npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@yxl-x/core

v1.0.0

Published

Core SDK and package tooling for Yuxiaolong YLX plugins.

Downloads

13

Readme

@yxl-x/core

御小龙统一插件格式的公共项目。这里放与某个具体插件无关的能力:

  • Manifest、平台和权限 Schema;
  • 三维风险计算、review、Integrity、签名输入与撤销合同;
  • 确定性 .ylx 打包与安全路径检查;
  • Ed25519 分离签名,以及 .ylx.sig.json、.ylx.review.json 的原子生成;
  • Desktop、admin_server 和发布工具共用的错误码与类型。

具体插件不能放在这个包内,统一放在仓库根目录的 ../plugins/。Desktop 的页面、IPC 和安装流程也不能放进这里;它们只能通过 @yxl-x/core 的公开合同接入。

CLI

YLX 与 KunX 一样,把“源码编译”和“插件打包”分开。每个插件使用自己的 TypeScript、Vite、Rust 或原生构建工具生成 dist/;YLX CLI 不执行项目脚本,只校验并打包已有产物:

pnpm run build
pnpm exec ylx validate .
pnpm exec ylx pack . --all-targets --overwrite
pnpm exec ylx sign . --overwrite

validate 对工程目录会真正生成并解包一次临时 .ylx,对 .ylx 文件会验证 Manifest、Integrity 和每个文件。pack 默认输出到 artifacts/<id>-<version>-<os>-<arch>.ylx,支持 --target darwin-arm64|darwin-x64|win32-x64、--all-targets、--output、--overwrite 和 --json;输出目录不能位于作为包内容的 dist/ 内。

sign 对单个 .ylx 生成同名的 .ylx.sig.json 和 .ylx.review.json;对插件工程目录会签署 artifacts/ 中属于当前插件版本的全部现有平台产物。私钥来自 --private-key、YLX_PUBLISHER_PRIVATE_KEY_BASE64 或 YLX_PUBLISHER_PRIVATE_KEY_PEM,并且必须是 Ed25519。

pnpm --filter @yxl-x/core build
pnpm --filter @yxl-x/core test
pnpm --filter @yxl-x/core typecheck
pnpm --filter @yxl-x/core verify
pnpm --filter @yxl-x/core pack

公开入口只引用 dist/*.js 和 dist/*.d.ts。prepare 会在 monorepo 安装依赖时生成这些文件,pack 会把经过类型检查、测试和产物校验的 npm tarball 写入 artifacts/,安装包不包含 src/ 和测试文件。

发布流程必须先调用 packYlx() 生成确定性 .ylx,再调用 signYlxPackage() 生成同名签名和审核旁文件。签名工具会重新计算真实包摘要,验证审核内容与 Manifest、Integrity 完全一致,拒绝非 Ed25519 私钥,并拒绝覆盖已有旁文件。

API 稳定性

YLX 只提供一个稳定合同:apiVersion: "1.0.0"。它同时包含 Package Core、Managed Component、Browser/Node Runtime、精确贡献点和 Credential Broker;未知版本一律拒绝,不提供隐式兼容分支。

公共 npm SDK @yxl-x/core 从 1.0.0 开始遵循 SemVer:minor 版本只能新增兼容能力,patch 版本只能修复行为,删除或改变既有合同必须升级 major。

  • schemaVersion 只描述 Manifest 外层结构,目前固定为 1。
  • apiVersion 描述行为与安全合同,目前只接受 "1.0.0"。
  • 插件自己的 version 独立升级,engines.yuxiaolong 单独声明最低 Desktop 版本。
  • @yxl-x/core 的公开导出是唯一稳定 API。当前没有 experimental API;未来实验能力必须使用名称明确的独立入口,不能从稳定入口导出,也不能进入正式市场包。

Browser Runtime 只在隔离页面内运行,没有 Node/Electron API,只能调用 Manifest 已声明且用户已授权的 Broker。Node Runtime 是完整 Node 子进程,按用户权限执行,整包因此属于 Full Trust;runtime.nodeInvoke 只是受控调用入口,不会把 Node Runtime 变成沙箱。

Browser Runtime 的挂载目标使用互斥对象:{ surface: { type: "settingsPage", pageId } }、{ surface: { type: "workspaceMode", modeId } } 或 { surface: { type: "workbenchView", modeId, viewId, slot } }。调用方不能把设置页 ID、模式 ID 和视图 ID 混在同一个扁平参数中。

Browser Host 使用独立的 protocolVersion: "1.0.0"。Host 和插件必须使用 SDK 导出的严格 Schema 校验每条消息;未知字段、未知消息、协议版本不一致和错误的页面身份都会立即拒绝。Descriptor、Connect 和 mount() 始终传递同一个嵌套页面身份,任何一层都不能重新推断页面类型。

正式市场只接受通过稳定 Schema 的 apiVersion: "1.0.0" 包,并继续强制 Ed25519、review、Integrity 和撤销验证。未知 API 版本、experimental 入口和未签名源码包必须拒绝,不能忽略未知字段后继续安装。