npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

oxcgen

v0.2.0

Published

Oxc/Oxlint generation adapter with safety corrections and explicit validation gates; not production-ready.

Readme

oxcgen

Generate and normalize TypeScript and JavaScript through native Oxc/Oxlint policy before publishing source. Authored implementation files are TypeScript (.ts and .mts). Oxc builds the installable JavaScript into lib/.

Local use

bash scripts/bootstrap-local.sh
./dev npm run docs:preview

Bootstrap already runs release validation and installed-consumer checks. Node 24.20.0 is selected by ./dev. The native build uses pinned Oxc Rust and TypeScript-Go sources; revisions, archive checksums, Cargo.lock and go.sum are retained. package-lock.json owns the actual npm dependency tree. Keep vendor/ with source checkouts: the pinned Pi development dependency installs from a local tarball with the corrected AI dependency bundled. See LOCAL_SETUP.md and vendor/README.md; ./dev npm ci is the dependency-only reinstall command once the runtime is selected.

Generation

import { createOxcgen } from 'oxcgen';
const project = await createOxcgen({ cwd: process.cwd() });
try {
  await project.generate({
    files: [{ path: 'src/answer.ts', construction: {
      declarations: [{ kind: 'const', name: 'answer', type: 'number', value: 42 }],
    }}],
    publish: true,
  });
} finally {
  await project.close();
}

The built-in normalizers handle typescript/no-floating-promises, typescript/no-unsafe-assignment, and import/no-cycle. Semantic choices require explicit intent: awaiting a promise, introducing an unknown boundary or runtime validator, or permitting a proven type-only import. Other rules remain native acceptance constraints. Invalid candidates are rejected before publication.

Rust resolves effective per-file policy using the pinned initialized Oxlint implementation, including external JavaScript plugin options and provenance. The persistent Go host owns checked TypeScript programs and bounded type queries for immutable snapshot epochs. The verifier checks unchanged consumers alongside changed files, including creation and deletion overlays. No JavaScript TypeScript checker is used for generation; TypeScript 6 is a development dependency for Blume.

React compilation runs before lowering for the project's React 19 scope. Authored TSX and compiled JSX are separate artifacts. Compiled bytes must pass .oxlint.compiled.config.ts before they are returned as policy-verified artifacts. Verification sees accepted authored snapshot overlays, including new/deleted dependencies. Module-level React accounting is retained; per-function outcomes and recoverable bailouts are unavailable in the pinned NAPI.

inspect() returns version/hash/epoch-bound AST, native type facts, program membership and import graph sections. Queries require the prior snapshot identity; AST pagination limits returned projections, not pre-construction AST memory.

Publication and agents

Publication uses expected hashes, a cooperative lock and durable transaction journals. recoverPublications({cwd}) rolls back an interrupted transaction and refuses conflicting later edits. Visibility is per-file rename, not globally atomic across multiple files.

runRestrictedAgent provides OS-enforced project write restrictions on macOS and Linux (Landlock ABI 3+). Its JSONL broker allows publication only through generation and verification. Merely setting required mode or installing AGENTS.md does not restrict unrelated editors or agents. Enforcement is explicitly launched.

The Pi extension routes managed edit/write candidates and retains verification reports. Required-mode reports reuse publication receipts and edit diffs show normalized published bytes. /lint, /lint list, /lint show <id> and /lint check <literal-path> inspect or refresh reports. These overrides do not intercept shell or arbitrary filesystem writers.

oxcgen mcp serves the same capabilities to any Model Context Protocol host over stdio, as nine tools: oxcgen_doctor, oxcgen_catalog, oxcgen_policy, oxcgen_inspect, oxcgen_verify, oxcgen_facts, oxcgen_generate, oxcgen_publish and oxcgen_recover. Each tool advertises the request schema the engine already validates, so the published manifest cannot drift from the validator. A rejected candidate writes nothing. An MCP server answers its host's requests and cannot veto that host's own write tools, so required mode still depends on the host routing managed writes through oxcgen.

zed/ holds a Zed extension that registers oxcgen as a context server. It bundles nothing: it runs the project's own node_modules/.bin/oxcgen, falling back to PATH. It is not published to Zed's registry; install it as a dev extension.

Evidence

oxcgen is published to npm with optional per-platform binary packages (oxcgen-darwin-arm64, oxcgen-linux-arm64, oxcgen-linux-x64); npm installs only the one matching the consumer's os/cpu. See VALIDATION_STATUS.md. Original failed runs are retained in .oxcgen/local-runs/ when present. Local tests include test doubles; test:integration uses real dependencies. Production docs, browser checks, native benchmarks and the Docker clean-install runner have separate logs. The docs site deploys to GitHub Pages.