pkg.soopen package index

npm / rank 733

Install ctrf with npm

CTRF reference implementation in TypeScript for creating and validating CTRF documents. Version 0.2.1 via npm; verified 2026-06-06.

install

Additional install commands

Portable and language managers

npmverified · 100%
npm install -g ctrf

local npm package metadata

overview

Package summary

CTRF reference implementation in TypeScript for creating and validating CTRF documents.

Commands and aliases

  • ctrf

security posture

No protected-tool coverage found yet

No matching local secret-handling manifest was found for ctrf. Package metadata is still published here so future coverage has a stable package URL.

Install behavior

  • No npm postinstall script is recorded in package metadata.
  • No Homebrew bottle metadata was recorded.
  • Installs with 4 runtime dependencies.
  • Build metadata lists 14 build dependencies.

Recommended review

Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.

executables

Installed executables

CommandKindExposureNote
ctrfcliglobal executable

freshness

Version and freshness

These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.

page generated2026-08-04
manager version0.2.1
manager updated2026-06-06
local dataok
upstreamnot checked
latest detectednot detected

https://github.com/ctrf-io/ctrf-js

install metadata

Package metadata

Package keynpm:ctrf
Version0.2.1
Package managernpm
Package manager pagehttps://www.npmjs.com/package/ctrf
Homepagehttps://ctrf.io
Repositoryhttps://github.com/ctrf-io/ctrf-js
Upstream docshttps://ctrf.io
LicenseMIT
Source archivehttps://registry.npmjs.org/ctrf/-/ctrf-0.2.1.tgz
Issue trackerhttps://github.com/ctrf-io/ctrf-js/issues
Last updated2026-06-06T17:15:37.667Z
Published2026-06-06T17:15:37.667Z
Pulseupdated
Dependenciesajv, ajv-formats, glob, yargs
Build dependencies@arethetypeswrong/cli, @d2t/vitest-ctrf-json-reporter, @eslint/js, @types/node, @types/yargs, @vitest/coverage-v8, eslint, prettier, tsup, typedoc, typedoc-plugin-markdown, typescript, typescript-eslint, vitest
Bottlenot recorded
npm postinstallnot defined
Servicenone declared
Keywordstest, testing, ctrf, reporter, report, json, standard, typescript, reference-implementation, test-results, validation, schema

registry facts

Source database details

Source Databasenpm registry
Dist Tags
Version Count35
Maintainers
  • ctrf-io
AuthorMatthew Poulton-White
PublisherGitHub Actions
Engines
Integritysha512-iUo/eHcM5yG8aBS3Miqce9NNiZCtmVZxPpgmZEJIZ96bubwj7IpZx3IqsDqCH2FZjR71EH2NLtbBhtfzDjpaUg==
Shasum81ef73a8bfcb17fffc027f2fdf49a4c729f7f623
Unpacked Size223,677
File Count0
Created At2024-06-09T17:29:36.426Z
Latest Published At2026-06-06T17:15:37.667Z
Modified At2026-06-06T17:15:37.928Z

source trail

Generated from repository data

This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.

Used sources

  • cross-ecosystem install command graph
  • package relationship graph
  • package version freshness
  • package-page enrichment
  • pkg.so package database
  • pkgdb category and tag curation