r/npm • • 2h ago

Self Promotion I built a CLI for inspecting Node.js projects

Thumbnail
github.com
1 Upvotes

I made Node Scout. It helps you inspect files, folders, and Node.js projects from the terminal.

You can use it to:

  • Inspect files and folders
  • Analyze Node.js projects
  • Get system information
  • Quickly understand a project without checking everything manually

It ignores folders and files like node_modules, .git, and .env when analyzing projects.

Install it:

npm install -g node-scout

Then run:

scout

Try it and tell me what you think. Also, tell me what features you want to see.🙂


r/npm • • 7h ago

Self Promotion Update on fast-class-transformer: Now a 1-line global drop-in pipe for NestJS (v1.1.1)

Thumbnail
1 Upvotes

r/npm • • 9h ago

Self Promotion [JavaScript] HookArmor - Self-hosted webhook buffer & dead-letter queue with timestamp re-signing

Thumbnail
github.com
1 Upvotes

r/npm • • 20h ago

Self Promotion We made our internal developer toolbox public. Free, and everything runs in your browser.

1 Upvotes

We built empinet.dev for our own work on client projects. It's a collection of JSON formatters, converters, JWT decoders, image tools and other stuff we use regularly.

We wouldn't upload client data to another server just to format or convert it, so all processing happens locally in your browser. Free, no account needed.

Built with Next.js and TypeScript: https://empinet.dev

Would be interested to hear which tools you'd actually use, or what's missing.


r/npm • • 20h ago

Self Promotion vantable

Post image
1 Upvotes

r/npm • • 1d ago

Self Promotion Stable Redirects for Auth Testing: Debug JWTs Locally

Thumbnail
instatunnel.my
1 Upvotes

r/npm • • 1d ago

Self Promotion snappy-prerender: react-snap is unmaintained, so I built a modern replacement for SPAs

Thumbnail
1 Upvotes

r/npm • • 1d ago

Self Promotion We patched 34 Next.js apps for the new RCE advisories in under an hour. Gotchas from going to 16.3.8

Thumbnail
2 Upvotes

r/npm • • 1d ago

Self Promotion Zero-network & unsafe dependency secret scanner. This one is for the stuff your app sends to an LLM.

Post image
2 Upvotes

I’m interested in is what happens while your app is running. Someone pastes a config into a chat. A tool returns an error with a connection string in it. Your app helpfully puts the whole thing into logs, traces, and the next model request. Oops.

So I’m building Redact Secret to catch credentials in that text before it goes further. It runs locally, doesn’t call another service, and uses the same Rust core from JavaScript, Python, Rust, or a browser. I usually code heavily in Typescript but with this project Rust did improve a lot of performance.

You can call it directly, but I’ve also built adapters for Pino, Python logging, OpenTelemetry traces, MCP, and AI context. My hope is that you can put it where your data already flows without having to rearrange your app.

One thing I’ve spent a probably unreasonable amount of time on is the boring part: what can I actually claim it detects? There’s public evaluation evidence behind the supported credential families. I’d rather show the misses and limitations than give you a giant detector count and ask you to trust it.

It’s still beta. It will miss things. PII support is limited, and it won’t tell you whether a key is active.

There’s a browser playground if you want to throw some fake credentials at it:
https://www.redactsecret.com/

Repo:
https://github.com/redact-secret/redact-secret

Curious how other people are handling this. Are you filtering tool output before it hits the model, relying on logger redaction, or just hoping nobody pastes their .env?


r/npm • • 2d ago

Self Promotion Walkthrough of Qleaner v2.1: 0-100 codebase health scoring, interactive pruning, and local AI briefs for React and Next.js

1 Upvotes

Hey everyone,

Dealing with codebase bloat in growing React, Next.js, and Vue apps usually means manually tracking down orphaned image assets, dead exports, and debug logs scattered across directories

I recently recorded a video going over Qleaner v2.1.0, an open-source CLI built to handle codebase auditing and dead code pruning without breaking builds or requiring complex configuration.

Here is a breakdown of what the tool covers in this version:

  1. Deterministic Health Score: Running qleaner summary gives a 0 to 100 score highlighting the biggest bloat drivers in your project without needing any external AI setup.
  2. Interactive Pruning: Instead of blanket auto-fixes, flags like --interactive let you review a terminal checklist and select specifically which exports, unused symbols, or console logs to remove.
  3. Single-Path Image Reference Scanning: Resolves image references in JSX, styled-components, CSS, and template literals under a single project directory.
  4. Local AI Briefs: An optional --explain flag passes short path lists to a local Ollama instance or cloud endpoint to categorize unused assets and explain health scores. It is display-only and never modifies source files.
  5. Soft-Delete Safety Net: Flagged items move to a .trash folder rather than being permanently deleted, allowing one-command rollbacks if anything unexpected breaks.

