JSR
The open-source package registry for modern JavaScript and TypeScript
- Also known as
- jsr
What is JSR?
A modern package registry for JavaScript and TypeScript that works with multiple runtimes (Node.js, Deno, Bun, Cloudflare Workers, and browsers) and is backwards compatible with npm. Packages are published as ES modules with automatically generated API documentation and type definitions.
What JSR does
The capabilities that matter for package registries, normalised so it lines up with every alternative. “-” means we haven't confirmed it, not that it's missing.
- Role
- Public registry
- Ecosystem / language
- JavaScript
- Deployment
- Both
- Package formats supported
- Single ecosystem
- Private / scoped packages
- ✓
- Upstream proxy / caching
- -
- Lockfile / deterministic installs
- -
- Workspaces / monorepo
- ✓
- Content-addressable store
- -
- Supply-chain integrity
- ✓
- Vulnerability / licence scanning
- -
- Openness
- Open-source
- Pricing model
- Free / OSS
Platform & deployment
Independently observed- CLI
- Web
- Cloud / SaaS
- Self-hosted
JSR alternatives
Other package registries we track, ranked by the same independent score.
- BunA fast all-in-one JavaScript runtimelow · 19%
- uvAn extremely fast Python package and project manager, written in Rust.low · 40%
- pnpmFast, disk space efficient package managerlow · 28%
- pipThe package installer for Pythonlow · 26%
- HomebrewThe Package Manager for Everywherelow · 18%
- PoetryPython dependency management and packaging made easylow · 32%
The Vioscale score: one lens on the evidence
Not user reviews and not a paid placement: a confidence-weighted blend of the independent signals below (adoption, activity, security posture, and more), which you can sort and re-weight yourself. Vendors can correct their listing but can never move their rank, and stars are weighted low as a vanity metric. It is one way to read the evidence for JSR, not the verdict.
| Signal | Score | Weight | Contribution | Evidence |
|---|---|---|---|---|
| Capabilities | 58 | 14.00 | 809.4 | ✓ |
| Github Activity | 19 | 16.00 | 303.3 | ✓ |
| Github Stars | 66 | 4.00 | 262.0 | ✓ |
| Integrations | 0 | 8.00 | 0.0 | - |
| Release Cadence | 0 | 10.00 | 0.0 | - |
| Security Posture | 0 | 26.00 | 0.0 | - |
| Package Downloads | 0 | 22.00 | 0.0 | - |
| Stackoverflow Activity | 0 | 8.00 | 0.0 | - |
Computed . Re-weight it by intent, or see the full method.
All data & sourcesshow ↓
Every value we hold, with its source, retrieval date, and confidence. This is the evidence behind the score: don't trust it, verify it.
Activity
| Attribute | Value | Evidence |
|---|---|---|
| Commits last 30d | 3 | mediumsource · 2026-08-03 · 65% |
Adoption
| Attribute | Value | Evidence |
|---|---|---|
| Github stars | 2,968 | highsource · 2026-08-03 · 90% |
Features
| Attribute | Value | Evidence |
|---|---|---|
| Capabilities | {"role":"public_registry","ecosystem":"js","deployment":"both","workspaces":true,"open_source":"oss","pricing_model":"free","package_formats":"single","private_packages":true,"supply_chain_integrity":true} | mediumsource · 2026-08-03 · 60% |
Language
| Attribute | Value | Evidence |
|---|---|---|
| Primary | Rust | highsource · 2026-08-03 · 90% |
License
| Attribute | Value | Evidence |
|---|---|---|
| Spdx | MIT | highsource · 2026-08-03 · 95% |