npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@proofbyte/pqc-radar

v0.2.0

Published

Cryptographic inventory (CycloneDX CBOM) and post-quantum migration report for your codebase

Readme

pqc-radar

Cryptographic inventory (CycloneDX CBOM) + post-quantum migration report for your codebase. Part of ProofByte: Vanta proves your processes — we prove your bytes.

Regulators now ask for a Cryptographic Bill of Materials: US EO 14412 / CNSA 2.0 (2027), UK NCSC discovery + migration plan (2028), EU PQC transition (from 2026). pqc-radar produces that artifact from your actual code in seconds.

Usage

npx @proofbyte/pqc-radar scan ./my-repo --cbom cbom.json --report report.md --sarif findings.sarif

Detects quantum-vulnerable cryptography — RSA, ECC/ECDSA/ECDH, DH, DSA, Curve25519, legacy MD5/SHA-1, weak TLS configs — across Java/Kotlin/Scala, Python, JavaScript/TypeScript, Go, C#, Rust, Ruby, PHP, C/C++, nginx/Apache configs, and flags certificate/keystore files.

Outputs:

| Flag | Artifact | |---|---| | --cbom <file> | CycloneDX 1.6 CBOM JSON — the auditor-facing inventory | | --report <file> | Markdown findings report with ML-KEM / ML-DSA migration recommendations | | --sarif <file> | SARIF 2.1.0 log for GitHub code scanning | | --fail-on-findings | Exit 1 when quantum-vulnerable crypto is found (CI gate) |

Live TLS endpoint check

npx @proofbyte/pqc-radar scan-tls your-api.example.com github.com:443 [--json out.json]

One handshake per named host (no data sent): negotiated protocol, cipher, key-exchange group, certificate key type — and whether the endpoint already negotiates hybrid post-quantum key exchange. Unknown groups are reported as inconclusive, not findings.

CI gate example

- run: npx @proofbyte/pqc-radar scan . --sarif findings.sarif --fail-on-findings
- uses: github/codeql-action/upload-sarif@v3
  if: always()
  with:
    sarif_file: findings.sarif

Security posture

Fully offline (zero network calls), zero runtime dependencies, read-only, symlinks not followed. See SECURITY.md.

Caveats

v0 detection is pattern-based: fast and broad, but absence of findings is not proof of absence. A deep AST engine (PQCA CBOMkit integration) is on the roadmap.

License

MIT