AuPM
Health Warn
- License — License: AGPL-3.0
- Description — Repository has a description
- Active repo — Last push 0 days ago
- Low visibility — Only 6 GitHub stars
Code Fail
- rm -rf — Recursive force deletion command in .claude/settings.json
- exec() — Shell command execution in .github/actions/aupm/install.mjs
- process.env — Environment variable access in .github/actions/aupm/install.mjs
- process.env — Environment variable access in .github/actions/aupm/install.test.mjs
- process.env — Environment variable access in .github/actions/aupm/run.mjs
- process.env — Environment variable access in .github/actions/aupm/run.test.mjs
- process.env — Environment variable access in .github/workflows/publish-cli.yml
Permissions Pass
- Permissions — No dangerous permissions requested
No AI report is available for this listing yet.
npm-compatible registry that crowdfunds supply chain security: donors pay auditors and maintainers in USDC on Algorand via x402
https://github.com/user-attachments/assets/f7fec474-bfa1-4453-812c-a7dfe773142a
AuPM — audited package manager
See which npm packages a human has actually read.
Support open source · Try it · AI agents · Install · Donations · Auditors
Your project installs hundreds of npm packages. No person has read most of them. Many
companies audit their dependencies internally, but that review work stays private and never
reaches the open-source project.
AuPM is an npm-compatible registry that tells you, for each exact package version, whether a
human auditor has read that tarball. Every answer is a signed attestation that you can verify
offline. Installs stay free. Users and their agents can optionally donate to fund more
reviews.
Support open source as you go
Open-source funding depends on people who visit a project's page and click "Sponsor". Today,
agents and CI pipelines choose and install most packages, and no person sees that page.
Have you ever thought you can thank the open source you use as you install it, just $0.001 at
a time? Add --donate to an install. AuPM pays for a human review of each reviewed package in
your lockfile. Today that donation pays the auditor who read the tarball (30%) and runs AuPM
(70%). The planned split also pays maintainers and contributors. See
How donations work.
Try it in 30 seconds
You need no wallet and no account. Nothing here costs money.
Point npm at AuPM. npm works as before, and the integrity hashes are npm's own:
npm config set registry https://aupm.fyi/Check one package version:
curl https://aupm.fyi/api/v1/status/ms/2.1.3Check a whole project. This writes a signed attestation for your lockfile:
npx aupm-cli attest package-lock.json
UNREVIEWED is the normal answer today. Auditors have reviewed few packages so far. To go back to the
public registry, run npm config delete registry.
For AI agents
A coding agent can check a package before it adds the package. The MCP server gives it
three tools:
check_audit_status— a free status lookup for one package version.install_audited_package— installs a package, and donates only withallowDonation: true.attest_lockfile— attests a whole lockfile, and donates only withallowDonation: true.
{ "mcpServers": { "aupm": { "command": "npx", "args": ["-y", "aupm-mcp"] } } }
An agent without MCP can read aupm.fyi/llms.txt. It describes
the HTTP routes and how to read the results.
Review tiers
The MVP has two tiers:
UNREVIEWED— the default. No auditor has read this exact tarball.COMMUNITY_REVIEWED— a human auditor read this exact tarball and recorded the review
publicly (see "For auditors" below).
AuPM also reports two warnings: INTEGRITY_MISMATCH and UNRESOLVABLE. AuPM always shows
them, and never charges for them.
AuPM plans a tier filter for installs. It has not built that yet: today, aupm and the MCP
server install any package, reviewed or not.
Install the CLI
npm install -g aupm-cli
aupm is a drop-in for npm. It runs the real npm against the AuPM registry and passes your
arguments and npm's own exit code through unchanged.
aupm install [email protected] # installs through the AuPM registry, same as npm
aupm install [email protected] --donate # also donates for any reviewed package in the lockfile
aupm pnpm add [email protected] [--donate] # pnpm against the AuPM registry; attests pnpm-lock.yaml
aupm npx cowsay hi # npx against the AuPM registry; no lockfile, no --donate
aupm config set donate true # always donate; --no-donate skips it once
aupm attest and aupm verify --lockfile also accept a pnpm-lock.yaml (lockfileVersion 9.0,
at most 2 MiB).
AUPM_PROXY_URL sets the registry the CLI talks to. It defaults to https://aupm.fyi, the
MainNet deployment. For a local proxy, use http://localhost:4873/. To build the CLI from
source, see docs/DEVELOPMENT.md.
In CI
The aupm GitHub Action replaces an npm ci step. It installs through the AuPM registry and
falls back to npm. Then it checks the lockfile against the reviewed packages. Pin it to a full
commit SHA. See .github/actions/aupm/README.md. The
aupm-action-demo repository runs it on
MainNet.