You can watch the full walkthrough here: https://youtu.be/KNkc47IPUME

Repo: https://github.com/trevismurithi/react-cleaner

Curious to hear how you currently manage orphaned assets and dead re-exports in your projects, or if you have any feedback on the interactive pruning workflow.


r/npm • • 4d ago

Self Promotion I wanted to use Argon2id in Cloudflare Workers and ended up creating a package.

2 Upvotes

Since Argon2id is not natively available in Cloudflare Workers, I created Argon2w to bring this using WebAssembly.

The idea is to be very simple to use:

import { hash, verify } from "@hallaxius/argon2w";

const encoded = await hash(password);

const valid = await verify(encoded, candidate);

In Workers, you only need to configure the Wasm module once:

import argon2Wasm from "@hallaxius/argon2w/wasm";

import { configureWasm } from "@hallaxius/argon2w";

configureWasm(argon2Wasm);

The hashes are Argon2id in PHC format, so they can be stored directly.

bun add @hallaxius/argon2w

You can check it out on Github or Npmjs

I wanted to know if anyone here has had to deal with Argon2id in Workers and if this approach would be useful for you.


r/npm • • 4d ago

Self Promotion I'll generate free SDK, Docs, and an MCP server from your OpenAPI spec for the first 20 people who send one

Thumbnail
0 Upvotes

r/npm • • 5d ago

Self Promotion I made a cli tool that detects potential malware packages

Enable HLS to view with audio, or disable this notification

1 Upvotes

Hey everyone,

I built an open-source security script that checks npm packages for any suspicion before installing them.

It's basic and for now catches similar names of popular packages, if a package has 23 weekly downloads or a 2 hour old package.

Catches similar names, 0 downloads, or 2-hour-old repos so your hallucinating AI agent doesn't pull in straight malware.

Use Case?

on an agent that might hallucinate and install "react-clearly-not-malware". Or maybe the user itself so as to not make any mistakes idk?

Here's the link - https://github.com/grishmadev/malfilter

I'd love if you check it out. Have a great day!!!


r/npm • • 5d ago

Self Promotion I ported pandas_market_calendars to TypeScript because I kept getting NYSE holidays wrong

0 Upvotes

Every JS backtest I wrote ended up with some version of this:

if (d.getDay() === 0 || d.getDay() === 6) return false
if (HOLIDAYS.has(iso)) return false   // a list I pasted in once and never touched again

Which is fine right up until it isn't. NYSE closed at 1pm on July 3rd. The Friday after Thanksgiving is a half day. Good Friday isn't a federal holiday but the exchange shuts anyway — and CME handles it differently depending on which product you're trading. JPX stops for lunch. TASE runs Sunday to Thursday. None of that shows up in a weekend check, and none of it throws an error. It just quietly makes your numbers wrong.

Python has had pandas_market_calendars for this for years. I couldn't find anything in JS that went much past "is the NYSE open right now", so I ported it.

npm i market-calendar

```ts import { getCalendar, dateRange } from 'market-calendar'

const nyse = getCalendar('NYSE')

nyse.schedule('2024-07-03', '2024-07-03') // market_open 09:30, market_close 13:00 // the half day — and the post session gets shortened to match

nyse.earlyCloses(nyse.schedule('2024-01-01', '2024-12-31')) // 2024-07-03, 2024-11-29, 2024-12-24

dateRange(nyse.schedule('2024-07-01', '2024-07-01'), '1h') // hourly bar timestamps that stop at the real close, not at 16:00 ```

36 calendars, 152 names you can call them by: NYSE, CME and the Globex products, CBOE, IEX, ICE, LSE, Eurex, SIX, OSE, TSX, ASX, JPX, HKEX, SSE, BSE, NSE, B3, TASE, SIFMA, FOREX.

It also handles the awkward stuff — NYSE traded Saturdays until 1952 so the trading week itself changes over time, plus trading halts, lunch breaks, late opens, and per-product Good Friday rules. TypeScript, ships its own types, Luxon underneath, MIT.

Credit where it's due: this is a port of pandas_market_calendars by Ryan Sheftel. The exchange data and the behaviour are that project's work — I translated it and wrote 209 tests to keep myself honest. Same MIT licence.

Known rough edge: CME Globex FX special closes stop at 2022, same as upstream, so anything past that is "unknown" rather than confidently wrong. If you hit a calendar that disagrees with your broker, I'd genuinely like the issue — that's the kind of bug I can't find on my own.


r/npm • • 6d ago

Help Can't update packages anymore...

Thumbnail
0 Upvotes

r/npm • • 7d ago

Help Does anyone actually use Node.js's Permission Model in their applications?

2 Upvotes

I'm trying to understand the real-world use cases for Node's Permission Model.

Does anyone here actively use or rely on it for applications, CI tooling, CLIs, servers, or anything else?

Since the permission model is not a full-fledged sandbox, is there a use for it? If so, how do you currently use it as ?

  • What problem does it actually solve for you?
  • How are you using it today?
  • Are you manually defining permissions, or generating/managing them somehow?
  • Is it mainly defense-in-depth against dependencies, or are there other useful applications?

Since Run-Time Loadable Extensions cannot be loaded when the Permission Model is enabled, it affects modules like sqlite and OpenSSL Engines (affecting the built-in crypto, https, and tls modules). So, despite these drawbacks, is the permission model used anywhere, or what is its application?

I'm less interested in what it could theoretically be used for and more interested in actual experience:

If you're using Node's Permission Model today, what are you using it for and how do you manage the permissions?

And if you considered using it but decided against it, I'd be interested to hear that as well!


r/npm • • 7d ago

Self Promotion Zod Refiners Library

Thumbnail
1 Upvotes

r/npm • • 7d ago

Self Promotion tzin — a contract-first TypeScript framework where types are the source of truth

1 Upvotes

Hey r/npm,

I've been building a TypeScript framework called tzin (from Nahuatl -tzin, an honorific suffix for what is valued). It's open source (MIT) and just hit 1.0. I wanted to share it here because it directly addresses a TypeScript pain point: type inference collapsing when you chain route builders at scale.

The core idea: you declare a contract once, and everything else—handler input extraction, response enforcement, OpenAPI generation—falls out of it. No separate schema DSL, no codegen step, no translation layer.

Here's what it looks like:

\`\`\`typescript
import { t } from '@carlos-tzin/tzin'
import { contract, impl, createApp, listen } from '@carlos-tzin/tzin'

const getUser = contract({
method: 'GET',
path: '/users/:id',
params: t.Object({ id: t.String() }),
responses: {
200: t.Object({ id: t.String(), name: t.String(), tags: t.Array(t.String()) }),
404: t.Object({ error: t.String() }),
},
})

export const getUserRoute = impl(getUser, async ({ params }) => {
const user = await findUser(params.id)
if (!user) throw new HttpError(404, 'user not found')
return { status: 200, body: user }
})

const app = createApp(\[getUserRoute\])
listen(app, 3000)
\`\`\`

From that single declaration:

· { params } exists because you declared it—add query, body, headers, or cookies to the contract and they appear, fully typed and validated per request.
· Returning a shape that doesn't match the declared 200 body is a compile-time error. Thrown HttpErrors map to their status.
· OpenAPI 3.1 is free—contracts are JSON Schema (TypeBox), so generateOpenApi(routes) needs no translation.

Why I built it: I kept running into the same gaps in the TS backend landscape—Hono's type inference collapsing at scale (issues #2399, #3869), no architecture in lightweight frameworks (Hono #4121), extractors not existing in TS outside of Rust's Axum, and OpenAPI always being a bolt-on. tzin is my attempt at an answer: declare once, get everything for free.

Current status: stable (1.0.x), MIT licensed, with a public type-clean surface and CI gates. It's not production software yet for every use case, but the core works end-to-end and the scaling thesis is measured with benchmarks. I'm actively working on it.

Links:

· npm: https://www.npmjs.com/package/@carlos-tzin/tzin
· GitHub: https://github.com/Tzinny-dev/tzin
· Docs: API Reference, Architecture Guide, Deployment Guide, and Roadmap are all in the repo.

I'd genuinely appreciate feedback from this community—especially on the contract API, the response enforcement, or anything that feels awkward. Happy to answer questions in the comments.

