NPM
Description
The npm crawler looks recursively for every package.json file from a specific root directory, and tries to update the dependencies declared in dependencies and devDependencies.
This crawler is enabled by default, so it can be used either automatically by running updatecli diff from a directory containing the files to update, or by providing a manifest.
The automatic discovery behavior can be tuned by providing a YAML manifest with an npm crawler in top-level directive autodiscovery as explained in the "Autodiscovery" page.
Requirements
What the crawler generates depends on which lock file sits next to package.json, and on which package manager is installed where Updatecli runs.
| Lock file | Command available | Result |
|---|---|---|
none | - |
|
|
| A shell target runs |
|
| A shell target refreshes |
|
| A shell target runs |
any of the above | its command missing | The whole |
Important | The lock file decides which command is required, not what is installed. A project with a yarn.lock is skipped when yarn is absent, even when npm is available. |
Dry-run support
npm version 8 and later can update a yarn.lock, and unlike yarn it supports a dry run. So when a yarn.lock is found and npm is recent enough, Updatecli generates the npm command in preference to the yarn one.
Warning | When Updatecli has to fall back to yarn add --mode update-lockfile or pnpm add --lockfile-only, neither supports a dry run. updatecli diff will then modify the lock file on disk rather than only reporting the change. Installing npm 8 or later avoids this for yarn projects. |
Generated manifests
Version constraints
A dependency declared with a range, such as ^4.18.0 or ~29.7.0, keeps that constraint by default: the range is respected when looking for a newer version.
Set ignoreversionconstraints: true to disregard the declared range and offer the latest published version instead.
Manifest
Parameters
| Name | Type | Description | Required |
|---|---|---|---|
| age | object | “age” defines the minimum or maximum age of a release to be considered valid. default: remark:
| |
| maximum | string | “maximum” defines the maximum age a release may have to be considered. remark:
example:
| |
| minimum | string | “minimum” defines the minimum age a release must have to be considered. remark:
example:
| |
| ignore | array | “ignore” defines rules to exclude matching npm packages from the autodiscovery. remark:
| |
| hasversionconstraint | boolean | “hasversionconstraint” defines whether the package must be declared with a version constraint. example:
| |
| packages | object | “packages” defines the npm packages to match, keyed by package name. remark:
| |
| path | string | “path” defines a package.json path pattern. remark:
| |
| ignoreversionconstraints | boolean | “ignoreversionconstraints” defines whether the version constraints set in package.json are ignored. When true, a package declared with a version constraint is updated to the latest version accepted by “versionfilter”, instead of the latest version accepted by the constraint. default: false remark:
| |
| npmrcpath | string | “npmrcpath” defines the path of the .npmrc file used by every discovered package. remark:
| |
| only | array | “only” defines rules to restrict the autodiscovery to matching npm packages. remark:
| |
| hasversionconstraint | boolean | “hasversionconstraint” defines whether the package must be declared with a version constraint. example:
| |
| packages | object | “packages” defines the npm packages to match, keyed by package name. remark:
| |
| path | string | “path” defines a package.json path pattern. remark:
| |
| registrytoken | string | “registrytoken” defines the token used to authenticate with the registry. remark:
| |
| rootdir | string | “rootdir” defines the directory where the crawler starts searching for package.json files. default: the scm directory when “scmid” is set, otherwise the directory relative paths resolve from, by default the working directory. remark:
| |
| url | string | “url” defines the npm registry url. default: https://registry.npmjs.org/ remark:
| |
| versionfilter | object | “versionfilter” defines the version filter used by the generated manifests. default:
remark:
example: | |
| kind | string | “kind” defines the versioning scheme used to select a version. default: latest remark:
example:
| |
| pattern | string | “pattern” defines the version pattern, according to “kind”. default:
remark:
example:
| |
| regex | string | “regex” defines the regular expression extracting the version from each entry. remark:
example:
| |
| replaceall | object | “replaceall” applies a regular expression replacement to each version before filtering. remark:
example: turns “curl-8_15_0” into “curl-8.15.0”. | |
| pattern | string | “pattern” defines the regular expression matching the text to replace. example:
| |
| replacement | string | “replacement” defines the text replacing each match of “pattern”. remark:
example:
| |
| strict | boolean | “strict” enforces strict semantic versioning rules when parsing versions. default: false remark:
| |
| vulnerability | object | “vulnerability” switches the autodiscovery to security updates, based on the OSV database (https://osv.dev). A package is only updated when its current version has known vulnerabilities, to the lowest version without any. remark:
example: | |
| ignore | array | “ignore” defines the vulnerability IDs or aliases to disregard. example: | |
| minseverity | string | “minseverity” defines the minimum severity of the vulnerabilities to account for. remark:
example:
| |
| strategy | string | “strategy” defines the version a vulnerable dependency is updated to. default: lowest remark:
| |
| url | string | “url” defines the OSV API URL. default: https://api.osv.dev |
Example
Basic Example
# updatecli.d/npm.yaml
autodiscovery:
crawlers:
npm:
rootdir: "."
versionfilter:
kind: semver
pattern: minorPrivate Registry Example
The following example shows how to configure npm autodiscovery to work with a private npm registry:
# updatecli.d/npm-private.yaml
autodiscovery:
crawlers:
npm:
rootdir: "."
# URL of your private npm registry
url: "https://npm.example.com"
# Authentication token (use environment variables for security)
registrytoken: "${NPM_TOKEN}"
# Optional: path to custom .npmrc file
npmrcpath: "/path/to/.npmrc"
versionfilter:
kind: semver
pattern: ">=1.0.0"Note | The url, registrytoken, and npmrcpath parameters are propagated to all generated npm resource specs, allowing consistent authentication across all discovered dependencies. |