
Research
/Security News
Intercom’s npm Package Compromised in Ongoing Mini Shai-Hulud Worm Attack
Compromised intercom-client@7.0.4 npm package is tied to the ongoing Mini Shai-Hulud worm attack targeting developer and CI/CD secrets.
Write a
package.jsonfile
Writes atomically and creates directories for you as needed. Sorts dependencies when writing. Preserves the indentation if the file already exists.
npm install write-pkg
import path from 'node:path';
import {writePackage} from 'write-pkg';
await writePackage({foo: true});
console.log('done');
await writePackage(path.join('unicorn', 'package.json'), {foo: true});
console.log('done');
Returns a Promise that resolves when the package.json file has been written.
Type: string
Default: process.cwd()
The path to where the package.json file should be written or its directory.
Type object
JSON data to write to the package.json file.
Type: object
See Options.
Returns a Promise that resolves when the package.json file has been updated.
import {updatePackage} from 'write-pkg';
await updatePackage({foo: true});
//=> { "foo": true }
await updatePackage({foo: false, bar: true});
//=> { "foo": false, "bar": true }
Type: string
Default: process.cwd()
The path to where the package.json file should be written or its directory.
Type object
JSON data to write to the package.json file. If the file already exists, existing fields will be merged with the values in data.
Type: object
See Options.
Returns a Promise that resolves when the package.json file has been written.
import {writePackage, addPackageDependencies} from 'write-pkg';
await writePackage({foo: true});
//=> { "foo": true }
await addPackageDependencies({foo: '1.0.0'});
//=> { "foo": true, "dependencies": { "foo": "1.0.0" } }
await addPackageDependencies({dependencies: {foo: '1.0.0'}, devDependencies: {bar: '1.0.0'}});
//=> { "foo": true, "dependencies": { "foo": "1.0.0" }, "devDependencies": { "bar": "1.0.0" } }
Type: string
Default: process.cwd()
The path to where the package.json file should be written or its directory.
Type: Record<string, string> | Partial<Record<'dependencies' | 'devDependencies' | 'optionalDependencies' | 'peerDependencies', Record<string, string>>>
Dependencies to add to the package.json file.
Type: object
See Options.
Returns a Promise that resolves when the package.json file has been written. Does not throw if the file does not exist.
import {writePackage, removePackageDependencies} from 'write-pkg';
await writePackage({foo: true, dependencies: {foo: '1.0.0'}, devDependencies: {bar: '1.0.0'}});
//=> { "foo": true, "dependencies": { "foo": "1.0.0" }, "devDependencies": { "bar": "1.0.0" } }
await removePackageDependencies(['foo']);
//=> { "foo": true, "devDependencies": { "bar": "1.0.0" } }
await removePackageDependencies({devDependencies: ['bar']});
//=> { "foo": true }
Type: string
Default: process.cwd()
The path to where the package.json file should be written or its directory.
Type string[] | Partial<Record<'dependencies' | 'devDependencies' | 'optionalDependencies' | 'peerDependencies', string[]>>
Dependencies to remove from the package.json file.
Type: object
See Options.
Type: string | number
Default: Auto-detected or '\t'
The indentation to use for new files.
Accepts '\t' for tab indentation or a number of spaces.
If the file already exists, the existing indentation will be used.
Type: boolean
Default: true
Remove empty dependencies, devDependencies, optionalDependencies and peerDependencies objects.
Available as part of the Tidelift Subscription.
The maintainers of write-pkg and thousands of other packages are working with Tidelift to deliver commercial support and maintenance for the open source dependencies you use to build your applications. Save time, reduce risk, and improve code health, while paying the maintainers of the exact dependencies you use. Learn more.
package.json fileThe jsonfile package provides similar functionality for reading and writing JSON files. It is more general-purpose compared to write-pkg, which is specifically designed for package.json files. jsonfile can be used to read and write any JSON file, not just package.json.
The edit-json-file package allows you to easily read, edit, and write JSON files. It provides a more user-friendly API for modifying JSON files compared to write-pkg. It is also more general-purpose and can be used for any JSON file, not just package.json.
The fs-extra package extends the native Node.js fs module with additional methods for working with the file system, including methods for reading and writing JSON files. It is a more comprehensive solution for file system operations, including but not limited to JSON file manipulation.
FAQs
Write a package.json file
The npm package write-pkg receives a total of 931,225 weekly downloads. As such, write-pkg popularity was classified as popular.
We found that write-pkg demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Compromised intercom-client@7.0.4 npm package is tied to the ongoing Mini Shai-Hulud worm attack targeting developer and CI/CD secrets.

Research
Socket detected a malicious supply chain attack on PyPI package lightning versions 2.6.2 and 2.6.3, which execute credential-stealing malware on import.

Research
A brand-squatted TanStack npm package used postinstall scripts to steal .env files and exfiltrate developer secrets to an attacker-controlled endpoint.