npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

rollup-plugin-file-pin

v1.0.2

Published

Fails the build unless a set of files match their pinned hash digests

Readme

rollup-plugin-file-pin

Fails the build unless a set of files match their pinned hash digests. Verification runs before the bundle emits anything, so a silently swapped, corrupted or accidentally regenerated input can never make it into a shipped artifact.

The pins live with the consumer - a map of file path to expected digest - so a legitimate change updates the pin in the same commit that changes the file, and any drift becomes a loud build failure instead of a silent substitution. It is well suited to pinning vendored binaries (wasm/tflite models, prebuilt native assets) whose identity you want to guarantee at build time.

Installation

npm install rollup-plugin-file-pin

Usage

// rollup.config.js
import filePin from "rollup-plugin-file-pin";

export default {
	plugins: [
		filePin({
			pins: {
				"vendor/detection.wasm": "5a7b24f12467b004a3de91c62d5f08c521039568eb335d0d174a3f441d20ee06",
				"vendor/face.tflite":    "b4578f35940bf5a1a655214a1cce5cab13eba73c1297cd78e1a04c2380b0152f"
			}
		})
	]
};

Place it before any plugin that copies or transforms the pinned files, so verification happens first. A mismatch, a missing file or an unknown algorithm throws and fails the build.

Options

| Option | Required | Description | | ----------- | -------- | ----------- | | pins | yes | Map of file path to expected hex digest. A build fails if any file is missing or hashes differently. | | algorithm | no | Hash algorithm applied to every pin - any algorithm node's crypto supports (default "sha256"). | | baseDir | no | Directory the pinned paths are resolved against (default process.cwd()). | | once | no | Verify only once per process, even when a single instance is shared across bundle configs (default true). |

The hashFile(file, algorithm) function is also exported for computing a file's digest outside rollup - useful for producing the pin values in the first place.

Development

npm install
npm test        # vitest
npm run coverage
npm run lint

Security

See SECURITY.md for how to report a vulnerability.

Contributing

Issues and pull requests are welcome on GitHub. The default branch is mirrored from an internal repository; maintainers merge accepted pull requests and the mirror picks them up on the next sync.