npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@projectpac/operation-jc-box

v0.6.0

Published

Part of PAC: @projectpac/operation-jc-box.

Readme

@projectpac/operation-jc-box

An operation adapter for the operation the spec names first: submit named sources to a verified executor, encrypted.

The box is a machine both sides can check and neither side owns. A flow drives the session -- propose a public program, approve it, submit, fetch -- but every step that touches material goes through here, because a flow writing a party input would be a flow holding the principal's data. So the flow writes the input's shape, names the sources that fill it, and this adapter substitutes what data management resolved.

  • Nothing sensitive goes back. A submit receipt says how many bytes went, a fetch receipt carries this party's own output, and no receipt ever repeats an input.
  • Verification is enforced, not decorative. The remote client checks the box's attestation against pinned measurements and refuses a mismatch; the same client against the same box accepts the real value and rejects a wrong one.
  • The party key is its own key. The RSA keypair a box requires of a participant belongs to this adapter, beside it -- it is a different key for a different job than the node's identity.

The verbs are party, propose, view, approve, submit, await and fetch, plus the egress allowlist -- the hosts this principal will let a run reach, refused at propose and again at approve. That allowlist is the one place this adapter says no on its principal's behalf: there is no policy layer behind it, and pac-node/core/data is a placeholder that does nothing. mock mode runs a whole box in-process for tests; dstack, gcp, aws, and nitro are the real verification backends, and the vocabulary is the box's own so a settings file written for one is read by the other.