
Security News
PEP 810 Proposes Explicit Lazy Imports for Python 3.15
An opt-in lazy import keyword aims to speed up Python startups, especially CLIs, without the ecosystem-wide risks that sank PEP 690.
alarmist-npm
Advanced tools
Wrap npm scripts in alarmist jobs
It is expected that your project already has alarmist
installed
npm install --save-dev alarmist alarmist-npm
You can then add something like the following to your package.json
scripts (using mocha
for tests and chokidar
to watch for changes)
{
...
"scripts": {
...
"cmd:test": "mocha",
"alarmist:test": "chokidar \"+(src|test)/**/*\" -c \"alarmist-npm cmd:test\"",
...
},
...
}
The job name will default to the script name.
Usage: alarmist-npm [options] <script> [<arg>...]
Start a job using an npm script name. The working directory
should match the working directory of the monitor and usually this will
be the default. If the job is started via a watcher started
by the monitor then the 'ALARMIST_WORKING_DIRECTORY' environment
variable will have already been set.
<script>: The command to start the job
<arg>: arguments for the command
Environment Variables:
FORCE_COLOR
ALARMIST_WORKING_DIRECTORY
ALARMIST_SERVICE
ALARMIST_NPM_SILENT
Options:
--name, -n The name to use for the job, defaults to the script name
--working-dir, -w The directory in which to write logs, etc (default: ".alarmist")
--service, -s Flag the job as a service (default: false)
--force-color, -c Set the FORCE_COLOR environment variable for the job (default: true)
--silent, -q Set the silent flag for npm run (default: true)
--help, -h Show help
--version, -v Show version number
Run lint, tests, build, etc before pushing/submitting PRs
npm test
- lint and testnpm run build
- run tests then buildnpm run watch
- watch for changes and run buildnpm run ci
- run build and submit coverage to coverallsnpm start
- watch for changes and build, lint, test, etc in parallel with alarmistFAQs
Wrap npm scripts in alarmist jobs
We found that alarmist-npm demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
An opt-in lazy import keyword aims to speed up Python startups, especially CLIs, without the ecosystem-wide risks that sank PEP 690.
Security News
Socket CEO Feross Aboukhadijeh discusses the recent npm supply chain attacks on PodRocket, covering novel attack vectors and how developers can protect themselves.
Security News
Maintainers back GitHub’s npm security overhaul but raise concerns about CI/CD workflows, enterprise support, and token management.