@socketregistry/packageurl-js


TypeScript Package URL (purl) parser and builder. Drop-in replacement for packageurl-js with full type safety, zero dependencies, and spec compliance with the Package URL specification.
Installation
pnpm install @socketregistry/packageurl-js
Drop-in replacement via package override:
{
"pnpm": {
"overrides": {
"packageurl-js": "npm:@socketregistry/packageurl-js@^1"
}
}
}
Requirements: Node >= 18.20.4
Usage
Parse purls:
import { PackageURL } from '@socketregistry/packageurl-js'
const purl = PackageURL.fromString('pkg:npm/lodash@4.17.21')
console.log(purl.name)
console.log(purl.version)
Build purls:
import { PackageURLBuilder } from '@socketregistry/packageurl-js'
PackageURLBuilder.npm().name('lodash').version('4.17.21').build()
PackageURLBuilder.pypi().name('requests').version('2.28.1').build()
PackageURLBuilder.maven()
.namespace('org.springframework')
.name('spring-core')
.version('5.3.21')
.qualifier('classifier', 'sources')
.build()
Constructor API:
import { PackageURL } from '@socketregistry/packageurl-js'
new PackageURL('npm', null, 'express', '4.18.2')
new PackageURL('npm', '@babel', 'runtime', '7.18.6', null, 'helpers/typeof.js')
Convert to URLs:
import { UrlConverter } from '@socketregistry/packageurl-js'
UrlConverter.toRepositoryUrl(purl)
UrlConverter.toDownloadUrl(purl)
Use type-safe PURL types:
import { PURL_Type, EcosystemString } from '@socketregistry/packageurl-js'
console.log(PURL_Type.NPM)
console.log(PURL_Type.PYPI)
console.log(PURL_Type.MAVEN)
function processPurl(type: EcosystemString) {
}
Documentation
→ API Reference - Complete API documentation
→ Examples - Common use cases
→ Builders - Builder pattern guide
Development
pnpm install
pnpm build
pnpm test
pnpm check