New Research: Supply Chain Attack on Axios Pulls Malicious Dependency from npm.Details →
Socket
Book a DemoSign in
Socket

package-json-plus

Package Overview
Dependencies
Maintainers
1
Versions
1
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

package-json-plus

Get metadata of a package from the npm registry

latest
Source
npmnpm
Version
4.0.2
Version published
Maintainers
1
Created
Source

package-json-plus Build Status

Get metadata of a package from the npm registry

How is this different from package-json?

This fork adds this feature:

You can specify npm registry,even without scope.

Please refer to the usage.

Install

npm

$ npm install --save package-json-plus

yarn

$ yarn add package-json-plus

Usage

const packageJson = require('package-json-plus');

packageJson('ava').then(json => {
	console.log(json);
	//=> {name: 'ava', ...}
});

// Also works with scoped packages
packageJson('@sindresorhus/df').then(json => {
	console.log(json);
	//=> {name: '@sindresorhus/df', ...}
});

// You can specify npm registry
packageJson('ava', {registryUrl: 'http://r.cnpmjs.org/'}).then(json => {
	console.log(json);
	//=> {name: 'ava', ...}
});

API

packageJson(name, [options])

name

Type: string

Name of the package.

options

Type: Object

version

Type: string
Default: latest

Package version such as 1.0.0 or a dist tag such as latest.

The version can also be in any format supported by the semver module. For example:

  • 1 - get the latest 1.x.x
  • 1.2 - get the latest 1.2.x
  • ^1.2.3 - get the latest 1.x.x but at least 1.2.3
  • ~1.2.3 - get the latest 1.2.x but at least 1.2.3
registryUrl

Type: string

Specify npm registry.

fullMetadata

Type: boolean
Default: false

By default, only an abbreviated metadata object is returned for performance reasons. Read more.

allVersions

Type: boolean
Default: false

Return the main entry containing all versions.

Authentication

Both public and private registries are supported, for both scoped and unscoped packages, as long as the registry uses either bearer tokens or basic authentication.

License

MIT

Keywords

npm

FAQs

Package last updated on 10 May 2017

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts