PyPI & npm Release Artifact Evidence API
Pricing
from $1.50 / 1,000 package release observations
PyPI & npm Release Artifact Evidence API
Compare selected public PyPI/npm release declarations: resolved version, file sizes, yanking, declared digests and runtime constraints. No package download or execution.
Pricing
from $1.50 / 1,000 package release observations
Rating
0.0
(0)
Developer
Salih Can Kurnaz
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
1
Monthly active users
3 days ago
Last modified
Categories
Share
Audit the distribution metadata selected by a release without installing it. For Python releases, record up to100 file names, sizes, yanking flags, upload dates and declared SHA256 digests. For npm, record tarball URL, declared integrity/SHA1, unpacked size/file count when supplied, and engine constraints. Compare with an earlier snapshot for upgrade triage or a package-metadata dashboard.
One official JSON request per input object, at most5. PyPI /pypi/name/version/json uses an exact release; omitting version uses the project endpoint and its latest metadata. The deprecated releases/downloads fields are ignored. npm GET /package/version supports exact version or latest; scoped names are encoded. Names and exact returned versions are checked. Python names use PEP503-style separator normalization. No SemVer resolution, version-range matching, dependency installation, SBOM generation, vulnerability clearance, artifact/signature verification or complete release history. Digests, license and engine requirements are publisher declarations. Linked tarballs/files are never contacted. Maintainers, emails, README and scripts are omitted.
At more than100 PyPI files, first100 are returned and complete=false. A source404 is an error, not an empty release or proof that a project never existed. Result identity uses registry:name@requested-version, so latest can detect a changed resolved version. Changing the requested exact version changes identity. Metadata outside selected fields is not tracked.
Quick start
{"packages": [{"registry": "pypi", "name": "requests", "version": "2.32.5"}, {"registry": "npm", "name": "express", "version": "5.1.0"}]}
Pricing and budget
0.0015 USD per emitted package release observation (1.5 USD per1000), plus0.005 USD startup at default256MB. Higher memory can multiply startup events; check effective Store pricing. Failed/empty sources do not emit result charges; startup can still apply. At zero result budget, input validation occurs but no upstream request is sent, and rowsAvailable is null (unknown). A positive budget can request the bounded source set before output; emission stops at the result cap and complete=false/PARTIAL_BUDGET reports truncation.
Snapshot, integration and limits
Use dataset rows together with OUTPUT and SNAPSHOT. Pass SNAPSHOT.previousHashes as previousHashes in a later run. NO_BASELINE/FIRST_SEEN/UNCHANGED/CHANGED compare only selected metadata including itemKey and sourceUrl; missing records are not deletions. FIRST_SEEN means absent from the supplied baseline. There is no persistent hidden state or automatic polling. Export JSON/CSV/Excel through the default dataset.
API example: POST https://api.apify.com/v2/actors/soilair~package-registry-release-artifact-evidence-api/runs with your Apify Authorization header and the JSON input above. Poll the returned run; read dataset items and OUTPUT/SNAPSHOT records using its store IDs. Do not place tokens or confidential data in input. No upstream key is needed. Results live in Apify run storage according to retention; no separate analytics service.
Only fixed HTTPS provider endpoints are constructed from validated identifiers. Public-IP DNS validation, pinned connections, TLS hostname verification,2MiB decoded responses, approximately95 seconds of network budget, at most5 same-provider redirects. Official API calls are distinct from website crawling; no arbitrary URLs or HTML pages. No linked documents/files are fetched. Queries are sequential with1-second spacing. Provider403/429 or Retry-After stops later calls; retry instructions are reported and no retry/proxy/circumvention is attempted. Shared IP limits and changes to upstream services can still block runs. Caller must respect provider headers and cache/reduce repeated requests. Text is data and should not be executed.
Developed with AI assistance. Tests and live/cloud comparisons qualify the selected-field contract; they do not prove commercial demand, provider uptime or a legal/license determination. Support: share a run ID and expected fields, without credentials or private material.
References: https://docs.pypi.org/api/json/ · https://github.com/npm/registry/blob/main/docs/REGISTRY-API.md