🚀 DAY 4 OF LAUNCH WEEK: Introducing GitHub Actions Scanning Support.Learn more →
Socket
Book a DemoInstallSign in
Socket

@sonatype/js-sona-types

Package Overview
Dependencies
Maintainers
5
Versions
97
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

@sonatype/js-sona-types

Useful libraries for talking to Sonatype services, using javascript

latest
Source
npmnpm
Version
1.2.20
Version published
Weekly downloads
1.5K
145400%
Maintainers
5
Weekly downloads
 
Created
Source

JS SONA TYPES

CircleCI

Hi, hello! This library is mostly for consumption by Sonatype projects that need a common way to talk to OSS Index, Nexus IQ, and etc...

Goals

js-sona-types is just a library, meant to be used by our JavaScript/TypeScript projects so that we can share some common code around communicating with OSS Index, Nexus IQ Server, etc...

Since we also include examples, there are a few living breathing sub projects that show how to use it.

This project started in Developer Experience and was primarily focused on getting the following projects to share common communication code:

  • vscode-iq-plugin
  • auditjs
  • nexus-iq-chrome-extension

Surface area

There are lots of things we do that are similar in each project. However creating a common library for browser, node, etc... in JS can be complicated. The goal realistically is to limit the surface area of this project to areas we can easily rip out of the projects, and have be beneficial for all projects.

Development

To get started you'll need node, yarn, and that's about it!

Building

  • yarn
  • yarn build

Examples

In the /examples dir, there is a README that has examples of how to test that the project is working for both node, and React. Go browse there for more information!

You can see if the examples are working by running in the root of this project:

  • yarn run ci

Alternatively you can look at test.sh to see the "magic" we are running to locally link the library in case you want to run only one project.

Releasing

We use semantic-release to generate releases from commits to the main branch.

For example, to perform a "patch" release, add a commit to main with a comment like:

fix: Adds supercow flag, implements (#xyz)

To avoid performing a release after a commit to the main branch, be sure your commit message includes [skip ci] .

Need Help?

Internal folks, reach out to the Developer Experience team. Filing an issue here is good too!

External folks, file an issue here!

FAQs

Package last updated on 15 May 2024

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts