{"_id":"@agentic-research/depgraph-collect","_rev":"2-919d1fa542e4e6feb397032afb1bc512","name":"@agentic-research/depgraph-collect","dist-tags":{"latest":"0.2.0"},"versions":{"0.1.0":{"name":"@agentic-research/depgraph-collect","version":"0.1.0","keywords":["dependency-graph","manifest","monorepo","provenance"],"license":"Apache-2.0","_id":"@agentic-research/depgraph-collect@0.1.0","maintainers":[{"name":"jamestexas","email":"jamestexasgardner@gmail.com"}],"dist":{"shasum":"58d0bf86912cb48a8143ba8aea192872d2334a64","tarball":"https://registry.npmjs.org/@agentic-research/depgraph-collect/-/depgraph-collect-0.1.0.tgz","fileCount":15,"integrity":"sha512-zddfgwbBUXjsvbpw1IKTGCC+OAQWnrZDpJD5hZPSO1o16rqewhKouRcXq3g4rKFK9leElXuwliTVvDRArJc3Rg==","signatures":[{"sig":"MEUCIQD+9AUdEcyylEmePCicEEYwt9c2Ci7KheftmoLN1V5VswIgK4lzhQuqMtleBs69LVxTHkSVhi7TocojalBiHSkdk6Y=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":102405},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"scripts":{"test":"pnpm run test:package","build":"rm -rf dist && tsc -p tsconfig.build.json","test:package":"pnpm run build && node -e \"import('./dist/index.js').then(() => console.log('package import ok'))\""},"_npmUser":{"name":"jamestexas","email":"jamestexasgardner@gmail.com"},"repository":{"url":"git+https://github.com/agentic-research/0day-api.git","type":"git","directory":"packages/collect"},"description":"Read what repositories declare — manifests, lockfiles, workflows — into a sources lock the portable core derives from. Node-only, no credential.","directories":{},"_nodeVersion":"25.9.0","dependencies":{"smol-toml":"^1.7.1","@agentic-research/depgraph-core":"0.1.0"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/depgraph-collect_0.1.0_1785443537606_0.6808459742249955","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@agentic-research/depgraph-collect","version":"0.2.0","description":"Read what repositories declare — manifests, lockfiles, workflows — into a sources lock the portable core derives from. Node-only, no credential.","type":"module","main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"dependencies":{"smol-toml":"^1.7.1","@agentic-research/depgraph-core":"0.2.0"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"license":"Apache-2.0","repository":{"type":"git","url":"git+https://github.com/agentic-research/0day-api.git","directory":"packages/collect"},"keywords":["dependency-graph","manifest","monorepo","provenance"],"scripts":{"build":"rm -rf dist && tsc -p tsconfig.build.json","test":"pnpm run test:package","test:package":"pnpm run build && node -e \"import('./dist/index.js').then(() => console.log('package import ok'))\""},"_nodeVersion":"25.9.0","_id":"@agentic-research/depgraph-collect@0.2.0","dist":{"integrity":"sha512-/tx0QBuZs82gIkR1eMvNQiNpzYAQCvAmINZAoJhkc1rNiod2KPzOFI8QVsoU2ILO5KuGeGiDdADC5+g6ZCAdxw==","shasum":"565e79b4b4bec81de60246dff8437ccfd70a92c1","tarball":"https://registry.npmjs.org/@agentic-research/depgraph-collect/-/depgraph-collect-0.2.0.tgz","fileCount":15,"unpackedSize":108126,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDKzqwxCN3BfcAul5QnefuKduBBafOMieaN96SQCvQdHAIhALFX8XM3zg1i3wY/vPryMC3ICgG+8wg/WUDc8DL1SJnT"}]},"_npmUser":{"name":"jamestexas","email":"jamestexasgardner@gmail.com"},"directories":{},"maintainers":[{"name":"jamestexas","email":"jamestexasgardner@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/depgraph-collect_0.2.0_1785461070871_0.05476547082913563"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-30T20:32:17.390Z","modified":"2026-07-31T01:24:31.226Z","0.1.0":"2026-07-30T20:32:17.737Z","0.2.0":"2026-07-31T01:24:31.053Z"},"license":"Apache-2.0","keywords":["dependency-graph","manifest","monorepo","provenance"],"repository":{"type":"git","url":"git+https://github.com/agentic-research/0day-api.git","directory":"packages/collect"},"description":"Read what repositories declare — manifests, lockfiles, workflows — into a sources lock the portable core derives from. Node-only, no credential.","maintainers":[{"name":"jamestexas","email":"jamestexasgardner@gmail.com"}],"readme":"# @agentic-research/depgraph-collect\n\nReading repositories into a sources lock, which\n[`@agentic-research/depgraph-core`](../core) derives the map from. Node-only —\neverything that touches a filesystem, a network or a process lives here so the\ncore does not.\n\n## No credential, deliberately\n\nNothing in this package reads a token or an environment variable for one.\nRepository visibility is established by asking GitHub **unauthenticated**, and\nit fails closed: a repository whose visibility cannot be established is treated\nas private, its manifests are never read, and any edge touching it carries no\ndetail.\n\nThis is a constraint, not an oversight. A graph whose contents depend on who\nauthenticated is not reproducible by anyone else. It is also a bug this code\nhas already had: an earlier version used a token \"if present\", and a\nprivileged run recorded three private repositories as public.\n\nThe cost is the unauthenticated rate limit — sixty requests an hour, one per\nrepository. That is the right trade, and a token cannot buy your way out of it\nwithout reintroducing the bug.\n\n## Membership is yours to supply\n\nThe roster — which repositories the map may name — is an authored judgment, so\nthis package does not discover it. Build a `RosterEntry[]` however your project\nalready records membership and hand it over:\n\n```ts\nimport {\n  entryFromGithub,\n  resolveCheckouts,\n  parseRoots,\n} from \"@agentic-research/depgraph-collect\";\n\nconst roster = resolveCheckouts(\n  [\n    entryFromGithub(\"agentic-research/mache\"),\n    entryFromGithub(\"agentic-research/rosary\"),\n  ],\n  parseRoots(process.env.REPO_ROOTS),\n);\n```\n\nThere is no default search root. A package cannot know where you keep your\ncheckouts, and guessing would silently find the wrong repository.\n\n## License\n\nApache-2.0\n","readmeFilename":""}