npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

deepbom

v1.95.0

Published

Local multi-format deployment-artifact analysis for on-device AI models

Readme

DEEPBOM CLI

Local deployment-artifact analysis for TFLite, ONNX, GGUF, SafeTensors, Core ML, and ExecuTorch.

npx deepbom audit model.onnx --format cyclonedx
npx deepbom audit model.onnx --format sarif --output deepbom.sarif --fail-on high
npx deepbom capabilities --compact
npx deepbom gguf model.gguf --context 8192 --memory-mib 8192
npx deepbom audit Model.mlpackage --compact
npx deepbom audit safetensors-repository/ --compact
npx deepbom verify model.tflite --contract production-interface.json
npx deepbom diff baseline.tflite candidate.tflite
npx deepbom explore model.tflite --target-profile target-profile.json
npx deepbom audit model.pte --executorch-build deepbom.executorch-build.json --compact

The default output is a bounded human-readable summary. Use --json or --compact for the complete analysis document, --format envelope for the canonical cross-format contract, --format cyclonedx for CycloneDX 1.7, or --format sarif for OASIS SARIF 2.1.0. --policy-output records a deterministic finding gate when --fail-on is selected.

verify fails closed on interface contradictions, diff preserves the canonical multi-target TFLite delta ledger, and explore exposes deterministic WASM Pareto candidates. These commands do not add a second analysis engine.

The package contains one generated JavaScript analysis bundle and the canonical TFLite WebAssembly module. It does not send model bytes or results over the network. TensorRT parser observations and build profiles can be imported with --tensorrt-parser-evidence and --tensorrt-profile.

ONNX external data next to the model is discovered only from safe serialized references. Use --external-data-dir to bind a different explicit root. ExecuTorch PTE audits use the same option for PTD data; --executorch-build binds a duplicate-key-checked selected-build and binary inventory without promoting it to observed execution. Core ML packages and sharded SafeTensors repositories are hashed as canonical multi-file artifact sets rather than collapsed to one unqualified file hash.

Static provider/delegate placement remains predicted or conditionally eligible unless an identity-bound runtime or parser observation is imported.

This public channel package is licensed under Apache-2.0. Protected analyzers and private rulepack-generation sources are not included.