npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@volter/twin-webrisk

v0.1.35

Published

Local Google Cloud Web Risk twin built on @volter/world-core.

Readme

@volter/twin-webrisk

A local Google Cloud Web Risk twin for offline URL-safety checks. It models the Runhuman-critical SearchUris path used by @google-cloud/web-risk, plus local submissions, deterministic threat-list diffs, hash lookup, and operation status envelopes.

world-webrisk serve [--port N] [--root DIR] [--read-only]
world-webrisk conformance [--root DIR]

Coverage

The capability manifest (src/webrisk-capabilities.ts) is an honest partial denominator for Google Cloud Web Risk v1/v1beta1/v1eap1: SearchUris, SearchHashes, ComputeThreatListDiff, SubmitUri, long-running operations, threat-list data types, submission metadata, auth/error behavior, and the preview EvaluateUri surface are enumerated.

Modeled:

  • Auth: OAuth 2.0 Authorization: Bearer <token> enforcement and the x-goog-user-project quota header on the network path. Missing/malformed credentials return Google-shaped UNAUTHENTICATED (401); sentinel tokens exercise PERMISSION_DENIED (403) and RESOURCE_EXHAUSTED (429).
  • SearchUris: GET /v1/uris:search and Google SDK fallback transport with deterministic safe/unsafe verdicts, threat-type filtering, validation, RFC3339 cache-expiry, and faithful Google URL canonicalization (host lowercasing, dot stripping, /./ + /../ resolution, slash collapse, fragment removal, repeated percent-unescaping).
  • SearchHashes: real full-hash (SHA-256) matches for any local full hash sharing the requested 4-byte prefix (base64url binary transport), with negativeExpireTime cache hints and explicit empty matches.
  • ComputeThreatListDiff: faithful update-client protocol against a deterministic local threat list — RAW hash additions, RiceDeltaEncoding (Golomb-Rice encoder/decoder that round-trips), database checksum = SHA-256 of the delivered prefix set, maxDiffEntries / maxDatabaseEntries constraints, supportedCompressions (RAW/RICE by name or number), and incremental diffs (matching versionToken → no-op DIFF).
  • Submissions and operations: local POST /v1/projects/:project/uris:submit with parent-project validation; submission threatTypes + ThreatInfo (faithful AbuseType, deterministic Confidence score/level, and ThreatJustification labels/comments), SubmitUriMetadata.State lifecycle (resolves to SUCCEEDED), submission get and per-project list; operations get, list (/v1/projects/:project/operations), :wait, :cancel (no-op on a finished op → {}), and DELETE (removes the record → {}).
  • EvaluateUri (v1eap1 preview): POST /v1eap1/uris:evaluate returns scored per-threat-type matches (abuseType + deterministic confidence score/level) rather than a binary verdict; safe URLs yield an empty score list.
  • Type enums: faithful proto enums (names + numbers) for ThreatType (incl. THREAT_TYPE_UNSPECIFIED=0, rejected as a request value), CompressionType, ThreatInfo.AbuseType, Confidence.ConfidenceLevel, ThreatJustification.JustificationLabel, SubmitUriMetadata.State, ThreatDiscovery.Platform, and the historical Safe Browsing v4 PlatformType / ThreatEntryType names (retained for parity).
  • Errors: RESOURCE_EXHAUSTED (429) carries google.rpc.RetryInfo (retryDelay) and QuotaFailure error details, as Google attaches.
  • Audit: a local audit log of URL checks (GET /v1/twin/audit) recording method, resource, uri, threatTypes, and matched — read-only checks are not logged.
  • v1beta1: uris:search, hashes:search, and threatLists:computeDiff compatibility endpoints route to the v1 handlers.
  • Connector: injected-client pulls for verdicts, threat-list diffs (pullWebRiskDiff → threatlist state), full-hash matches (pullWebRiskHashes), project config (pullWebRiskProject → project state), and submission history (pullWebRiskSubmissions), all idempotent; push confirms local submissions.

Not yet modeled (honest todos): SubmitUri ThreatDiscovery (platform + regionCodes) targeting metadata, a v1eap1 SearchHashes preview surface, and project IAM policy (getIamPolicy / setIamPolicy / testIamPermissions).

Out of scope:

  • Real Google threat intelligence, ML scoring, privacy-preserving global update list freshness, and enforcement-grade false-positive/false-negative behavior are what the real root does. The twin reproduces the full update/transport protocol (canonicalization, Rice encoding, checksums, version tokens) against a deterministic local list, but the list contents are local, not Google's. The per-URI confidence scores returned by EvaluateUri are deterministic local stand-ins (no hosted ML), faithful to the response shape only.

No UI mirror

Google Web Risk is a vendor whose product is the API: it is a threat-list lookup service called from server code, with no operator-facing product UI at all (its Cloud Console presence is project and quota administration). Per ../../../docs/contributing/adding-a-twin.md ("Does this vendor get a mirror?") and ../../../docs/contributing/architecture.md C1b, this pack ships no React mirror and no UI capabilities — omit rather than fabricate a dashboard. Coverage is API + connector.

Architecture

State lives in the @volter/world-core event/action log. The serve path makes no real network calls. Connector functions accept injected executors for real Web Risk I/O and are not used by the local handler.