Socket
Socket
Sign inDemoInstall

ci-npm-update

Package Overview
Dependencies
Maintainers
1
Versions
20
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

ci-npm-update

Keep NPM dependencies up-to-date with CI, providing version-to-version diff for each library


Version published
Weekly downloads
9
increased by200%
Maintainers
1
Weekly downloads
 
Created
Source

ci-npm-update CircleCI

This command keeps npm dependencies up-to-date, making pull-requests from CI.

For example: https://github.com/gfx/ci-npm-update/pull/13

Usage

For CI:

# setup env vars in the CI dashboard:
export GITHUB_ACCESS_TOKEN=...
export GIT_USER_NAME=gfx
export GIT_USER_EMAIL=gfx@users.noreply.github.com

# and later:
ci-npm-update --execute

For local use:

# envchain is recommended to save credentils locally
envchain --set github GITHUB_ACCESS_TOKEN

# run in dry-run mode:
envchain github ci-npm-update

# run:
envchain github ci-npm-update --execute

Development

Setup:

npm run setup

Easy test command in dry-run mode:

npm run build && envchain github node bin/ci-npm-update

Heroku Scheduler

If you want to setup heroku schedulers, there's a template for it:

Deploy

See Also

License

Copyright (c) 2016 FUJI Goro (gfx).

Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at

http://www.apache.org/licenses/LICENSE-2.0

Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.

Keywords

FAQs

Package last updated on 31 Jul 2016

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts

SocketSocket SOC 2 Logo

Product

  • Package Alerts
  • Integrations
  • Docs
  • Pricing
  • FAQ
  • Roadmap
  • Changelog

Packages

npm

Stay in touch

Get open source security insights delivered straight into your inbox.


  • Terms
  • Privacy
  • Security

Made with ⚡️ by Socket Inc