10,007 packages matching owns

@noir-ai/daemon

v1.9.1 · 1 hour ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

Noir daemon — the runtime authority: owns the store write handle and exposes the single Noir MCP server (stdio + Streamable HTTP).

1.9KDownloads across all versions in the last 7 days, from the official npm downloads API.MITLicense declared in the package manifest.

No known vulnerabilities

Known vulnerabilities affecting v1.9.1 (the latest release), from the OSV.dev database.

mastra-pharos

v0.6.0 · 22 days ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

pharos — CLI for Mastra's company memory. Ask what happened, who owns what, and what's unresolved.

16Downloads across all versions in the last 7 days, from the official npm downloads API.UNLICENSEDLicense declared in the package manifest.

No known vulnerabilities

Known vulnerabilities affecting v0.6.0 (the latest release), from the OSV.dev database.

@vellumai/vellum-gateway

v0.11.2 · 2 days ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

Standalone service that serves as the public ingress boundary for all external webhooks and callbacks. It owns Telegram integration end-to-end, routes Twilio voice webhooks, handles OAuth callbacks, and acts as an authenticated reverse proxy for the assis

23.9KDownloads across all versions in the last 7 days, from the official npm downloads API.MITLicense declared in the package manifest.

No known vulnerabilities

Known vulnerabilities affecting v0.11.2 (the latest release), from the OSV.dev database.

@modular-react/journeys

v1.10.0 · 17 days ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

Typed, serializable workflows that compose multiple modules. A journey declares entry/exit transitions between modules and owns shared state; modules stay journey-unaware.

1.8KDownloads across all versions in the last 7 days, from the official npm downloads API.

No known vulnerabilities

Known vulnerabilities affecting v1.10.0 (the latest release), from the OSV.dev database.

@vitest-agent/plugin

v2.0.13 · 3 days ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

Vitest plugin for the vitest-agent ecosystem: owns persistence, classification, baselines, trends, and dispatches rendering to a configurable reporter.

756Downloads across all versions in the last 7 days, from the official npm downloads API.MITLicense declared in the package manifest.

No known vulnerabilities

Known vulnerabilities affecting v2.0.13 (the latest release), from the OSV.dev database.

@nifrajs/auth

v2.8.2 · 2 days ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

Session primitives for nifra - signed-cookie + server-store sessions, CSRF, and route guards. Bring your own identity (Better Auth / Lucia / OAuth); nifra owns the session.

1.3KDownloads across all versions in the last 7 days, from the official npm downloads API.MITLicense declared in the package manifest.

No known vulnerabilities

Known vulnerabilities affecting v2.8.2 (the latest release), from the OSV.dev database.

@shipfox/api-integration-jira

v12.2.0 · 18 hours ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

This package owns Jira provider persistence and token storage. The provider is non-functional until ENG-1001 adds the OAuth install flow.

586Downloads across all versions in the last 7 days, from the official npm downloads API.MITLicense declared in the package manifest.

No known vulnerabilities

Known vulnerabilities affecting v12.2.0 (the latest release), from the OSV.dev database.

@excitedjs/feishu-channel

v4.1.1 · 10 days ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

Built-in Feishu ChannelProvider package for Dreamux (alias builtin:feishu). Owns Feishu channel session logic, inbound normalization, access/trust, and MCP tool backing on top of @excitedjs/feishu-transport; depends on @excitedjs/dreamux-types + @excitedj

2.2KDownloads across all versions in the last 7 days, from the official npm downloads API.MITLicense declared in the package manifest.

No known vulnerabilities

Known vulnerabilities affecting v4.1.1 (the latest release), from the OSV.dev database.

@burnt-labs/abstraxion-js

v1.0.0-alpha.2 · 7 days ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

The framework-agnostic runtime for XION account abstraction. Owns the per-mode auth state machine, controllers, strategies, and signing clients — with no React, no DOM, and no platform assumptions baked in.

1.9KDownloads across all versions in the last 7 days, from the official npm downloads API.MITLicense declared in the package manifest.

No known vulnerabilities

Known vulnerabilities affecting v1.0.0-alpha.2 (the latest release), from the OSV.dev database.

peaks-loop-doctor

v0.0.12 · 15 days ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

Doctor check orchestration for peaks-loop — owns the runDoctor probe-driven check pipeline (slice 3b).

20Downloads across all versions in the last 7 days, from the official npm downloads API.MITLicense declared in the package manifest.

No known vulnerabilities

Known vulnerabilities affecting v0.0.12 (the latest release), from the OSV.dev database.

@archon-research/charting

v0.8.0 · 3 days ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

Token-aware charts for UIKit consumer applications, built as a thin layer over [visx](https://github.com/airbnb/visx). UIKit owns the visual language (design tokens); visx owns the rendering mechanics. See [DESIGN.md](./DESIGN.md) for the full contract.

706Downloads across all versions in the last 7 days, from the official npm downloads API.

No known vulnerabilities

Known vulnerabilities affecting v0.8.0 (the latest release), from the OSV.dev database.

@mmmnt/feat-emit-ts

v0.1.8 · 14 days ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

Feat emit: TestTopology + resolved schemas/goldens -> complete deterministic Vitest test file (ADR-0006 header, ADR-0001 inlining). Owns no runtime code.

49Downloads across all versions in the last 7 days, from the official npm downloads API.MITLicense declared in the package manifest.

No known vulnerabilities

Known vulnerabilities affecting v0.1.8 (the latest release), from the OSV.dev database.

@agenticprimitives/agreements

v0.0.0-alpha.18 · 4 days ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

Commitment-only AgreementRegistry SDK. Owns AgreementCredential shape (PD-22) + commitment math + bilateral status transitions + joint-assertion gateway.

81Downloads across all versions in the last 7 days, from the official npm downloads API.MITLicense declared in the package manifest.

No known vulnerabilities

Known vulnerabilities affecting v0.0.0-alpha.18 (the latest release), from the OSV.dev database.

tsumugu-theme-default

v0.9.0 · 4 days ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

The default Tsumugu theme. Renders Semantic AST nodes as accessible, readable HTML with a stylesheet it owns.

1.7KDownloads across all versions in the last 7 days, from the official npm downloads API.MITLicense declared in the package manifest.

No known vulnerabilities

Known vulnerabilities affecting v0.9.0 (the latest release), from the OSV.dev database.

@voyant-travel/admin-host

v0.83.0 · 4 days ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

Generic host primitives for a Voyant admin frontend. It owns selected-graph presentation and workspace composition, TanStack Start policy, static-asset serving, and the SSR handler. Product routes, providers, and styles belong to a distribution such as `@

5.5KDownloads across all versions in the last 7 days, from the official npm downloads API.Apache-2.0License declared in the package manifest.

No known vulnerabilities

Known vulnerabilities affecting v0.83.0 (the latest release), from the OSV.dev database.

@couch-kit/display

v0.4.0 · 10 days ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

Browser display host for cross-network Couch Kit games — owns the authoritative runtime and bridges it to a game-agnostic relay

317Downloads across all versions in the last 7 days, from the official npm downloads API.MITLicense declared in the package manifest.

No known vulnerabilities

Known vulnerabilities affecting v0.4.0 (the latest release), from the OSV.dev database.

@uzolab/skillhub

v0.14.0 · 10 days ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

SkillHub — npm for agent skills: publish, review, and sync SKILL.md packages from registries your team owns.

196Downloads across all versions in the last 7 days, from the official npm downloads API.UNLICENSEDLicense declared in the package manifest.

No known vulnerabilities

Known vulnerabilities affecting v0.14.0 (the latest release), from the OSV.dev database.

@nseng-ai/sdk

v0.1.4 · 22 days ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

`@nseng-ai/sdk` owns the `ns` CLI host and the `@nseng-ai/sdk` author API for command-contributing extensions. It owns command discovery, precedence, selected-command loading, argument/schema parsing, rendering glue, completion plumbing, shell integration

10Downloads across all versions in the last 7 days, from the official npm downloads API.

No known vulnerabilities

Known vulnerabilities affecting v0.1.4 (the latest release), from the OSV.dev database.

@capxul/sdk-react

v1.0.0-alpha.22 · 15 days ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

The React projection over `@capxul/sdk`. It owns provider lifecycle, TanStack Query bindings, cache invalidation, and React-friendly error state while the Core SDK remains the domain and transport boundary.

29Downloads across all versions in the last 7 days, from the official npm downloads API.UNLICENSEDLicense declared in the package manifest.

No known vulnerabilities

Known vulnerabilities affecting v1.0.0-alpha.22 (the latest release), from the OSV.dev database.

@git-stacks/service

v0.21.0-rc.1 · 22 days ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

The Node.js interactive authority for git-stacks. It owns revisioned projections, typed operations, events, signals, filesystem reconciliation, native-keyring/protected-fallback identities, signed certificate rollover, pinned WebTransport, directly truste

16Downloads across all versions in the last 7 days, from the official npm downloads API.MITLicense declared in the package manifest.

No known vulnerabilities

Known vulnerabilities affecting v0.21.0-rc.1 (the latest release), from the OSV.dev database.