npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@usedrift/cli

v0.1.14

Published

Find which dependency upgrades affect your code, show the evidence, and prepare reviewable fixes from the command line.

Readme

Drift

OpenSSF Scorecard CI License: MIT

Dependency upgrades, checked against your code. Drift downloads both published versions, diffs their real API, and searches your repository for the code that uses whatever changed. It keeps uncertainty visible, and it never merges for you.

$ drift outdated

2 of 2 direct dependencies have a newer version

Package    Current  Wanted  Latest  Declared in
glob         8.1.0   8.1.0  13.0.6  package.json
lru-cache   7.18.3  7.18.3  11.5.2  package.json

  ▲ glob 8.1.0 → 13.0.6  Affects your code · 1 actionable site in 1 file · …
  ? lru-cache 7.18.3 → 11.5.2  Runtime Unknown · Upstream requires Node 20.x || >=22 · …

Ask it why, and every claim comes with its evidence and its location:

$ drift explain glob          # your agent gets the same answer over MCP

glob  8.1.0 → 13.0.6  (npm, declared in package.json)

Verdict: BREAKS THIS CODE — a breaking change with located call sites in this repository
Upgrade after review. 1 place in this repository uses an API that glob changed.

Breaking changes upstream (14):
  [removed-export] the default export of glob
      `glob` no longer has a default export (was a function).
  [removed-export] glob.sync, sync
      `glob.sync` is no longer exported (was a function).
  …

Where it reaches this repository (1):
  src/app.js:2  sync
      export function findAll() { return glob.sync('**/*.ts'); }

Nothing above came from a changelog. glob.sync was read out of the two published .d.ts files, and src/app.js:2 came from searching this repository for it.

Why this is not just npm outdated

An update bot tells you a newer version exists. Drift tells you whether you can take it.

| | Dependabot / Renovate | OpenRewrite / Moderne | Drift | | --- | --- | --- | --- | | Finds available upgrades | yes | no | yes | | Says what broke upstream | no | via curated recipes | computed from the artifacts | | Says where it breaks in your code | no | n/a | file and line | | Works on packages nobody wrote a recipe for | n/a | no | yes | | Refuses to claim "safe" without evidence | n/a | n/a | yes |

OpenRewrite is the better tool once you have decided to migrate — it rewrites the code, and Drift does not. Drift answers the question before that one: which of these ninety upgrades can I take, and what will the rest cost me?

Measured, not asserted

Drift is scored against public research corpora, including two with real negative controls — the only ones that can support a precision at all.

| Corpus | Scored | Negatives | Precision | Recall | F1 | | --- | ---: | ---: | ---: | ---: | ---: | | Kong — real-world npm API changes | 16,333 | 16,168 | 83.9% | 97.6% | 0.902 | | Roseau — hand-labelled Java pairs | 255 | 157 | 99.0% | 100% | 0.995 |

Recall against consumer-impact corpora (BUMP, SWE-Bump, TimeMachine) is reported separately, because those are positives-only and cannot support a precision. Every number, every refusal to compute one, and the runs behind them: benchmarks.

What Fix with AI is, and is not

Detection is one question; fixing is another. Fix with AI hands the upgrade to the coding agent you selected, as one session over whatever you pressed it on — the whole upgrade, one package, or one concern — and then judges the result: every file the session changed is validated on its own, and a file that breaks a rule (a protected path, a weakened test or configuration, a downgraded dependency) is reverted while the rest is kept.

What it does not do is hand the agent Drift's findings as its instructions. Measured on real upgrades with hidden compatibility tests, findings in the prompt made the agent fix what was listed and stop looking, so a session is given the task a developer would give it. Drift's analysis stays where it belongs: in the report a human reads, and in the agent interface an agent can query when it wants it. Drift claims no accuracy or token advantage over the same agent working alone; the paired benchmark behind that statement runs on every change to this path, and its publication gates are what keep a number off this page until one earns it.

What Drift will not tell you

  • That an upgrade is safe, without evidence. When the API surface cannot be computed, the verdict is insufficient-evidence, not "clean".
  • That your code is unaffected because a search found nothing. A completed search is not proof; only an isolated build-and-test run turns "found nothing" into "unaffected".
  • Everything. Localization is a search. It misses dynamic dispatch, reflection, and behaviour changes with no signature. drift outdated --verify installs each upgrade and runs your own build and tests, which is the only thing that can settle it.

Install

npm install -g @usedrift/cli     # Node.js 22.6+
drift outdated

Coding agent (MCP) — Drift as a tool your agent calls, so it stops guessing what a version pair changed. Runs locally over stdio; there is no service.

claude mcp add drift -- npx -y @usedrift/cli mcp

An agent fixing an upgrade calls plan_upgrade and gets a short plan (under 2,300 tokens) with only the findings that reach your code, then pulls a finding or its evidence by id when it needs more (get_finding, get_evidence), and runs your checks with verify_upgrade. The full report stays for people. See the agent interface; drift analyze --agent prints the same plan without MCP.

VS Code — install Drift — Safe Dependency Upgrades (drift.usedrift) · docs

GitHub Action — copy examples/workflows/drift.yml; approval mode is the default.

- uses: trydrift/drift@v0
  with:
    repo-token: ${{ secrets.GITHUB_TOKEN }}

Commands

| Command | What it does | | --- | --- | | drift outdated | Find available upgrades and check their impact. | | drift analyze | Check a dependency change already in git. | | drift check | Whether this code is already wrong about the versions it has installed. | | drift upgrade | Install only the upgrades Drift found safe. | | drift fix | Prepare fixes, push a branch, open a PR. | | drift explain <package> | What changed in one upgrade, and where it lands. | | drift diff <eco> <pkg> <from> <to> | Real git diff between two published versions. | | drift mcp | Serve Drift to a coding agent over MCP. |

Add --verify to install each upgrade in a scratch worktree and run your project's own checks against it.

drift check is the one that asks nothing about upgrades. The version on disk exports a set of names, this repository imports a set of names, and an import naming something that version does not export is an error that already exists — no upgrade required for it to be true, and no test run to find it. It happens for ordinary reasons: a range resolved forward on a fresh install, a lockfile regenerated on another machine, a dependency bumped without anyone reading what moved.

$ drift check

1 import in 1 file names something the installed version does not export.

  src/app.js:1  GlobSync  —  not exported by [email protected]

Checked 2 packages against 2 files.

This compares the names your code imports against the API of the version on disk.
It does not follow member access through an imported object, so a clean result
means every name you import exists — not that your use of the package is correct.

That last paragraph is printed on every run, clean or not, along with a count of what could not be checked and why. In an internal cold-cache sweep across 50 public repositories — jest, nest, eslint, prettier, react-router, vue, axios and more — Drift checked 372 packages and reported zero findings. It also declined to judge 179 packages it was asked about, because their API could not be enumerated from the published declarations: a name missing from a surface Drift cannot read is not evidence of anything, and saying so is the difference between a finding and a guess.

Ecosystems

npm, PyPI and Maven are the three measured against research corpora. Detection also covers Go, Cargo, NuGet, Packagist, RubyGems, Hex, Pub, Conan, vcpkg, Swift, CocoaPods, OPAM and Arduino — with capabilities per ecosystem in supported ecosystems.

License

Drift is MIT licensed. You may use, copy, modify, distribute, sublicense, and sell copies of it, subject to the license notice.

Documentation

Why Drift · CLI · Architecture · Configuration · Ecosystems · Fix plans · Trust & safety · Deployment · Research · Telemetry

Real runs, published: trydrift.github.io/drift