Verify an attestation offline
aupm verify verifies one signed attestation against a published key. It makes no network
request.
aupm verify attestation.json --lockfile package-lock.json --keys aupm-keys.json
Early days: come build it with us
AuPM is at an early stage. It runs on Algorand MainNet, and donations settle there. Many
steps are still manual, and only the auditor and ops roles are paid today.
docs/ROADMAP.md lists what comes next. If one of these fits you, please
join:
- Review packages. Read a tarball, record your review, and get paid for it. See
"For auditors" below. - Maintain a package? Tell us in an issue. The maintainer share is planned, not live.
Your input decides how it works. - Write code. Pick an item from the roadmap, or open an issue first.
- Try it. Point npm at
https://aupm.fyi/and tell us what breaks.
How donations work
Everything above is free. This section is for people who want to fund reviews.
A donation pays an auditor to read one exact tarball and match it against the published npm
release. It costs $0.001 (1,000 microUSDC) per reviewed package, in USDC on Algorand, on
every paid route. A lockfile donation costs $0.001 times the number of reviewed packages in
that lockfile, with no cap and no discount. A donation always pays for a reviewed version,
never for an unreviewed one.
Only these opt-ins donate:
aupmwith--donate,AUPM_DONATE=trueoraupm config set donate true.- The MCP server's
allowDonation: true. - The CI Action's
donate: 'true'input, with adonor-secretsecret. The Action donates on
MainNet unless the job setsNETWORK: testnet.
Plain npm install through AuPM never donates. To donate, you need a funded Algorand account
holding USDC. See "Donor account setup" in docs/DEVELOPMENT.md.
Why crypto?
We know: the wallet setup is the hardest step in AuPM today. We chose crypto anyway, for
two reasons.
- The payment is too small for a card. Card networks charge a fixed fee on each
payment, typically tens of cents. That is far more than $0.001. A USDC payment on
Algorand costs a small fraction of a cent, so a $0.001 donation works. - The protocol is an open standard. AuPM pays over x402, which
turns HTTP status 402 "Payment Required" into a working payment flow. The
x402 Foundation
at the Linux Foundation governs it. Its members include Google, AWS, Visa, Stripe and
Cloudflare. AuPM depends on that open standard, not on one vendor.
Where the money goes
Target split, per $0.001 donated:
| Recipient | Share |
|---|---|
| Auditor | 30% |
| Contributor | 10% |
| Maintainer | 20% |
| Adversarial reviewer pool | 25% |
| Treasury | 10% |
| Ops | 5% |
MVP split. So far, the split pays only the auditor and ops roles:
| Recipient | Share |
|---|---|
| Auditor | 30% |
| Ops | 70% |
The MVP's 70% is ops income now, not a debt owed to the other roles. Each role gets its
target share once it onboards. TestNet runs the same split. See
ADR 0011 for the split rationale.
Trust model
The contract admin is a 2-of-3 multisig, not one key. The admin is trusted: two of the three
signers can together redirect any credited balance and the unallocated USDC at any time, with
no delay, because remapping an identity or changing the crediter key takes effect at once.
A migration to a new contract needs a public announcement, then a 7-day delay, and then must
run within the next 7 days or be announced again. The delay gives payees a warning window
for a migration. It does not limit what the multisig can do. Any balance still unclaimed at
migration moves to the treasury account, which pays it to the payee on request. See
ADR 0010 for the full design.
For auditors
Onboarding is manual in the MVP (planned). The path today:
- Open an Algorand account and opt it in to USDC.
- The admin maps your identity on-chain with
setIdentity. - You read the exact tarball you are reviewing.
- You anchor the review with a 0-ALGO self-payment to your own address, carrying an ARC-2
note (aupm:j{...}, see ADR 0007). - The operator runs
record-reviewagainst your anchor transaction, which flips the package
toCOMMUNITY_REVIEWED. - The nightly batch credits your balance in PaymentRouter.
- You call
claim()once your balance reachesMIN_CLAIM.
Attestations use DSSE envelopes with in-toto Statement v1 and ed25519 signatures.
Links
- SPEC.md — the authoritative specification.
- docs/DEVELOPMENT.md — build, run and deploy this repository.
- docs/ROADMAP.md — what comes next, and where help is welcome.
- docs/adr/ — design decisions.
- Leaderboard
License
Licensed under AGPL-3.0-only. See LICENSE.
Reviews (0)
Sign in to leave a review.
Leave a reviewNo results found