New Research: Supply Chain Attack on Axios Pulls Malicious Dependency from npm.Details
Socket
Book a DemoSign in
Socket

ripcord

Package Overview
Dependencies
Maintainers
1
Versions
100
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

ripcord

project scaffolding and opinion enforcer!

latest
Source
npmnpm
Version
4.0.0
Version published
Maintainers
1
Created
Source

deprecated

ripcord functions are being migrated out of ripcord and into independent utilities.

ripcord

project scaffolding and build tooling.

Codeship Status for cdaringe/ripcord Coverage Status semantic-release Greenkeeper badge

install

npm install --save-dev ripcord

usage

api docs found here

reporting

generate dependency report. operates in two modes:

  • node mode
    • uses your package.json depedencies & devDependencies as sole source of depedencies
  • ui build
    • uses ui build compiler output as declaration of which dependencies are used, and uses remaining devDependencies as source of external devDependencies.
      • currently only supports webpack

license checking

check or dump (output) project licenses. only outputs licenses for dependencies not devDependencies by default.

licenses [options] <check|dump>

npm repo package syncning

sync packages from npm repo to repo. current implementation assumes artifactory API present to successfully copy!

ripcord sync-packages --help

margdking

todo

  • ui build support for license checking

FAQs

Package last updated on 01 Oct 2017

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts