{"_id":"@agentic-research/depgraph-core","_rev":"2-8f8397b835853bcdeafd7b1648990532","name":"@agentic-research/depgraph-core","dist-tags":{"latest":"0.2.0"},"versions":{"0.1.0":{"name":"@agentic-research/depgraph-core","version":"0.1.0","keywords":["dependency-graph","provenance","sbom","monorepo","zod"],"license":"Apache-2.0","_id":"@agentic-research/depgraph-core@0.1.0","maintainers":[{"name":"jamestexas","email":"jamestexasgardner@gmail.com"}],"dist":{"shasum":"61fae97899db8d5cb29ca2e48e6b627c157893b4","tarball":"https://registry.npmjs.org/@agentic-research/depgraph-core/-/depgraph-core-0.1.0.tgz","fileCount":15,"integrity":"sha512-x5e36/ZtBYEcXIB1XdkMQebGCdOURohGvRi1+Txkguc1REgqbUiV5pQSX2fWQyEqr0iMYmDu+DF/9lW2Pq0PUg==","signatures":[{"sig":"MEQCIHfiI4t6iApVGPnApZhWdncXMes69hIUFGI1f4ZijDOSAiAOhR5igF5mrYnsC+ju0Ds57wgD+hiMI9xx+UtUoISxug==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":165983},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"scripts":{"test":"pnpm run test:workerd","build":"rm -rf dist && tsc -p tsconfig.build.json","test:package":"pnpm run build && node -e \"import('./dist/index.js').then(() => console.log('package import ok'))\"","test:workerd":"vitest run --config vitest.workerd.config.mts"},"_npmUser":{"name":"jamestexas","email":"jamestexasgardner@gmail.com"},"repository":{"url":"git+https://github.com/agentic-research/0day-api.git","type":"git","directory":"packages/core"},"description":"Portable dependency-map contract, derivation and gate. One dependency (zod), no filesystem, no network — runs in workerd.","directories":{},"_nodeVersion":"25.9.0","dependencies":{"zod":"^4.4.3"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"4.1.10","@cloudflare/vitest-pool-workers":"0.18.7"},"_npmOperationalInternal":{"tmp":"tmp/depgraph-core_0.1.0_1785443500470_0.45571875311495935","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@agentic-research/depgraph-core","version":"0.2.0","description":"Portable dependency-map contract, derivation and gate. One dependency (zod), no filesystem, no network — runs in workerd.","type":"module","main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"dependencies":{"zod":"^4.4.3"},"devDependencies":{"@cloudflare/vitest-pool-workers":"0.18.7","vitest":"4.1.10"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"license":"Apache-2.0","repository":{"type":"git","url":"git+https://github.com/agentic-research/0day-api.git","directory":"packages/core"},"keywords":["dependency-graph","provenance","sbom","monorepo","zod"],"scripts":{"build":"rm -rf dist && tsc -p tsconfig.build.json","test":"pnpm run test:workerd","test:workerd":"vitest run --config vitest.workerd.config.mts","test:package":"pnpm run build && node -e \"import('./dist/index.js').then(() => console.log('package import ok'))\""},"_nodeVersion":"25.9.0","_id":"@agentic-research/depgraph-core@0.2.0","dist":{"integrity":"sha512-hF341vzvurW+7WQXuxpYhO791O6hOUEvT/pckpJ42dvbEtLKZ8tOq97aHONbpadMZP9h2vAHi6eTN7Klptn01g==","shasum":"63b5f3a2e376e9c5488f95e9d1ebd72c6d58f530","tarball":"https://registry.npmjs.org/@agentic-research/depgraph-core/-/depgraph-core-0.2.0.tgz","fileCount":17,"unpackedSize":189966,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIBqvekLzIHFEXj2mlAW2Qz5FX8SiHKPsa2MET+yvfrY6AiACADLJ5SynnBjNaOE1/YvwHk6Qwvhns6AoiIHIXkN85A=="}]},"_npmUser":{"name":"jamestexas","email":"jamestexasgardner@gmail.com"},"directories":{},"maintainers":[{"name":"jamestexas","email":"jamestexasgardner@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/depgraph-core_0.2.0_1785460948172_0.940158441596421"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-30T20:31:40.323Z","modified":"2026-07-31T01:22:28.501Z","0.1.0":"2026-07-30T20:31:40.600Z","0.2.0":"2026-07-31T01:22:28.337Z"},"license":"Apache-2.0","keywords":["dependency-graph","provenance","sbom","monorepo","zod"],"repository":{"type":"git","url":"git+https://github.com/agentic-research/0day-api.git","directory":"packages/core"},"description":"Portable dependency-map contract, derivation and gate. One dependency (zod), no filesystem, no network — runs in workerd.","maintainers":[{"name":"jamestexas","email":"jamestexasgardner@gmail.com"}],"readme":"# @agentic-research/depgraph-core\n\nThe portable half of a derived dependency map: the contract, the derivation,\nand the gate. No filesystem, no network, no process — its only dependencies\nare `zod` and `smol-toml`, so it runs in workerd, a Durable Object or a\nbrowser as readily as in Node.\n\nReading repositories is [`@agentic-research/depgraph-collect`](../collect),\nwhich is Node-only and depends on this.\n\n## Why the split is here and not somewhere convenient\n\nThe derivation is the part that has to be reproducible. The design rests on\none gate — _re-derive from the same sources and compare byte-for-byte_ — and\nthat gate is only meaningful if deriving cannot reach the network. If it\ncould, \"the artifact matches its sources\" would quietly become \"the artifact\nmatches whatever the network returned this time\".\n\nSo the boundary is not stylistic. It is what makes the guarantee checkable.\n\n## What it produces\n\nA document splitting **authored** statements (a maintainer's judgment:\nstatus, membership, editorial relationships) from **derived** facts (read\nfrom a repository's own manifests). Every edge carries how it was resolved:\n\n- `edges` — the target was named outright, or named an identifier that\n  repository declares publishing.\n- `weak_edges` — the target could only be matched by name. Kept, because\n  deleting a real coupling is its own distortion, but never folded into\n  `edges`.\n- `unresolved` — parsed, and resolved to no repository, with the reason.\n\n## Scope, stated plainly\n\n`unresolved` records **resolution** gaps. A coupling declared in a format the\ncollector has no parser for is never attempted, so it is _absent rather than\nrecorded_. Read `sources_read` for which formats were actually read, and\ntreat everything outside that list as unexamined rather than empty.\n\n## Usage\n\n```ts\nimport { derive, checkGraph, schemaUrl } from \"@agentic-research/depgraph-core\";\n\nconst graph = derive(lock, projects, { origin: \"https://example.com\" });\n\nconst result = checkGraph({\n  lockText,\n  graphText,\n  projects,\n  origin: \"https://example.com\",\n});\nif (!result.ok) throw new Error(result.message);\n```\n\n`origin` is required and deliberately not defaulted: it becomes the\ndocument's `$schema`, and a default would have every deployment publish an\nartifact pointing at somebody else's contract — a link that resolves, returns\na plausible document, and is wrong.\n\n## License\n\nApache-2.0\n","readmeFilename":""}