npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

cursedbelt-server

v4.22.0

Published

The app-facing Bun/Hono server tier of the cursedbelt split — storage, sharing, activity, guard, sync. React-free; cursedbelt-core below it.

Readme

cursedbelt-server

The server tier of the cursedbelt split: Hono on Bun, the D1 seam a Worker crosses, the binary-server client, the guard, and the fleet standards (retention, activity, notifications, engagement). cursedbelt-core is below it, the React design system cursedbelt above it.

bun add cursedbelt-server

🔴 The root export is a BARREL — import the leaf

import … from "cursedbelt-server" re-exports everything, so it reaches every optional peer and bun:sqlite at once (the table below). An app that wants one function pays for all of them, and on a Worker wrangler deploy fails to bundle it. Import the subpath that owns the symbol — cursedbelt-server/login-throttle, cursedbelt-server/binary-store, cursedbelt-server/d1 — never the root. package.json exports is the list of subpaths.

Why this stays prose: which symbol an app WANTS is decided in the app, and a repo's gate proves that repo — so the barrel-importer grep belongs to the generation's tools, not to this package.

What you install

Most subpaths need nothing beyond hono (and zod where they validate). These are the only ones that statically reach an OPTIONAL peer, or a bun builtin a Worker does not have. The table is checked: src/readmeInstallTable.spec.ts fails when it disagrees with src/subpathReach.ts, and src/barrelsReachNoOptionalPeer.spec.ts fails when that disagrees with what a bundler actually keeps.

| subpath | optional peers it imports | bun builtins it needs | |---|---|---| | . | kysely, kysely-bun-sqlite, otplib, plainjob | bun:sqlite | | ./jobs | plainjob | — | | ./d1/backup-local | — | bun:sqlite | | ./guard | — | bun:sqlite | | ./guard/revocations | — | bun:sqlite | | ./sqlite | — | bun:sqlite | | ./engagement | — | bun:sqlite | | ./request-log | — | bun:sqlite |

sharp and @node-rs/argon2 are loaded lazily (await import()), so a missing one breaks only the feature that asks for it, not the build.

🔴 Bun.serve's websocket selects an OVERLOAD

It is not an optional field. An options object whose websocket may be undefined — a conditional value or a conditional spread — matches no overload, and TypeScript reports an error about the whole options object rather than the one field. Use serveBun(app, { websocket }), which takes it as a genuinely optional field and makes the two concrete calls itself. src/server/serveBunOverload.spec.ts runs tsc on the trap and goes red when bun's types change.

Standards

docs/retention.md, docs/activity.md, docs/notifications.md, docs/engagement.md — the contracts every app that uses those modules is agreeing to. Cite them from an app with the package prefix (cursedbelt-server/docs/retention.md).

Verifying

cd "$FORGE/libs/cursedbelt-server" && bun run verify