npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

bulkhead-connect

v0.1.1

Published

Dial out to Bulkhead so your agent can be certified without exposing an endpoint.

Readme

bulkhead-connect

Get certified without exposing an endpoint.

The other way to be certified is to expose an HTTPS endpoint and let Bulkhead call it, verifying our signature so nobody else can. That works, and for many teams it is the easier internal approval. It is also impossible for a great many production agents: inside a VPC, in a cluster, behind a corporate proxy, there is no public ingress to expose and no appetite for creating one.

This reverses the direction. You run it beside your agent; it opens one outbound TLS connection to Bulkhead and receives certification probes on it. You open no port, change no firewall rule, and add no public surface — the same shape as a CI runner or a compliance agent.

npm install bulkhead-connect

With your handler

import { createBulkheadHandler } from 'bulkhead-adapter';
import { connect } from 'bulkhead-connect';

connect({
  credential: process.env.BULKHEAD_AGENT_CREDENTIAL,   // bhc_… from the console
  handler: createBulkheadHandler(myAgent),             // what you already wrote
  binding: 'production',
});

If you already have /bulkhead working, that is the whole change. The connector calls the same handler Bulkhead would have called over HTTP.

Or without touching your code

Already running the endpoint on localhost and simply not willing to make it public? Point the CLI at it:

BULKHEAD_AGENT_CREDENTIAL=bhc_… \
  npx bulkhead-connect --forward http://127.0.0.1:8080/bulkhead --binding production

What it can and cannot do

  • It receives a scenario name from a closed list and calls your handler. It rejects any scenario it was not compiled with, so new scenarios reach you as a version of this package you choose to install — never as something pushed into a running process.
  • There is no message in the protocol that names code to run, a URL to fetch, or a suite to execute. That is a limit on Bulkhead, not on you, and it is the first thing to show a reviewer.
  • It cannot read your filesystem or reach your other services.
  • It holds one credential, issued by us and scoped to your one agent. It holds no credential of yours.
  • It is never in your request path. If it dies, your agent is unaffected.
  • It is MIT licensed and short. Read it rather than trusting this list.

binding

What you are connecting: production, staging or sandbox. It is printed on your certificate so a buyer can see the scope of what was tested. We do not verify it — the same convention a classification or ISO certificate uses, where the auditor verifies the declared scope and the scope appears on the certificate so the reader can judge it. Defaults to sandbox.

Credentials

Issue one per agent in the console. It is shown once; only a hash is stored, so there is no recovery — rotate instead. Both credentials stay live during a rotation, so deploy the new one, confirm it connects, then revoke the old one. No maintenance window.

Reconnection

Automatic, with exponential backoff to 30 seconds. A deploy or a restart is a disconnect, not a failed check: your seal is not suspended for reconnecting, and the connector never becomes the reason a container refuses to exit.

Events

connect({
  ...,
  onEvent: (event) => {
    // connected | disconnected | reconnecting | probe | refused | error
    console.log(event);
  },
});

Requires Node 20 or later, which has a built-in WebSocket. Pass WebSocketImpl to supply your own.

Full transport contract: docs/protocol-v1.md. What we do and do not receive: agentbulkhead.com/trust.