npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

aloic

v0.1.18

Published

Publish a folder to Aloic from a terminal or a build machine.

Downloads

373

Readme

aloic

Put your site live on Aloic in one command, from your terminal or any build server.

curl -fsSL https://get.aloic.ai | sh
aloic login
aloic deploy ./dist

Deploys finish in seconds because only the files you changed are uploaded. Installing never needs root, and every file is verified before it runs.

Open a new terminal to use aloic, or run source ~/.aloic/env in the one you installed from. Remove it any time with aloic uninstall.

Requires Node 18 or newer, which the installer checks for before it downloads anything. To pin a version, pass it: curl -fsSL https://get.aloic.ai | sh -s -- 0.1.0.

Commands

| | | |---|---| | aloic login | Sign this machine in through your browser | | aloic logout | Forget the key on this machine | | aloic init | Choose which project this folder publishes to | | aloic deploy [folder] | Publish a folder and point the project at it | | aloic deploy preview | Publish this project's newest preview | | aloic test preview | Open the newest preview at a temporary address | | aloic projects | List the projects this machine can publish to | | aloic whoami | Show who this machine is signed in as |

aloic deploy signs you in and asks which project to use the first time, so you can start with it alone.

aloic deploy publishes, unless aloic settings has publishing off or you pass --preview. Then it creates a preview: the files are uploaded, the project keeps serving what it was serving, and aloic deploy preview publishes it.

Your site is published from the folder that holds index.html, so server code and config files next to it stay private. Use --root <folder> to choose a different folder, or --root . to publish everything.

Projects with a backend

Your server runs on your own Vercel account and answers on the same address as your site. Connect one in the project's settings under Backend, or say yes when aloic deploy finds a server in your folder.

With a backend connected, one aloic deploy ships your site and your server together. Either can go on its own:

aloic deploy            # files, and the backend if there is one
aloic deploy --backend  # only the backend. Nothing is published here
aloic deploy --files    # only the files. The backend is left alone

The backend half sends source rather than output, because Vercel runs the install and the build. It carries up to 400 files and 2.5MB of them; past that, vercel deploy --prod is the tool for the job and this says so.

A deployment starts queued, so the command finishes before the build does. Aloic writes the route the moment that build is ready.

Options

| | | |---|---| | --title <text> | Names the deployment, shown as its heading | | --description <text> | What changed, shown under the name | | --project <slug> | Publish to this project, ignoring .aloic | | --preview | Create a preview without publishing it | | --root <folder> | Publish this folder rather than the one holding the index.html. --root . publishes everything | | --quiet | Print only the address at the end |

Every deployment has an address

aloic deploy ./dist            # publishes it, and prints both addresses
aloic deploy ./dist --preview  # creates a preview, prints its address

A deployment gets its own permanent address the moment it exists, published or not: <secret>--<project>.aloic.ai. That is what --preview is for. It is not a folder somebody has to go and find in a dashboard, it is a link you can open and send.

The address carries a random word. A project's name is public, so anything derived from it would let people read what you had not shipped yet. The secret is printed by the command and never changes, so a link you hand out keeps working; a build's page in the dashboard can replace it if one gets out.

An unpublished build is not indexed by search engines and is not counted in the project's analytics. Anybody holding the address can still open it: it is unguessable, not private.

Publishing one afterwards is aloic deploy preview, or one button on its page.

Variables

aloic env                          # what this project has
aloic env add API_TOKEN            # asked for, hidden as you type
echo -n "$TOKEN" | aloic env add API_TOKEN
aloic env add REGION eu-west-1 --config
aloic env rm API_TOKEN

A value on the command line is in that machine's shell history, so it is accepted and never asked for that way: interactively the prompt is hidden, and a pipe is what a build machine uses.

--config stores a readable value rather than a secret, for an address or a flag that is on the project's screens anyway. --production, --preview and --development limit which builds see it; by default all three do, and the limit reaches the backend as well as this project.

It goes to the backend too, if the project has one. A variable exists to be read by something running, and a project with a Vercel backend joined to it needs the same token in both places. Adding one here writes it to Aloic and to that backend in the same breath, and removing one takes it out of both. Nothing is said when there is no backend, which is most projects.

There is no env pull, and there cannot be. A secret is sealed on the way in with a key that lives on the server and is never used in the other direction, so nothing anywhere reads one back, including this tool and including the dashboard. A command that wrote a .env file could only fill in the config values and leave every secret blank, which is a file that looks like it worked.

In a build

Set ALOIC_KEY and skip the sign in entirely:

ALOIC_KEY=alo_... npx aloic deploy ./dist

There is a ready made GitHub Actions workflow in github-action.yml. Copy it to .github/workflows/deploy.yml and add the key as a repository secret. The build runs on GitHub's machine and only the finished folder is sent.

What it writes

| | | |---|---| | ~/.aloic/config.json | The terminal key, mode 0600. Yours, per machine | | ./.aloic | Which project this folder publishes to. Commit it |

The key is per machine so signing in once covers every project on this computer. Which project a folder publishes to is a fact about the folder, so it lives beside it and can be committed, which is what lets a whole team deploy the same repository without each of them choosing from a list.

What a terminal key can do

Publish to the projects on your account, and nothing else. It cannot change your account, your domains, or your billing, and it cannot make more keys. Revoke one at any time in Settings on aloic.ai.

Notes

  • Only files that changed are uploaded. Content is addressed by its hash, so a second deploy of a site whose images did not change sends the one edited file.
  • node_modules, .git, .env and similar are skipped rather than refused, so pointing this at a project root works.
  • No dependencies. This is the one tool in a pipeline that has to still work on a machine nobody has looked at in a year.
  • Requires Node 18 or newer.