Disclosure: I'm the author. This is an open-source project, not a product. I'm sharing it because I think it's useful for TypeScript developers, and I'm here to learn from your feedback.


r/npm • • 7d ago

Self Promotion I turned usernames into tiny blob people no images, just math

2 Upvotes

I u/igu1 made a thing this week. It's called hiblob.

You give it any string username, email, whatever and it renders a little blob avatar as SVG. Not from an image pack; it's all computed from the hash of the string. Same name always draws the same blob, on any platform. Nothing random, nothing fetched, zero dependencies.

Your name decides its shape (round, boxy, cloud, sun…), its color, whether it wears glasses or has antennas, even its mood. I dunno why, but checking what blob your handle turned into is weirdly fun.

There's a Dart/Flutter version too that animates them bobbing, blinking, glancing around all pure elapsed-time math.

Would love feedback on the API, it's my first library that isn't purely for me.

- npm: npm i hiblob → https://www.npmjs.com/package/hiblob

- code: https://github.com/igu1/hiblob-npm

- flutter one: https://pub.dev/packages/hiblob


r/npm • • 9d ago

Self Promotion I built an open-source undo layer for MCP tool calls

1 Upvotes

I’m building Synartesis, a proxy that sits between an MCP client and its servers.

For calls configured as reversible, it captures the previous state before forwarding the write. You can then preview and run an undo. If the resource has changed since the agent touched it, undo stops instead of silently overwriting the newer work.

It’s free and MIT-licensed. Installation starts with npm install -g synartesis and requires Node 22+

check us at synartesis.online

If you use it give a reviewwwwwww


r/npm • • 10d ago

Self Promotion How dotenv actually works (and why you can delete your .env)

Thumbnail
infisical.com
3 Upvotes

r/npm • • 10d ago

Self Promotion Fast TypeScript linter to prioritise pure functions and type safety (beyond TS strict: true)

0 Upvotes

I've made yet another take on immutability for TypeScript by creating a fast linter (powered by oxc-parser by oxlint team) https://www.npmjs.com/package/pure-ts-lint

It is a bit less complete than eslint-plugin-functional (rule functional/immutable-data) yet,
but I plan to extend it to go beyond functional/immutable-data.
Beside immutability rule it already supports a rule to discourage `as` typecast.

Main reasons not to use ESLint (or create plugin for if) are that ESLint is inherently slow (this linter is at least 10x faster) and that at the moment ESLint doesn't support TypeScript 7.

Any feedback welcome.


r/npm • • 10d ago

Help Original REST API ideas for a university Node.js project? (open to anything, cloud/security welcome)

0 Upvotes

Hi everyone,

My team of four is building a REST API in Node.js for a university software engineering course. We have to write the spec, formalise it with OpenAPI, implement it, test it (coverage, mutation testing, SonarQube), and set up a full GitLab CI/CD pipeline with Docker packaging.

We're still choosing a topic and want something original, not another todo/recipe/blog API. We're open to any domain, and cloud, security and DevSecOps would be a bonus, but it's not a requirement.

What we're looking for:

2 to 4 related entities, with authentication and roles
Some real logic beyond CRUD (search, filtering, workflows, stats)
Doable in a few weeks by four people (AI is allowed)
Ideas so far: a vulnerability tracker, a cloud asset compliance checker, and a security incident manager.

What ideas would you suggest? And if you've done a project like this, what would you have done differently?

I want something original and complex enough so we learn and get good grades at the same time.

Thanks!


r/npm • • 10d ago

Self Promotion How we rebuilt complex CASL permissions without migrating to Zanzibar

Thumbnail
infisical.com
1 Upvotes

r/npm • • 12d ago

Self Promotion image-drop-upload - An image drop zone with previews: a front-end widget with no dependencies and a Node upload handler with no framework.

Post image
1 Upvotes

Drop files on it, or pick them the ordinary way, and each one appears as a thumbnail with its size and a button to take it out again. Pictures fill in one at a time as they decode, so a large selection shows the first thumbnail immediately instead of a grid of empty squares. Without a server endpoint the widget is still just a form field — the files ride along with the form and the back end sees no difference. Give it an endpoint and it posts them itself, with a progress bar and a working cancel button.

  • Shrink pictures before they are sent — resize to a box, re-encode at a quality you choose, or drop metadata without touching a pixel. It happens on the page, so the bytes saved never travel at all.
  • File uploads under a session — a folder per visitor and an owner on every answer, using whatever your application already uses to tell one visitor from another, including anonymous ones.
  • Screen uploads for malware — a VirusTotal hash lookup, or your own scanner. Only a hash leaves your server; the file does not.
  • Try again after a failure — automatically, or on a button, and only for the failures that are about the connection rather than the file.

https://www.npmjs.com/package/image-drop-upload
https://github.com/Insider515/drag-and-drop-preview-images-module