npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@skilldeck/migrate

v0.1.0

Published

Change things without breaking prod: zero-downtime schema migrations, dependency upgrades and API contract diffs, each backed by a zero-dependency checker script.

Readme

migrate

Change the schema, the dependencies or the API without breaking prod.

Outages cluster around three kinds of change:

  • a migration that locks a hot table;
  • an upgrade applied from memory instead of the changelog;
  • an API edit that breaks clients nobody could see.

Each skill here pairs a short, opinionated playbook with a zero-dependency checker the agent runs before anything ships. That way "is this safe?" is answered by a tool, not a guess.

| Skill | Use when | Checker | |---|---|---| | schema-migration | Writing or reviewing a DB migration: columns, indexes, constraints, type changes, backfills | lint-ddl.mjs: flags DDL that blocks writes, rewrites tables or breaks running code (Postgres, MySQL) | | dependency-upgrade | Bumping a library, framework or toolchain; applying a codemod; lockfile breakage | upgrade-report.mjs: classifies what's outdated, audits the lockfile diff, lists every import of a package | | api-contract-diff | Changing a REST/OpenAPI, GraphQL or protobuf contract | contract-diff.mjs: sorts changes into breaking, warning and safe (uses oasdiff, graphql-inspector or buf when installed) |

Install

npx @skilldeck/migrate install                 # Claude Code, user-wide
npx @skilldeck/migrate install --project       # this repo only
npx @skilldeck/migrate install --agent all     # also Codex and .agents
# or, with every SkillDeck pack available:
npx @skilldeck/cli add migrate

Claude Code marketplace: /plugin marketplace add kitasid/skilldeck, then /plugin install migrate@skilldeck.

Run the checkers yourself

They work without an agent, in CI, or in a pre-merge hook:

npx @skilldeck/migrate lint prisma/migrations                     # exit 1 on lock-heavy DDL
alembic upgrade head --sql | npx @skilldeck/migrate lint -
npx @skilldeck/migrate upgrade outdated                           # upgrade steps, majors last
npx @skilldeck/migrate upgrade usages react                       # every import and the names used
npx @skilldeck/migrate contract openapi.yaml --base origin/main   # exit 1 on breaking changes

What lint-ddl catches

On Postgres:

  • CREATE INDEX without CONCURRENTLY
  • ADD COLUMN ... NOT NULL without a default
  • volatile or stored-generated defaults that rewrite the table
  • ALTER COLUMN TYPE
  • SET NOT NULL without a validated check
  • foreign-key and check constraints added without NOT VALID
  • unique or primary-key constraints added without a prebuilt index
  • VACUUM FULL and CLUSTER
  • migrations that set no lock_timeout

On MySQL, it catches MODIFY/CHANGE COLUMN and index builds without ALGORITHM or LOCK guards.

On both, it flags:

  • renames
  • drops
  • data changes inside the migration

Tables created in the same file are exempt, since locking an empty table costs nothing. Every finding comes with the safe recipe (see skills/schema-migration/references/postgres-locks.md).

MIT licensed. Node 20+. No dependencies beyond @skilldeck/core for the installer.