
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
@diotoborg/sequi-molestias-ullam
Advanced tools
Tool to automatically update dependencies one by one in chronological order. Most dependencies are compatible with other packages from a similar time or pastime. This tool helps to find the latest compatible version of the dependencies and update them.
This tool is intended to simulate the typical updating workflow as it was done regularly.
Run with npx to find the next recommended dependency to update:
npx @diotoborg/sequi-molestias-ullam --update --install
or install globally:
# npm
npm install -g @diotoborg/sequi-molestias-ullam
# yarn
yarn global add @diotoborg/sequi-molestias-ullam
# pnpm
pnpm add -g @diotoborg/sequi-molestias-ullam
Basic usage to find the next recommended dependency to update:
npx @diotoborg/sequi-molestias-ullam --update --install
Automatically update dependencies one-by-one running tests after each update. Tests are run with the npm test
command:
npx @diotoborg/sequi-molestias-ullam --update --install --auto
You can specify custom install and test commands:
npx @diotoborg/sequi-molestias-ullam --update --install --auto --install-script "yarn install" --test-script "yarn test"
Get a timeline of the updates in JSON format:
npx @diotoborg/sequi-molestias-ullam --timeline
To exclude some dependencies from the update, use the --exclude
option:
npx @diotoborg/sequi-molestias-ullam --update --install --exclude react,react-dom
or use the --exclude-file
option to exclude dependencies from the file:
npx @diotoborg/sequi-molestias-ullam --update --install --exclude-file exclude.txt
The tool reads the package.json
file and finds all dependencies. Then it resolves all the versions from the registry, sorts them by date and
finds the latest version of the dependency before finding another. Searching in version groups allows one to spot
incompatibility between dependencies. Built-in cache and auto mode allow to update dependencies faster.
Usage: @diotoborg/sequi-molestias-ullam [options]
Tool to automatically update dependencies one-by-one in the time order
Options:
-p, --packageFile <file> Path to package.json file (default: "package.json")
-u, --update Update package.json file with new versions
-is, --install-script <command> Install with script (default: "npm install")
-ts, --test-script <command> Test command (default: "npm test")
-i, --install Install with script
-t, --timeline Print timeline
-a, --auto Run in auto mode
-c, --cache Cache resolved dependencies
-ans, --allow-non-semver Allow non-semver versions (compare with dates then, experimental)
-cf, --cache-file <file> Cache file (default: "./.@diotoborg/sequi-molestias-ullam-cache.json")
-e, --exclude <dependency> Exclude dependency from update, separated by comma
-r, --registry-url <url> Registry url (default: "https://registry.npmjs.org")
-x, --exclude-file <file> Exclude dependencies from file, one per line (default: "")
-shmn, --stop-if-higher-major-number Stop if higher major number
-shmnv, --stop-if-higher-minor-number Stop if higher minor or major number
-pi, --print-info Print info about the packages
-h, --help display help for command
MIT
FAQs
security holding package
The npm package @diotoborg/sequi-molestias-ullam receives a total of 0 weekly downloads. As such, @diotoborg/sequi-molestias-ullam popularity was classified as not popular.
We found that @diotoborg/sequi-molestias-ullam demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.