
Security News
Axios Maintainer Confirms Social Engineering Attack Behind npm Compromise
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.
sync-local-deps
Advanced tools
Keep your local npm packages up-to-date with each other
npm install -g sync-local-deps
sync-local-deps [root] [options]
Options:
[root] directory where projects are located, defaults to cwd()
--dryrun, -D don't make changes [default: false]
--skip, -S list of directories to skip [array] [default: []]
--skipPublish, -P list of directories to not npm publish
[array] [default: []]
--skipGitPush, -G list of directories to not git push [array] [default: []]
--ignoreDevDeps, -I don't update dev deps [boolean]
--updateAll, -a include even those dependencies whose latest version
satisfies the declared semver dependency [boolean]
--npmVersion, -v npm version to bump to, see "npm version --help"
[string] [default: "patch"]
--only, -o only sync the given projects, looks at cwd if empty
[array]
--help Show help [boolean]
--version Show version number [boolean]
sync-local-deps does the following:
root directory for projects that depend on other projects in rootnpm install --save dep1@latest dep2@latest ...git commit -am 'bump deps'npm version patch && npm publishgit pushThis process continues until every package has up-to-date local dependencies.
The output will looks something like this:

FAQs
Keep your local npm packages up-to-date with each other
We found that sync-local-deps demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.

Security News
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.