npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

create-filegrc

v0.11.0

Published

Create a filegrc workspace for a SOC 2 program

Readme

create-filegrc

Create a Git-native filegrc workspace for a SOC 2 program. Use a dedicated private repository so browser-generated compliance commits stay separate from application development history.

npx create-filegrc@latest company-grc
cd company-grc
npm run validate
npm run serve

Setup asks for the legal organization name, the initial program lead and their organization job title and email, a security reporting address, and the program timezone. The generated Person records the lead’s actual position, while a separate dated Policy Owner Appointment owns the starter work. The generated private project includes a starter Security program, Program Readiness, a policy-driven Work Queue, Policy Events that add linked tasks, later audit preparation, evidence packets, and one dependency: filegrc.

Creation has two layers. The twelve-record foundation contains Workspace and Program settings, the initial program lead, two starter Appointments, the oversight Team, renderer settings, four Classifications, and the FileGRC repository Component. The default security starter adds Framework references, proposed Policies, Controls, Obligations, Documents, and Training records. Pass --starter foundation when you want to stop before selecting a Framework.

For one noninteractive run, pass company and service fields together or use --config setup.json. The optional setup object defines the service boundary and management goal after installation. Use --filegrc-package <directory> to exercise unpublished local engine changes instead of installing the registry release. This writes a machine-local file: dependency, so replace it with a released version before sharing the generated workspace.

{
  "companyName": "Example Company",
  "policyOwnerName": "Security Owner",
  "policyOwnerJobTitle": "Chief Executive Officer",
  "policyOwnerEmail": "[email protected]",
  "securityContactEmail": "[email protected]",
  "timezone": "America/Chicago",
  "starter": "security",
  "setup": {
    "serviceName": "Example Service",
    "boundary": "The production service and supporting infrastructure.",
    "criticality": "high",
    "classificationId": "confidential",
    "internetExposed": true,
    "programGoal": "type-2"
  }
}
npx create-filegrc@latest company-grc --config setup.json

Generated workspaces also include layered AGENTS.md instructions and model-driven headless commands. filegrc program-path gives agents the same five steps, exact page guidance, current status, and next actions shown in the renderer. Agents can define program scope, approve policies, implement controls and their evidence sources, complete policy work, trigger event tasks, and prepare later audit packets through the same domain functions used by the renderer.

Git is initialized on main when needed. New workspaces use trunk mode with main and origin. Browser editing becomes available after that branch has an upstream; each save fast-forwards, validates, commits, and pushes automatically. Existing parent repositories are supported and never receive a nested Git repository.

Creation output reports the resolved filegrc version, program timezone, starter record counts, whether installation ran, and whether the target joined an existing Git worktree or received a new repository.

Use npx create-filegrc@latest --help for noninteractive options.