{"_id":"@0xrama/bnpm","_rev":"5-aa36e1bdd54af539efdc69ecc2b5cd39","name":"@0xrama/bnpm","dist-tags":{"latest":"0.0.3"},"versions":{"0.0.1":{"name":"@0xrama/bnpm","version":"0.0.1","_id":"@0xrama/bnpm@0.0.1","maintainers":[{"name":"0xrama","email":"rama@0xrama.com"}],"bin":{"bnpm":"dist/src/cli.js","bnpmx":"dist/src/cli.js"},"dist":{"shasum":"74e485a04e8d7cf1756a5849cf541ec9d816c5e5","tarball":"https://registry.npmjs.org/@0xrama/bnpm/-/bnpm-0.0.1.tgz","fileCount":204,"integrity":"sha512-xUKH3tHkBsAWF/HH+Hy7DCW9Q1KyRVm1kYSW0fJXFLYiAIy/+AtV6W1pp/JLugV4waZu3ELCpu+7erJ494lrxQ==","signatures":[{"sig":"MEUCIBLo3jKgYjJAznaPE20zAmSTISj0+Nt2SLjYWDEJvl5wAiEA5xPPysgDb82JzW36VF7xGBme+oEkeT3N9TVD/DiUn0k=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1352873},"type":"module","engines":{"node":">=22.22.2"},"gitHead":"1d062ba0c0bf4e471ad6dab863d4b1b7749ad9bd","scripts":{"test":"npm run build && node --test dist/test/*.test.js","build":"tsc -p tsconfig.json","check":"tsc -p tsconfig.json --noEmit","start":"node dist/src/cli.js","benchmark":"npm run build && node scripts/benchmark.mjs","verify:package":"npm run build && node scripts/verify-package.mjs"},"_npmUser":{"name":"0xrama","email":"rama@0xrama.com"},"deprecated":"Early test release; please upgrade to @0xrama/bnpm@0.0.3 or later.","_npmVersion":"11.16.0","description":"A fast, security-focused npm-compatible package manager","directories":{},"_nodeVersion":"24.18.0","dependencies":{"yaml":"^2.9.0","semver":"7.8.5","node-gyp":"13.0.1","sigstore":"5.0.0","tar-stream":"3.2.0","npm-packlist":"11.3.0","npm-package-arg":"13.0.2"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^7.0.2","@types/node":"^22.0.0","@types/semver":"7.7.1","@types/tar-stream":"3.1.4","@types/npm-package-arg":"6.1.4"},"_npmOperationalInternal":{"tmp":"tmp/bnpm_0.0.1_1784463062726_0.6324532566541716","host":"s3://npm-registry-packages-npm-production"}},"0.0.2":{"name":"@0xrama/bnpm","version":"0.0.2","_id":"@0xrama/bnpm@0.0.2","maintainers":[{"name":"0xrama","email":"rama@0xrama.com"}],"bin":{"bnpm":"dist/src/cli.js","bnpmx":"dist/src/cli.js"},"dist":{"shasum":"e07129c89116d0120ad1eefcffffc83e1f7584d8","tarball":"https://registry.npmjs.org/@0xrama/bnpm/-/bnpm-0.0.2.tgz","fileCount":204,"integrity":"sha512-Qt4C3C4XYUuMcYO8cY9C9jyb9jkHtSCwZNT8mAwXXo4O9LsJnR30zyY4A7vOiN4iLsEVeeN49dRH3ssbZkDybw==","signatures":[{"sig":"MEUCICx3hSjySGkLeZiSPVYLWYI6KOo7F/tv3KefCCjZugadAiEAtjQ0cQw6k9WhscmhhlvVJ1Ta5ZaAsIlSd4KdJfSULrk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1353628},"type":"module","engines":{"node":">=22.22.2"},"gitHead":"7e7c9a9e1c547d07fa6bec6b495853b65a54ead3","scripts":{"test":"npm run build && node --test dist/test/*.test.js","build":"tsc -p tsconfig.json","check":"tsc -p tsconfig.json --noEmit","start":"node dist/src/cli.js","benchmark":"npm run build && node scripts/benchmark.mjs","verify:package":"npm run build && node scripts/verify-package.mjs"},"_npmUser":{"name":"0xrama","email":"rama@0xrama.com"},"_npmVersion":"11.16.0","description":"A fast, security-focused npm-compatible package manager","directories":{},"_nodeVersion":"24.18.0","dependencies":{"yaml":"^2.9.0","semver":"7.8.5","node-gyp":"13.0.1","sigstore":"5.0.0","tar-stream":"3.2.0","npm-packlist":"11.3.0","npm-package-arg":"13.0.2"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^7.0.2","@types/node":"^22.0.0","@types/semver":"7.7.1","@types/tar-stream":"3.1.4","@types/npm-package-arg":"6.1.4"},"_npmOperationalInternal":{"tmp":"tmp/bnpm_0.0.2_1784541607211_0.02127454055443656","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Early test release; please upgrade to @0xrama/bnpm@0.0.3 or later."},"0.0.3":{"name":"@0xrama/bnpm","version":"0.0.3","_id":"@0xrama/bnpm@0.0.3","maintainers":[{"name":"0xrama","email":"rama@0xrama.com"}],"bin":{"bnpm":"dist/src/cli.js","bnpmx":"dist/src/cli.js"},"dist":{"shasum":"29109869786939ccef42a00dd061136c4ffd41de","tarball":"https://registry.npmjs.org/@0xrama/bnpm/-/bnpm-0.0.3.tgz","fileCount":204,"integrity":"sha512-t3ajXCXegrxYA4RowphbJ4m4cLRosH3tMemYbBIxFSgtaZDaiqWKLp7fLL2IGL62IURvm/ou0xj6f3GTZmvxQg==","signatures":[{"sig":"MEUCIQCjTB2mlL/ROHxFw+U421j4we0Z7E8jJHVCadhcPIcx/QIgNIQ/o2BENiT3jv5MSzqGzHC/3a7HmrfkYIADi1zp3Gs=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1356917},"type":"module","engines":{"node":">=22.22.2"},"gitHead":"6e5a4d01e385b3ad6df9f35b085553d233b663fd","scripts":{"test":"npm run build && node --test dist/test/*.test.js","build":"tsc -p tsconfig.json","check":"tsc -p tsconfig.json --noEmit","start":"node dist/src/cli.js","benchmark":"npm run build && node scripts/benchmark.mjs","verify:package":"npm run build && node scripts/verify-package.mjs"},"_npmUser":{"name":"0xrama","email":"rama@0xrama.com"},"_npmVersion":"11.16.0","description":"A fast, security-focused npm-compatible package manager","directories":{},"_nodeVersion":"24.18.0","dependencies":{"yaml":"^2.9.0","semver":"7.8.5","node-gyp":"13.0.1","sigstore":"5.0.0","tar-stream":"3.2.0","npm-packlist":"11.3.0","npm-package-arg":"13.0.2"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^7.0.2","@types/node":"^22.0.0","@types/semver":"7.7.1","@types/tar-stream":"3.1.4","@types/npm-package-arg":"6.1.4"},"_npmOperationalInternal":{"tmp":"tmp/bnpm_0.0.3_1784543992329_0.7090734658103137","host":"s3://npm-registry-packages-npm-production"}}},"time":{"created":"2026-07-19T12:11:02.506Z","modified":"2026-07-20T10:41:54.109Z","0.0.1":"2026-07-19T12:11:02.936Z","0.0.2":"2026-07-20T10:00:07.389Z","0.0.3":"2026-07-20T10:39:52.539Z"},"description":"A fast, security-focused npm-compatible package manager","maintainers":[{"name":"0xrama","email":"rama@0xrama.com"}],"readme":"# Better NPM\n\nBetter NPM (`bnpm`) is an npm-compatible package manager designed for fast installs and explicit supply-chain security decisions.\n\n> Better NPM has a functional alpha command surface. It is not production-qualified yet; review the limitations below before using it for critical projects.\n\n## Install\n\n```sh\nnpm install --global @0xrama/bnpm\n```\n\nThis installs both the `bnpm` and `bnpmx` commands.\n\n## Commands\n\n- `bnpm install [spec...]` resolves and installs dependencies with bounded resolve, fetch/cache, byte-download, inspection, and linking progress; explicit specs are saved by default. Lockfile-only, non-mutating dry-run, and dev/optional/peer omit/include modes are supported.\n- `bnpm ci` recreates the installation exactly from `bnpm-lock.yaml`.\n- `bnpm add <spec...>` updates `package.json` and installs.\n- `bnpm remove <name...>` removes dependencies and updates the installation.\n- `bnpm update [name...]` refreshes all or selected dependencies within declared ranges.\n- `bnpm outdated [name...]` reports current, wanted, and latest versions.\n- `bnpm list [name...]` displays the installed graph; `bnpm why <name>` explains installation paths.\n- `bnpm query <selector>` supports npm-style graph combinators, dependency groups, semver/manifest selectors, registry-enriched outdated and vulnerability filters, and expected-result assertions. `bnpm diff` emits verified unified patches for the local package or two registry, directory, remote-tarball, or secure Git sources with path, context, whitespace, prefix, and name-only controls; `bnpm find-dupes` reports duplicate identities.