CompatLab

io.github.siddiksawaniv1.0.0更新於 Oct 9, 2026

Read recorded npm loading evidence across pinned Node.js, Bun and Deno runtimes.

已驗證Streamable HTTP可網頁執行Developer ToolsData & Analytics

概覽

AI 產生的概覽

讓助理透過遠端唯讀 MCP 端點,讀取已記錄的 npm 套件在固定 Node.js、Bun 與 Deno 執行環境下的載入證據。

功能
CompatLab 透過遠端 Streamable HTTP MCP 端點提供兩個唯讀工具 check_package 與 get_report。它們會回傳確切的套件版本、執行環境固定版本、涵蓋範圍,以及指向既有報告的連結,說明已發布的 npm 產物在固定的 Node.js、Bun 與 Deno 執行環境下如何載入。這些工具只讀取既有證據,不會送出或觸發新的掃描。
適用情境
當你需要確認某個已發布的 npm 套件是否已有針對特定 JavaScript 執行環境的載入證據,以便決定是否採用或升級時,可以使用它。它適合既有報告就能回答的相容性問題,而不是要求新的掃描。
執行需求
需要支援 Streamable HTTP 的遠端 MCP 用戶端,連線至提供方的端點。未宣告帳號、API 金鑰、環境變數或標頭,讀取 API 為匿名存取。
安裝前請注意
報告描述的是觀察到的載入行為、涵蓋範圍與環境限制,並非一般性的相容性結論;缺少證據不等於不相容。唯讀工具不會送出掃描,公開報告為匿名。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 CompatLab,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Web executable,透過 Streamable HTTP。 遠端服務在工作區中設定後即可從網頁執行環境執行。

其他 MCP 客戶端

把它新增到你客戶端的 mcpServers 設定中。

{
  "mcpServers": {
    "compatlab": {
      "type": "http",
      "url": "https://compatlab.me/mcp"
    }
  }
}

README

CompatLab

CompatLab tests published npm artifacts across pinned JavaScript runtimes. Reports distinguish observed loading behavior, coverage, and environment limits from broader claims of compatibility.

Production domain: compatlab.me. Read the methodology before interpreting a passing report.

Agents can read existing evidence through the anonymous API or connect a remote MCP client to https://compatlab.me/mcp using Streamable HTTP. The read-only check_package and get_report tools return exact versions, runtime pins, coverage and report links; they never submit scans. See MCP setup and validation. Missing evidence is not a compatibility verdict.

The local engine resolves and prepares public npm artifacts with scripts disabled, seals their dependency tree, and probes them across pinned Node, Bun, and Deno runtimes. The CLI supports bounded checks and explicit snapshot reuse or lock-based rebuilds. The worker includes host ownership, capacity reservations, recovery and hostile-code qualification. The PostgreSQL catalog and private control service provide transactional admission, durable leases, authenticated result ingestion and snapshot-local dispatch. The anonymous website supports discovery, explicit scan requests, durable progress, report matrices, evidence and reproduction downloads. SSH operator controls, deployment packaging, encrypted off-host backups, retention and release-qualification gates are included; public admission defaults to disabled. See the operations runbook and qualification record. See website setup, reports, orchestration, catalog and admission, worker lifecycle, local execution, preparation, and runtime profiles for limits and prerequisites.

Development

Named assertions and CI artifacts extend the maintainer workflow. Assertions use commit-pinned offline fixtures and separate behavioral evidence. The Linux/runsc CLI can check a pre-publication archive with a distinct source identity and caller-supplied provenance.

The public maintainer section is coming soon. Its optional account implementation uses GitHub App login, encrypted OAuth tokens, live repository authority checks, revocation and account quotas, but sign-in and release monitoring stay disabled in this deployment. Public reports remain anonymous.

Use Node.js 24.21.0 from .node-version and pnpm 12.8.1 from package.json.

sh
corepack enablepnpm install --frozen-lockfilepnpm checkpnpm cli --helppnpm cli doctor --json

pnpm check runs formatting/lint checks, a strict workspace build, test type checking, and unit/CLI tests. Build before running the CLI or tests directly. Development checks work on macOS and Linux; a Docker daemon is needed for doctor, sandbox tests and the local PostgreSQL test server. See database qualification for the separate integration gate.

doctor reports whether a Linux amd64 Docker server has a registered runsc runtime. It returns exit code 1 when prerequisites are missing and never executes package code. Passing it does not qualify a host for untrusted execution. There is no fallback to running packages on the developer's machine.

On a prepared Linux amd64 host with runsc:

sh
pnpm buildpnpm test:sandbox

The smoke test builds a digest-pinned fixture image and checks ESM/CommonJS completion, module failure, fake stdout success, missing results, and abnormal exit. It uses authored fixtures only. CI installs a checksum-pinned gVisor release on a disposable GitHub-hosted runner; that installer is not for development or production machines.

Repository structure

PathImplemented responsibility
apps/cliPrerequisites, checks, CI archives, reproduction, SSH administration and backup encryption
apps/webAnonymous discovery, scan requests, durable progress and report pages
packages/engineRegistry resolution, analysis, planning and bounded probe orchestration
packages/catalogPostgreSQL identities, admission, leases, result validation, recovery and cache lookup
packages/contractsCanonical vocabulary and bounded completion validation
services/workerPreparation, sealed storage, runtime supervision and local evidence storage
services/controlPrivate WireGuard-bound worker API and reconciliation
harnessesAutomatic loading and separate named assertion completion protocols
services/maintainerRelease reconciliation, comparison and independently retried email
runtime-imagesDigest-pinned minimal runtime image recipe
fixturesAuthored module/protocol and preparation archive fixtures
infraPinned service packaging, worker provisioning, backup and recovery configuration
scriptsContainment, corpus, deployment and recovery qualification
docsArchitecture, delivery sequence, research, and decision records

Delivery and contribution

The fourteen-PR delivery plan covers the public MVP and gated maintainer workflows. The architecture plan, PRD v1.1, and research notes define the design. The original PRD is preserved as historical reference.

All project changes use feature branches and pull requests. See CONTRIBUTING.md for checks and review expectations, and SECURITY.md for reporting security issues. The repository is maintained by siddiksawani and licensed under MIT.

For operating the public site, see production operations and search discovery. The deferred maintainer release-monitoring workflow is described in monitoring and deployment.

來源:README.md,提交 ac0b9bf

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v1.0.0最新Oct 9, 2026