npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@servanda/vault

v0.4.0-pre

Published

Servanda sovereign local store (L0): encrypted, git-backed, persona-scoped

Readme

@servanda/vault

The sovereign local store — L0. Encrypted, git-backed, and complete on its own: a vault with no network, no server and no counterparty is a fully working Servanda install (M-10).

Shape

const vault = await Vault.create({ path, passphrase, author });
const vault = await Vault.open({ path, passphrase });

The vault directory is its own git repository, and each mutating operation commits. That gives history for free and makes the §6.1 git transport a natural later addition rather than a retrofit. Content is encrypted with a content key that is wrapped per device and by a passphrase — sealContentKey refuses any other arrangement (M-16).

What it stores

Commitments, expectations, edges with their append-only assertion chains (§4.2), envelopes, personas and keys, publish records, and the pending-extraction queue.

Assertion chains are append-only. A node retains the full chain, never a computed current state — the state is the fold over the chain, so it can always be recomputed and always be audited.

M-5: no org-context mixing

Reads are scoped by persona. A query that would combine two org personas' content is not expressible through the ordinary API.

There is exactly one escape hatch, and it is named so it can be found:

export const CROSS_PERSONA_APIS = ['listOrderingKeysAcrossPersonas'] as const;

It returns ordering keys, not content — which is precisely the exception §5.3 permits: the personal attention queue may order opaque items across personas; it may never transfer content between them. Any future addition to that list is a constitutional change and should be treated as one.

M-15: retention decay

await vault.runRetention({ now });

After the owner-configured window, closed, expired, released and superseded edges lose their commitment plaintext, while the edge and its full assertion chain are preserved.

That asymmetry is the whole point (ADR-0004): afterwards you can still prove that a promise was made and kept, with dates and both signatures, and nobody — including you, including a court — can reconstruct what it said. Remember that, not what.

Personal-scope escrow does not exist in this package. Not as a disabled flag, not as an option: M-15 forbids it, so there is nothing to turn on.