Bundle-roast – the NPM scale that knows your sins
Bundlephobia with teeth: real brotli compression and wire-graph dep trees.
Dependency risk analysis tool for npm packages
Simulates dependency removal to show structural impact before you install.
Frontend developers, engineering teams
Bundlephobia · Snyk · Depcheck
Still early. The most useful thing so far has been simulating removal and surfacing which package has the biggest structural impact.
Happy to answer questions or hear where this feels useful vs not useful.
Bundlephobia with teeth: real brotli compression and wire-graph dep trees.
npm for Kotlin, but Gradle already solves this—friction is real though.
License classifier for npm with CI enforcement, but tools like FOSSA and Snyk already own this.
Treats LLMs as package dependencies for reproducible AI project setups.
Lifecycle intelligence beyond CVEs, but SCA competitors already bundle EOL tracking.
Real-world bug bounty wins ($625+), but dependency confusion detection is a known category.