jcsCanonical(value) returns canonical UTF-8 bytes.
  • jcsHash(value) returns the 32-byte SHA-256 digest of those bytes.
  • jcsHashHex(value) returns that digest as lowercase hexadecimal.
  • sign(separator, body, privateKey, intermediateHash?), verify(separator, signature, body, publicKey, intermediateHash?), and generateKeypair() provide Ed25519 operations.
  • The exported separator maps, guards, and buildSignedBytes expose the repository's closed domain-separator registry.

The DACS CORE CF-1 pre-pass normalizes JSON string values to NFC. Object member names are not normalized: RFC 8785 preserves them and orders their raw UTF-16 code units. The implementation also rejects BigInt, non-finite numbers, numbers whose magnitude exceeds Number.MAX_SAFE_INTEGER, unpaired UTF-16 surrogates, and other inputs that cannot produce the repository's reproducible JSON form.

Signing is registry-bound. sign accepts only an emittable separator registered by src/domain-sep.ts; read-only legacy separators cannot produce signatures. verify returns false for an unknown separator. This prevents callers from using the signing primitive without an assigned purpose string.

Vectors

vectors/canonical-form-v0.1.json is derived deterministically from conformance/partner-kit/vectors.json: it carries only the canonical-accept and canonical-reject sections (the repository's JCS corpus, including NFC/NFD value and member-name cases) and records the source file's SHA-256; the partner-kit signing and drift sections, which carry test keys, are not packaged. vectors/index.json records its package path, byte count, SHA-256 digest, and origin.

Provenance and build

There is one authoritative implementation: the repository files src/jcs.ts, src/domain-sep.ts, and src/lib/sign.ts. The build refreshes their package source copies byte-for-byte and compiles those exact files with packages/jcs/src/index.ts. provenance.json lists each compiled source and records sourceManifestSha256, the SHA-256 of the JCS-encoded, path-sorted list of source paths and content hashes. It is content-derived and contains no Git HEAD or timestamp.

From the repository root:

node --import tsx scripts/build-jcs-package.mts
node --import tsx scripts/build-jcs-package.mts --check