npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

tupass

v0.2.0

Published

A terminal UI for GNU pass (the standard unix password manager), built with OpenTUI.

Downloads

23

Readme

tupass

A fast, keyboard-driven terminal UI for GNU pass - the standard unix password manager - built with OpenTUI and React.

Browse your store as a collapsible tree, decrypt on demand, copy to the clipboard (auto-clearing), generate passwords, manage OTP codes, and rename/move/duplicate entries - all without leaving the terminal. It themes itself from your terminal palette and ships a dozen bundled color schemes with a live picker.

tupass

Features

  • Tree browser - collapsible folders, windowed for large stores, fuzzy filter (/).
  • Lazy decryption - entries are only decrypted when you open them; the rest is instant.
  • Clipboard - copy the password or a specific field via pass -c (auto-clears after 45s).
  • OTP - generate TOTP codes for entries (requires the pass-otp extension).
  • Full CRUD - add, edit, generate, rename (in place), move (folder picker), duplicate, delete.
  • Git - one-key sync (pull --rebase + push) and recent-log view for git-backed stores.
  • Theming - auto-detects your terminal colors, plus bundled schemes (Catppuccin, Dracula, Tokyo Night, Nord, Gruvbox, Rosé Pine, Kanagawa, Everforest, Solarized, GitHub Light…) switchable live with t. Your choice persists.
  • Responsive - side preview pane on wide terminals; on narrow ones it collapses to a single-column list with each entry's details expanding inline.

Requirements

  • Bun (runtime + package manager)
  • pass with an initialized store (pass init <gpg-id>)
  • gpg + gpg-agent - a graphical pinentry (gtk/qt/gnome) is recommended; a TTY pinentry can conflict with the full-screen UI on first unlock
  • Optional: the pass-otp extension for OTP codes
  • A terminal with truecolor and a Nerd Font (icons + glyphs)

Install

tupass runs on Bun - OpenTUI uses bun:ffi for its native renderer, so Node is not supported. The tupass command is a tiny launcher that runs on your installed Bun; no runtime is bundled.

Install globally (Bun fetches the right native renderer for your platform):

bun add -g github:d7omdev/tupass

Then just run:

tupass

From source

git clone https://github.com/d7omdev/tupass
cd tupass
bun install
bun link          # puts `tupass` on your PATH (runs via your Bun)
# or run without linking:
bun run dev

If no store exists at ~/.password-store, tupass exits with instructions to run pass init.

Desktop entry

A launcher and lock icon live in docs/. Install them to get a tupass app entry (opens in a dedicated kitty window with WM_CLASS=Tupass):

install -Dm644 docs/tupass.svg ~/.local/share/icons/hicolor/scalable/apps/tupass.svg
install -Dm644 docs/tupass.desktop ~/.local/share/applications/tupass.desktop
update-desktop-database ~/.local/share/applications 2>/dev/null || true
gtk-update-icon-cache ~/.local/share/icons/hicolor 2>/dev/null || true

Or just launch it directly:

kitty --class Tupass --title tupass tupass

Keybindings

| Key | Action | |-----|--------| | ↑ ↓ / j k | move selection | | → / l / space | expand folder · open entry | | ← / h | collapse folder · jump to parent | | enter | open entry (decrypt) / toggle folder | | s | reveal / hide password | | c | copy password to clipboard (auto-clears) | | C | copy a specific field (login/url…) | | o | generate & copy OTP code | | a / n | add entry inside the current folder · A adds at the root | | g | generate a password | | e | edit entry | | r | rename file/folder in place (folder locked) | | M | move to another folder (pick or create) | | p | duplicate entry | | d | delete entry | | / | fuzzy filter | | t | switch color theme (live preview) | | E / W | expand all / collapse all | | G / L | git sync / git log | | ? | toggle help | | q / Ctrl+C | quit |

Configuration

| Variable | Purpose | |----------|---------| | PASSWORD_STORE_DIR | location of the store (default ~/.password-store) | | PASSWORD_STORE_CLIP_TIME | clipboard auto-clear seconds (honored by pass, default 45) | | TUPASS_NO_OSC | set to disable terminal-palette detection (for terminals that leak the OSC reply) |

The selected theme is saved to ~/.config/tupass/config.json (honors XDG_CONFIG_HOME).

Development

bun run validate   # typecheck + lint
bun run typecheck
bun run lint

Security

tupass never sees your passphrase - decryption is delegated to gpg/gpg-agent, and all entry names are passed as discrete argv (never interpolated into a shell), so a name like $(rm -rf ~) is inert.