npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

create-geonosis

v3.1.0

Published

Scaffold a microcompany repo that passes its own geonosis gates on day one.

Downloads

2,408

Readme

create-geonosis

A repo that passes its own gates on day one.

npm create geonosis@latest pinecone -- \
  --runtime pnpm --backend medusa --ui atoms-only --brand Pinecone

There is no default for --runtime, --backend or --ui. Each decides the shape of the tree, and a default borrowed from another repo would be that repo's stack hardcoded into this one.

| Flag | Choices | |---|---| | --runtime | pnpm · bun | | --backend | medusa · sagaflow-cf · none | | --ui | tiered-shadcn · atoms-only · none | | --domains <a,b> | the domains the app composes, written into its src/platform.ts | | --medusa <range> | the Medusa a --backend medusa tree declares | | --brand <name> | turns on no-brand-names for that word | | --themekit <name> | consumes a themekit by version, never by copying it | | --marketplace <path> | install the plugin from a local marketplace instead of GitHub | | --kit <path> | read the kit from a workspace instead of the registry — a proof aid | | --no-install | write the files and stop | | --check | say what an existing repo lacks of what the scaffold writes today; write nothing | | --plan | what adopting an existing repo would take, computed off its tree; write nothing |

What it writes

  • One catalog of shared versions — pnpm-workspace.yaml on pnpm, workspaces.catalog on bun. A repo whose workspaces each pin their own typescript is a repo where one of them typechecks against a compiler the others do not run.
  • An exports map and no barrel in every workspace.
  • typecheck + lint + test in EVERY workspace — Midday has several without, and turbo silently skips those. Each test asks vitest for its own JSON report, because a runner's exit code is not a verdict.
  • docs/architecture.md, and the edges table is the one place the graph is written. geonosis-ledger sync generates turbo's boundaries.tags AND the linter's layer-walls layers from it, so a tag added there reaches both gates and neither can drift from the other. The scaffold runs both splices for you.
  • LAW.md under 60 lines, with CLAUDE.md the one line that imports it, plus a docs/pipelines/ page template.
  • The five config files: geonosis.json (verify tiers, ledger, walk, testbed, doctor), .oxlintrc.json with the presets the answers imply, geonosis.ratchet.json, gate-baseline.json, .oxfmtrc.json.
  • lefthook.yml (staged oxfmt + oxlint), .github/workflows/ci.yml with nothing switched off in it, skills-lock.json empty, .claude/settings.json installing the kit's plugin.
  • lint-corpus/ — see below.

The baseline, and the one number that is not zero

Every counter starts at 0: a new repo has earned no debt. lawLineCount starts at the measured length of the LAW.md that was just written, because it counts something that already exists and a 0 there would fail the first ratchet run over a clean tree.

lint-corpus/ — the reach corpus a shipped one cannot be

geonosis-doctor asks whether every enabled rule can fire at all, against the corpus the plugin ships. That cannot answer for a rule whose reach is the repo's own vocabulary — its layer names, its brand, its plugin package root, the within its sagas live in — and the plugin's corpus says acme and layers/core. So the scaffold writes a small corpus in this repo's vocabulary, with a manifest.json naming exactly the rules it is evidence about.

It is deliberately broken code, so it is excluded from the repo's own lint, format and typecheck — the same treatment the plugin gives its own fixtures. The corpus run copies it to a temp root and lints with --no-ignore, so nothing is hidden from the check it exists for.

--kit <path>

A proof aid. It symlinks the kit's packages into node_modules after the install and rewrites the manifest to declare them as link: — which is a declaration geonosis-doctor accepts and can verify. It is done by hand because neither package manager can do it: pnpm resolves link: happily, and bun refuses both link: and file: here, because it follows into the target and tries to resolve the workspace:* specifiers the kit's own packages use.

--check — what an existing repo never received

npx create-geonosis . --check --runtime pnpm --backend medusa --ui tiered-shadcn

A repo is scaffolded once and the scaffold keeps learning, so the divergence is permanent and one-way. --check closes the loop in the only direction that is safe: it says what is missing and writes nothing — no file created, no file opened for writing, no writeScaffold on the path at all. Exit 0 when nothing drifted, 1 with a line per drift.

Two things are compared and two are deliberately not:

  • a file the scaffold writes that the repo has never had — drift;
  • a key inside a JSON file the repo does have — drift, named as file → a.b.c;
  • a file's contents — never. A repo that has been worked in has rewritten them and was entitled to;
  • a value — never. doctor.corpus pointing somewhere else is that repo's answer, not a drift.

The workspaces are out of the question. packages/core/src/money.ts is a sample that makes a new repo compile, not a shape a repo must hold. Measured over a consumer: including them turned 24 real findings into 52, thirty of them about a sample workspace that repo does not have.

Over a repo scaffolded before D-054 moved the law it reads LAW.md, geonosis.json → law.file and the rest of what the scaffold has learned since; proofs/024-W31a-create-check/ has a whole run and the before/after hash.

A JSON file the repo has that is not plain JSON — a tsconfig.json with // comments, legal JSONC — is reported rather than skipped. A check that could not read a file has not passed over it.

Proven, not claimed

A repo scaffolded on both runtimes passes its own geonosis-verify full in a temp directory — see proofs/022-W10-scaffold/.