npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@voyant-travel/app-manifest

v0.2.6

Published

Validate and compile a Voyant app release manifest, and reproduce the release digest the marketplace admits.

Downloads

13,558

Readme

@voyant-travel/app-manifest

Everything a Voyant app publisher needs to declare a release: the manifest schema, and the compiler that normalizes a manifest, canonicalizes it, and produces the release digest.

This package exists so a publisher can validate a release offline, before submitting it, and get the same answer the host will. compileAppManifest does not merely check a manifest — it produces the sha256: digest that identifies the release, so anything reproducing that digest has to use the same canonicalization. A JSON Schema alone cannot do that.

Its dependencies are the extension slot vocabulary, the custom-field contract, and the webhook contract. It does not pull in the operator runtime.

Install

pnpm add -D @voyant-travel/app-manifest

A build-time/test dependency is the normal shape: nothing here runs in your app's request path.

Compile a release

import { compileAppManifest } from "@voyant-travel/app-manifest/compiler"

const { manifest, digest, canonicalJson, normalizedRelease } =
  compileAppManifest(JSON.parse(await readFile("voyant-app.json", "utf8")))

console.log(digest) // sha256:…  — stable across key order and array order

Compilation fails loudly, as a ZodError, on anything the host would reject: an unknown top-level key, a non-HTTPS entry URL, a webhook endpoint pointing at a private host, declared webhooks without the app-webhooks:configure scope, a default locale missing from supported, or pages in one navigation group disagreeing about insertAfter.

Pin this package in CI and assert the digest to catch a manifest change that would otherwise surface only at admission.

Validate webhook subscriptions against a deployment

Pass the deployment's event catalog to additionally check that every subscribed event actually exists as an external contract:

compileAppManifest(input, { eventCatalog })

Without a catalog, subscriptions are checked for scope but not for existence — which is the right default for an offline publisher build.

Related

  • @voyant-travel/admin-extension-sdk — the slot vocabulary and the UI extension protocol your framed pages speak
  • @voyant-travel/webhook-delivery-contracts — verify the webhooks you receive
  • @voyant-travel/custom-fields-contracts — the custom field definition shape an app-owned field extends