
Security News
Axios Supply Chain Attack Reaches OpenAI macOS Signing Pipeline, Forces Certificate Rotation
OpenAI rotated macOS signing certificates after a malicious Axios package reached its CI pipeline in a broader software supply chain attack.
scripts-cli
Advanced tools
This package aims to take out the step of remembering all of the scripts in your package.json file and remove the need to put all utility scripts into package.json.

npm install --save-dev scripts-cli
yarn add --dev scripts-cli
By default scripts-cli will include all scripts in package.json. By selecting a script in package.json it will run:
npm run <selected script>
In order to change the behaviour of package.json scripts and add any other scripts for the project you can create a .scriptscli.config.mjs file.
type Options =
| {
args?: boolean
argumentsLabel?: string
exec?: string
}
| {
options: Options
}
type Config = {
exclude: string[]
options: Options
}
For each option entry you can provide the following:
| key | description |
|---|---|
| args | default ( false ). When true the cli will allow arguments to be provided and passed to final command. |
| argsLabel | default ( Arguments ). When provided this will be used in the CLI as a label for the arguments input. |
| options | default ( {} ). This allows for nested options. The object supplied has the same options as the top level. |
| exec | default ( undefined ). For a script in package.json if a value is provided here it will override the script. This string will be provided to the shell to run. |
{
"scripts": {
"test": "echo \"Running tests\"",
"dev": "ts-node . -w",
"db:migrate:latest": "echo \"Running latest migrations\"",
"db:create:migration": "echo \"Creating migration$1\"",
"scripts": "scripts-cli"
}
}
/** @type { import("scripts-cli").Config } */
export default {
// This list will exclude scripts with this name from being added at the top level by default.
// Adding them manually to the options will allow them to still be selected.
// excludes can also be globs where a single `*` is treated as a wildcard
exclude: ['scripts', 'db:*'],
// These are the options to be presented.
// For package.json scripts the key needs to be the same as in package.json
options: {
test: {
args: true, // This will ask the user to provide arguments then run 'npm run test' followed by any provided arguments.
},
'Create test file': {
args: true, // This will ask the user for any arguments
argsLabel: 'File name', // This will be the label used when asking for arguments input.
exec: './scripts/create-testfile.sh', // This will then run ./script/create-testfile.sh followed by any arguments provided.
},
db: {
options: {
// This will mean whenever 'db' is selected from the list nothing will be run
// but a new list consisting of 'create migration' and 'db:migrate:latest' will show.
'create migration': {
args: true,
exec: 'npm run db:create:migration',
},
'db:migrate:latest': {}, // As this key matches a script in package.json selecting this will run 'npm run db:migrate:latest'
},
},
},
}
FAQs
CLI to run package json scripts and any other scripts in an npm project.
The npm package scripts-cli receives a total of 21 weekly downloads. As such, scripts-cli popularity was classified as not popular.
We found that scripts-cli demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
OpenAI rotated macOS signing certificates after a malicious Axios package reached its CI pipeline in a broader software supply chain attack.

Security News
Open source is under attack because of how much value it creates. It has been the foundation of every major software innovation for the last three decades. This is not the time to walk away from it.

Security News
Socket CEO Feross Aboukhadijeh breaks down how North Korea hijacked Axios and what it means for the future of software supply chain security.