\n- `bnpm bin`, `bnpm prefix`, and `bnpm root` print local or global installation paths.\n- `bnpm run [--workspaces|--workspace <name>] [script] [-- args...]` lists scripts or analyzes and runs a project, selected workspaces, or every workspace; install mutations accept the same workspace selection and `--if-present` safely skips missing scripts. Scripts receive npm-compatible lifecycle and package environment variables.\n- `bnpm test`, `start`, `stop`, `restart`, `install-test`, and `install-ci-test` provide npm-compatible script workflows.\n- `bnpm audit` combines local static findings with npm registry advisories; `bnpm audit fix` applies safe in-range re-resolution and supports dry-run.\n- `bnpm exec <bin> [-- args...]` runs an installed binary; repeated `--package <spec>` options install inspected packages ephemerally before execution.\n- `bnpm explore <package> [-- command...]` runs a command inside an installed package.\n- `bnpm edit <package>` opens a project-local installed instance and invalidates it for verified replacement on the next install.\n- `bnpm pack [directory]` creates a deterministic npm-compatible tarball; use `--dry-run` or `--pack-destination` as needed.\n- `bnpm publish [directory]` packs and publishes the exact verified artifact with scoped auth, tag, access, OTP, trusted-publisher OIDC, Sigstore provenance, and dry-run support.\n- `bnpm stage` safely publishes, lists, inspects, downloads, approves, or rejects staged artifacts; `bnpm unpublish` handles exact registry removals.\n- `bnpm access`, `owner`, `token`, `star`, `org`, `team`, `profile`, and `trust` expose bounded package and account administration, granular tokens, trusted publishers, passwords, and 2FA. Passwords use masked prompts and are never accepted as CLI operands.\n- `bnpm login`, `bnpm logout`, and `bnpm whoami` manage web authentication, explicit legacy authentication, and identity.\n- `bnpm view`, `bnpm search`, `bnpm dist-tag`, and `bnpm deprecate` provide bounded registry metadata and package-maintenance workflows.\n- `bnpm init`/`bnpm create` creates default packages, safely registers new workspaces, or resolves and executes inspected `create-*` initializer packages with npm-compatible naming and argument forwarding. `bnpm version` runs npm-compatible authoring lifecycles, semantic/prerelease calculation, lockfile synchronization, transactional workspace selection, clean-tree checks, Git commits and tags (or manifest-only mode); `bnpm config` manages safe user settings.\n- `bnpm shrinkwrap` exports the verified registry graph as deterministic npm lockfile v3 data.\n- `bnpm approve-scripts` and `bnpm deny-scripts` explicitly mutate exact lockfile-bound lifecycle approvals.\n- `bnpm prune`, `bnpm dedupe`, `bnpm rebuild`, `bnpm fund`, `bnpm cache add|ls|info|verify|clean`, `bnpm ping`, and `bnpm doctor` maintain and diagnose verified installations, storage, and registry access. Cache cleanup can target one package identity instead of deleting the entire store.\n- `bnpm install-scripts approve|deny|ls|prune` manages exact integrity- and content-hash-bound lifecycle approvals; `approve-scripts` and `deny-scripts` remain concise aliases.\n- `bnpm pkg`, `bnpm sbom`, `bnpm link`/`unlink`, and `bnpm completion` cover manifest updates, software bills of materials, live development links, and shell integration.\n- `bnpmx <spec> [-- args...]` installs and inspects an ephemeral package, gives a decision-first summary of detected execution capabilities across its dependency graph, and requires confirmation before starting it. Use `bnpmx --details <spec>` for raw package and file evidence.\n- `bnpmx check` scans every direct and transitive package recorded for the current project, reports runtime capabilities, lifecycle scripts, static findings, and registry advisories, and never executes package code.\n\nInstall, remove, update, outdated, list, why, audit, exec, bin, and prefix support `-g`/`--global` where applicable. Registry selection supports user/project `.npmrc`, scoped registries, path-scoped bearer/basic credentials, environment expansion, and one-shot `--registry` overrides. Dependency sources include registry packages, workspaces, bare, absolute, or `file:` local directories and package archives (saved canonically as relative `file:` requirements), HTTPS tarballs, and HTTPS/SSH Git repositories and hosted shortcuts, including semver tag selection, package subdirectories, validated recursive submodules, and approved prepare builds.\n\n## Implemented safeguards\n\n- Full-graph recent-publication checks with a first-use 1/6/24-hour policy, mature-version fallback during direct and transitive resolution, and exact non-cascading overrides.\n- Bounded HTTPS metadata/tarball requests, redirects, retries, deadlines, archive sizes, and extraction ratios.\n- Strong integrity verification before safe extraction and content-addressable promotion.\n- Explainable high-confidence static findings for reverse shells, remote payload execution, miners, credential targeting, persistence, destructive commands, and obfuscated process execution.\n- Pre-execution capability disclosure for ephemeral binaries, including AI-session history, credential/config access, network requests, local writes, subprocesses, and opaque native code.\n- Lifecycle approval bound to package version, integrity, stage, command hash, and referenced-content hash.\n- Deterministic lockfile security records, isolated package instances, offline/frozen installs, and interrupted-layout recovery.\n\nApproved lifecycle scripts are **not sandboxed**. They run with the current user's normal operating-system permissions after an exact approval.\n\n## Current limitations\n\n- The implementation is still alpha. Initial live-project, adversarial-archive, concurrency, corruption-repair, and controlled performance checks pass, but the broader production matrix is not complete.\n- The latest controlled isolated-cache fixture puts cold installs in pnpm's range while retaining static inspection; verified warm installs are about twice as fast. Results vary with registry conditions, and larger-project qualification remains incomplete.\n- macOS is the primary development target. Linux and Windows interfaces exist, but neither is advertised as production-qualified.\n- Native-platform release qualification is not complete. Web authentication is the default; password-only registries require the explicit `--auth-type=legacy` flow.\n\n## Principles\n\n- Resolve and install packages without delegating to another package manager.\n- Use a global content-addressable store and isolated symlink layout.\n- Quarantine and inspect package archives before linking them into a project.\n- Never run dependency lifecycle scripts without informed approval.\n- Warn about newly published versions throughout the dependency graph.\n- Produce concrete, explainable findings rather than an opaque risk score.\n\n## Development\n\nRequires Node.js 22.22.2 or newer.\n\n```sh\nnpm install\nnpm run check\nnpm test\nnpm run build\nnpm run benchmark\nnpm run verify:package\nnode dist/src/cli.js --help\n```\n\nSee [`docs/product-spec.md`](docs/product-spec.md), [`docs/threat-model.md`](docs/threat-model.md), [`docs/architecture.md`](docs/architecture.md), and [`docs/releasing.md`](docs/releasing.md).\n","readmeFilename":"README.md"}