
CompatLab
io.github.siddiksawaniv1.0.0更新于 Oct 9, 2026
Read recorded npm loading evidence across pinned Node.js, Bun and Deno runtimes.
概览
让助手通过远程只读 MCP 端点读取已记录的 npm 包在固定 Node.js、Bun 和 Deno 运行时下的加载证据。
- 功能
- CompatLab 通过远程 Streamable HTTP MCP 端点提供两个只读工具 check_package 和 get_report。它们返回确切的包版本、运行时固定版本、覆盖范围以及指向已有报告的链接,说明已发布的 npm 产物在固定的 Node.js、Bun 和 Deno 运行时下如何加载。这些工具只读取已有证据,不会提交或触发新的扫描。
- 适用场景
- 当你需要确认某个已发布的 npm 包是否已有针对特定 JavaScript 运行时的加载证据,以便决定是否采用或升级时,可以使用它。它适合已有报告即可回答的兼容性问题,而不是请求新的扫描。
- 运行要求
- 需要支持 Streamable HTTP 的远程 MCP 客户端,连接到提供方的端点。未声明账号、API 密钥、环境变量或请求头,读取 API 为匿名访问。
安装
在 SourceWeft 中
- 打开 控制台中的 CompatLab,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Web executable,通过 Streamable HTTP。 远程服务在工作区中配置后即可从网页运行时运行。
其他 MCP 客户端
把它添加到你客户端的 mcpServers 配置中。
{
"mcpServers": {
"compatlab": {
"type": "http",
"url": "https://compatlab.me/mcp"
}
}
}README
CompatLab
CompatLab tests published npm artifacts across pinned JavaScript runtimes. Reports distinguish observed loading behavior, coverage, and environment limits from broader claims of compatibility.
Production domain: compatlab.me. Read the methodology before interpreting a passing report.
Agents can read existing evidence through the anonymous API or connect a remote MCP client to https://compatlab.me/mcp using Streamable HTTP. The read-only check_package and get_report tools return exact versions, runtime pins, coverage and report links; they never submit scans. See MCP setup and validation. Missing evidence is not a compatibility verdict.
The local engine resolves and prepares public npm artifacts with scripts disabled, seals their dependency tree, and probes them across pinned Node, Bun, and Deno runtimes. The CLI supports bounded checks and explicit snapshot reuse or lock-based rebuilds. The worker includes host ownership, capacity reservations, recovery and hostile-code qualification. The PostgreSQL catalog and private control service provide transactional admission, durable leases, authenticated result ingestion and snapshot-local dispatch. The anonymous website supports discovery, explicit scan requests, durable progress, report matrices, evidence and reproduction downloads. SSH operator controls, deployment packaging, encrypted off-host backups, retention and release-qualification gates are included; public admission defaults to disabled. See the operations runbook and qualification record. See website setup, reports, orchestration, catalog and admission, worker lifecycle, local execution, preparation, and runtime profiles for limits and prerequisites.
Development
Named assertions and CI artifacts extend the maintainer workflow. Assertions use commit-pinned offline fixtures and separate behavioral evidence. The Linux/runsc CLI can check a pre-publication archive with a distinct source identity and caller-supplied provenance.
The public maintainer section is coming soon. Its optional account implementation uses GitHub App login, encrypted OAuth tokens, live repository authority checks, revocation and account quotas, but sign-in and release monitoring stay disabled in this deployment. Public reports remain anonymous.
Use Node.js 24.21.0 from .node-version and pnpm 12.8.1 from package.json.
pnpm check runs formatting/lint checks, a strict workspace build, test type checking, and unit/CLI tests. Build before running the CLI or tests directly. Development checks work on macOS and Linux; a Docker daemon is needed for doctor, sandbox tests and the local PostgreSQL test server. See database qualification for the separate integration gate.
doctor reports whether a Linux amd64 Docker server has a registered runsc runtime. It returns exit code 1 when prerequisites are missing and never executes package code. Passing it does not qualify a host for untrusted execution. There is no fallback to running packages on the developer's machine.
On a prepared Linux amd64 host with runsc:
The smoke test builds a digest-pinned fixture image and checks ESM/CommonJS completion, module failure, fake stdout success, missing results, and abnormal exit. It uses authored fixtures only. CI installs a checksum-pinned gVisor release on a disposable GitHub-hosted runner; that installer is not for development or production machines.
Repository structure
Delivery and contribution
The fourteen-PR delivery plan covers the public MVP and gated maintainer workflows. The architecture plan, PRD v1.1, and research notes define the design. The original PRD is preserved as historical reference.
All project changes use feature branches and pull requests. See CONTRIBUTING.md for checks and review expectations, and SECURITY.md for reporting security issues. The repository is maintained by siddiksawani and licensed under MIT.
For operating the public site, see production operations and search discovery. The deferred maintainer release-monitoring workflow is described in monitoring and deployment.
来源:README.md,提交 ac0b9bf
工具
0版本历史
1- v1.0.0最新Oct 9, 2026


