npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@weavix/cli

v1.1.1

Published

CLI to work with weavix plugin system

Downloads

1,760

Readme

@weavix/cli

CLI tool for developing and publishing Tracker plugins: create from a template, debug locally, build, update the template, and publish to the Catalog.

Installation

npm install -g @weavix/cli

Upgrade the CLI

weavix upgrade

Installs the latest published version of @weavix/cli from npm. When a newer version is available, the CLI suggests running weavix upgrade before regular commands.

Authentication

Publishing and Catalog operations require an OAuth token:

weavix login   # save OAuth token and select an organization
weavix logout  # remove saved credentials

login prints a link to obtain the token, then reads the organizations available to that token from the Platform and asks you to pick one.

That list is partial by nature: an OAuth token reports your Yandex 360 organizations and an IAM token your Yandex Cloud ones, so an organization you belong to can be missing, and for some tokens it comes back empty. Pick My organization is not listed — enter its ID to type the Organization ID by hand; login prints a link to look it up. The same prompt is used automatically when the list is empty or cannot be read at all, so a platform outage does not block login — only a token the platform rejects outright does.

Quick start

1. Create a plugin

weavix create

Prompts for a template, plugin name/description, and initialises the project directory.

Generated projects include AGENTS.md and a CLAUDE.md that imports it. Before UI work, agents read DESIGN.md for component selection, version-matched documentation, and visual checks. design/ORBITA.md explains the host's Orbita typography; the template includes its SCSS and a local WOFF2 font. up does not update these instructions: merge them into existing projects while preserving project-specific rules.

2. Debug

weavix debug

Starts a local dev server with hot reload. Find the plugin in the slot specified in manifest.json.

Sign in to Tracker in your browser. Plugin API requests run through the Tracker host using that browser session.

By default, debug validates manifest.json. --no-lint skips this validation only when permissions.data is empty or omitted. With any data permissions, the entire manifest is validated, including the declared permission names.

The CLI creates a temporary config.json for Tracker to load the local plugin. Each slot entry includes debugSessionId (the current debug run) and manifestRevision (the manifest revision). The CLI updates the file automatically and deletes it when debug stops. The template excludes it from version control; the standard production build and archive exclude it too. After a crash, restarting debug recreates the file.

3. Build

weavix build

Builds the production bundle into dist/.

4. Update template

weavix up

Pulls the latest template/config files into a project created from an older CLI version.

5. Publish

weavix login       # once
weavix submit --dry-run   # validate and build without submitting
weavix submit             # validate, build, and submit for review
weavix submit --public    # a new plugin: make it public and submit it for review

submit validates the manifest, catalog metadata, and assets; installs dependencies; runs lint and audit; runs typecheck and tests if the corresponding scripts are present. Then builds an archive and sends it to the Platform.

submit --dry-run performs the same local checks and builds the archive, but does not modify the manifest and does not call the Platform API to create, update, or submit the plugin.

After submitting, weavix info shows the automated checks of every version (secrets, text, image, code): whether each one ran, what it found and why the version stopped before or during moderation.

End User License Agreement (EULA)

To host your own agreement with the plugin, place a file such as public/eula/offer.html in the project and set eulaUrl in manifest.json to /eula/offer.html. The build copies the file to dist/eula/offer.html and includes it in the plugin archive, separately from documentation under /docs/. You can choose another filename or use an external HTTPS URL. The plugin card will link to the agreement.

The SDK packages PDF and DOCX files from public/eula/, but the Platform currently rejects these extensions when uploading the archive.

If you omit eulaUrl, the card will link to the common agreement (ru) in both Russian and English UIs. An English document is not available yet. You can adapt the document for your plugin and publish your version through eulaUrl.

To submit on behalf of a different organisation without changing the one saved at login, pass the ID for the current run only:

weavix submit --org-id <organization-id>

6. Go public

Being public is a property of the plugin, not of a version, and a public plugin cannot go back to your organization only.

  • A new plugin that has not been published yet: weavix submit --public makes it public right away, and its versions go through Yandex moderation to the public marketplace.
  • A plugin already published in your organization: weavix make-public files a publication request for the version your organization approved, and Yandex moderation reviews it. Submitting new versions is blocked until the request gets a verdict.
weavix make-public                  # request publication (asks for confirmation; --yes skips it)
weavix info                         # the request status and the moderator comment
weavix withdraw --publication       # withdraw the request and unblock submitting versions

If the marketplace card is incomplete, make-public lists what to fill in. If the secret scan finds something, it lists the findings and asks which of them are false positives; to confirm them without a prompt, pass --ack <fingerprint...>.


Commands

| Command | Description | | ---------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | create [--no-install] | Create a new plugin from a template and install its dependencies. --no-install skips the install | | install | Install the plugin dependencies in the current directory | | up | Update the plugin to the latest template version | | upgrade | Upgrade the installed CLI to the latest version | | build | Build the plugin for production | | build-docs | Build Diplodoc documentation | | debug [--no-lint] | Start a local dev server with hot reload. --no-lint skips manifest validation only when permissions.data is empty or omitted | | lint | Validate the manifest, TypeScript, ESLint, and styles | | version [newVersion] | Show or set the plugin version in manifest.json: an explicit semver or major/minor/patch | | manifest set <path> <value> | Set a manifest.json field at a dot-notated path, e.g. author.name | | manifest add <path> <value> | Add an item to the array at a dot-notated path (creates the array if it's missing) | | manifest remove <path> <value> | Remove a matching item from the array at a dot-notated path | | manifest unset <path> | Remove a field entirely at a dot-notated path | | manifest edit | Interactively pick and edit a manifest field | | login | Save OAuth token and select an organization | | logout | Remove saved authentication data | | submit [--dry-run] [--public] [--iam-token <token>] [--org-id <organization-id>] | Validate and build the plugin; without --dry-run also submit for review. --public makes a plugin that is not published yet public before submitting. --org-id overrides the saved organisation for the current run only | | make-public [plugin-id] [--ack <fingerprint...>] [--yes] [--iam-token <token>] | Make the plugin public; a plugin already published in your organization gets a publication request reviewed by Yandex moderation. --ack confirms secret-scan false positives | | list [--iam-token <token>] | List plugins and their moderation statuses | | info [plugin-id] [--iam-token <token>] | Show plugin information and the latest publication request, plus the moderation verdict, review notes and automated check results (secrets, text, image, code) per version; uses manifest.id by default | | withdraw [plugin-id] [version] [--publication] | Withdraw a submitted version; arguments default to the manifest values. --publication withdraws the pending publication request instead | | doctor [--json] [--network] [--publish] | Check the local project and authentication. --network verifies the token via the Platform API; --publish makes publish-only checks blocking |

The global flag --verbose enables verbose output.