Glossary

package metadata

package metadata is the structured record describing a published software package: name, version history, maintainers, license, dependencies and file listings. npm serves full and abbreviated variants, and the registries here publish it via REST endpoints as well as bulk database dumps. In Datadory's catalog of 1,744 datasets, npm Public Registry API and crates.io - Rust Package Registry API are.

What is package metadata?

Package metadata is the structured record describing a published software package: name, version history, maintainers, license, dependencies and file listings. npm serves full and abbreviated variants, and the registries here publish it via REST endpoints as well as bulk database dumps.

In this catalog it appears concretely: - npm Public Registry API — "package-metadata". - crates.io - Rust Package Registry API — "per crate, per version, per dependency edge metadata; JSON, NDJSON, SQL dump". - deps.dev - Open Source Insights API — "per package version records, e.g. 300+ version records in one serde response".

Why does package metadata matter when choosing a dataset?

A table is only as good as the column you actually need. If this field is absent, sparsely populated or defined inconsistently across rows, no amount of surrounding richness rescues the analysis, so it deserves its own line in your evaluation checklist.

The failure mode is concrete: the label appears in a listing, the delivered files tell a different story, and the gap surfaces mid-project when fixing it is most expensive.

You rarely have to take a vendor's word for it. 82.4% of the 1,744 datasets Datadory catalogs are free to access, and npm Public Registry API lets you inspect the real artifact before any budget is committed.

How do you evaluate package metadata in a data source?

Treat every claim of this attribute as testable:

  1. Open npm Public Registry API and confirm its record — "package-metadata" — against the files you actually receive.
  2. Open crates.io - Rust Package Registry API and confirm its record — "per crate, per version, per dependency edge metadata; JSON, NDJSON, SQL dump" — against the files you actually receive.
  3. Open deps.dev - Open Source Insights API and confirm its record — "per package version records, e.g. 300+ version records in one serde response" — against the files you actually receive.

See the term applied to real records: systems-software data.

Adjacent concepts worth reading next: - database dump - dependency graph - package registry

Frequently asked questions

What is an example of package metadata?

npm Public Registry API is the clearest example in this catalog. Its record states: "package-metadata". Across all 1,744 datasets Datadory averages a quality score of 7.81 out of 10, so a named example can be weighed rather than trusted blindly.

Is data described as "package metadata" free to use?

Treat access and permission separately. 82.4% of the 1,744 datasets in this catalog are free to access, but 235 are freemium and 61 are paid outright, so confirm both the price and the license on the exact distribution before building on it.

How do I verify a source really provides package metadata?

Open npm Public Registry API next to crates.io - Rust Package Registry API and compare the promise with the download. Field definitions are verified for 1495 of 1,744 datasets (85.7%), which makes that check fast inside the catalog and manual outside it.

Datasets containing this field

Datasets containing package metadata

6 datasets carry package metadata in the catalog. Open one, count the fields, judge for yourself.

Systems Software

endoflife.date Product Lifecycle Catalog

11-26h1-e · isLts · eoasFrom …+3 more

Systems Software

GitHut - GitHub Language Statistics

name · year · quarter …+3 more

Every listing shows the field dictionary, sample rows, and coverage before you commit. API, files, or your warehouse. Daily, weekly, or hourly.

Get sample rows