{"_id":"@4bhiy/watchtower-core","name":"@4bhiy/watchtower-core","dist-tags":{"latest":"0.1.0"},"versions":{"0.1.0":{"name":"@4bhiy/watchtower-core","version":"0.1.0","private":false,"license":"MIT","type":"module","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"types":"./dist/index.d.ts","scripts":{"build":"tsc -p tsconfig.build.json","prepack":"pnpm run build"},"publishConfig":{"access":"public"},"dependencies":{"fast-glob":"^3.3.3","semver":"^7.7.2","yaml":"^2.8.1","zod":"^3.24.4"},"_id":"@4bhiy/watchtower-core@0.1.0","gitHead":"92e23190d04eceb6eb0a09827ca87cd09d444e0b","description":"`@4bhiy/watchtower-core` is Watchtower's reusable, read-only dependency scanning engine. It contains the normalized data model and the code that turns a local checkout or configured GitHub repository into a scan snapshot.","_nodeVersion":"22.23.2","_npmVersion":"10.9.8","dist":{"integrity":"sha512-B0H5m7MYptfOp3vkAm/WSMfWDuK5ekScJqPaMyV/a6Vw7XuQE3sLqPWrRrWXoIL4cCi8w1betnEFe2mpdmhr2g==","shasum":"5a73a38b884145d6179d57ffd0f2f4ace3dec193","tarball":"https://registry.npmjs.org/@4bhiy/watchtower-core/-/watchtower-core-0.1.0.tgz","fileCount":55,"unpackedSize":196300,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDJ3z06sQSR3QHuewneRvIGU2ZQM3eCS9gMfxNUkh5X4wIhAKU7UmdEBoTX6OKJXQ1X0rgg5X7wgXuV06UA7hBdd2b+"}]},"_npmUser":{"name":"4bhiy","email":"4bhiy23@gmail.com"},"directories":{},"maintainers":[{"name":"4bhiy","email":"4bhiy23@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/watchtower-core_0.1.0_1787937482238_0.5587175494450427"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-28T17:18:02.051Z","0.1.0":"2026-08-28T17:18:02.388Z","modified":"2026-08-28T17:18:02.681Z"},"maintainers":[{"name":"4bhiy","email":"4bhiy23@gmail.com"}],"description":"`@4bhiy/watchtower-core` is Watchtower's reusable, read-only dependency scanning engine. It contains the normalized data model and the code that turns a local checkout or configured GitHub repository into a scan snapshot.","license":"MIT","readme":"# `@4bhiy/watchtower-core`\n\n`@4bhiy/watchtower-core` is Watchtower's reusable, read-only dependency scanning engine. It contains the normalized data model and the code that turns a local checkout or configured GitHub repository into a scan snapshot.\n\nIt does not write history, send notifications, render a dashboard, upgrade dependencies, or open pull requests. Those jobs belong to the packages and apps that consume this one.\n\n## What it owns\n\n- Loading and validating `projects.yml`\n- Acquiring a GitHub repository into a temporary checkout\n- Detecting npm or pnpm and discovering workspaces from repository configuration\n- Reading manifests and lockfiles\n- Separating internal workspace dependencies from external npm dependencies\n- Preserving declared and resolved versions for every workspace usage\n- Enriching dependencies with npm registry metadata, deprecation information, and stable update availability\n- Enriching resolved versions with OSV vulnerability advisories\n- Comparing two normalized snapshots to produce factual change events\n- Zod schemas and TypeScript types shared by every Watchtower interface\n\n## Scanner flow\n\n```text\nconfigured project or local root\n            ↓\nacquire (GitHub only) and detect Node package manager\n            ↓\ndiscover workspaces from pnpm-workspace.yaml or package.json workspaces\n            ↓\nread manifests and classify dependency usages\n            ↓\nresolve external usages from pnpm-lock.yaml or package-lock.json\n            ↓\nenrich with npm registry metadata and OSV advisories\n            ↓\nvalidate and return a Snapshot\n```\n\nThe snapshot aggregates a package once per project while retaining each individual workspace usage. This lets a consumer show a compact project-level view but expand to the workspaces responsible for a version, vulnerability, or mismatch.\n\n## Public API\n\nImport from the package root only:\n\n```ts\nimport {\n  scanNodeProject,\n  scanConfiguredProjects,\n  compareSnapshots,\n  SnapshotSchema,\n  type Snapshot,\n} from \"@4bhiy/watchtower-core\";\n```\n\nThe primary entry points are:\n\n- `scanNodeProject` — scan one already-available local repository.\n- `scanConfiguredProjects` — load a Watchtower project configuration, acquire GitHub sources when needed, and scan every project.\n- `compareSnapshots` — compare a previous snapshot with a current snapshot.\n- `SnapshotSchema`, `ChangesSchema`, and `HistoryIndexSchema` — validate data at package boundaries.\n\n## Consumers\n\n- `apps/cli` calls this package to run local and GitHub Actions scans.\n- `@watchtower/history` persists the returned `Snapshot` and uses `compareSnapshots`.\n- `@watchtower/telegram` formats `Snapshot` and `Changes` into a report.\n- `apps/dashboard` reads the JSON persisted from this model.\n- A future VS Code extension can import this package directly, without duplicating scanner logic.\n\n## Design constraints\n\nKeep this package interface-first and side-effect-light. New ecosystem support should arrive as an adapter that produces the existing normalized model. Features tied to one delivery channel—such as Telegram layout or dashboard state—do not belong here.\n","readmeFilename":"README.md","_rev":"1-a0387e40cf2726eb3aaf57050c5a1f3e"}