I'd also like a bunch of checks applied to
my use of that registry.
1. only packages > nK downloads
2. only packages with tests
3. only packages with publicly available code that is same that I am downloading
4. only packages with > nnn stars, forks, issues, pull requests
All are just proxies for being a valid node in a dependency graph.
And like to know if any transitive dep violates my inclusion rules.