
Product
Introducing Webhook Events for Alert Changes
Add real-time Socket webhook events to your workflows to automatically receive software supply chain alert changes in real time.
We all use a lot of open source projects. Really often we don't even know who is responsible for all the well done projects. You want to see who to thank for hard work?
Use credits and find out on whose work your projects are based on.
$ npm i --save credits
credits will check node_modules, bower_components, and jspm_packages to evaluate the Author and Maintainers of the installed dependencies included in the set path.
In case you want to use it over the command line, there is also credits-cli.
Description : Evaluate persons responsible for your dependencies.
credits returns a Promise which will be resolved with an Array containing a lot of great people.
The Array will be sorted according to the numbers of projects they are working on.
var credits = require( 'credits' );
var creditPath = '/Users/you/your-awesome-project';
/**
* @param {String} creditPath path to the project you want to analyze
*
* @return {Promise}
*/
credits( creditPath )
.then( function( credits ) {
console.log( credits );
} )
.catch( function( error ) {
console.log( error );
process.exit( 1 );
} );
/*
Will print:
{
npm:
[ { name : 'Some person',
email : 'some@email.io',
packages : [ 'package1', 'package2', 'package3', 'package4', 'package5'] },
{ name : 'Some other great person',
email : 'someOther@email.io',
packages : [ 'package6', 'package7', 'package8' ] },
...
...
...
],
jspm: [...],
bower: [...]
}
*/
Thanks goes to these wonderful people (emoji key):
Jayson Harshbarger 📖 💻 | Radimir Bitsov 📖 💻 | Allain Lalonde 💻 | Andrew Goode 💻 |
|---|
This project follows the all-contributors specification. Contributions of any kind welcome!
FAQs
Find out on whose work your project is based on
We found that credits demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Product
Add real-time Socket webhook events to your workflows to automatically receive software supply chain alert changes in real time.

Security News
ENISA has become a CVE Program Root, giving the EU a central authority for coordinating vulnerability reporting, disclosure, and cross-border response.

Product
Socket now scans OpenVSX extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.