NPM
| source | condition | target |
|---|---|---|
✔ | ✔ | ✗ |
Description
The npm resource queries an npm registry for the versions of a package.
- source
Returns the version of the package matching
versionfilter.- condition
Checks that
versionis published for the package.- target
Not supported - a registry is not something Updatecli publishes to. A target fails with
Target not supported for the plugin Npm. To bump a dependency in a file, use the "JSON" resource againstpackage.json, or the npm autodiscovery crawler.
Note | An scm attached to a condition is ignored, with a warning (the lookup always goes to the registry). |
Parameters
| Name | Type | Description | Required |
|---|---|---|---|
| age | object | “age” defines the minimum or maximum age a release must have to be considered. compatible:
remark:
example:
| |
| maximum | string | “maximum” defines the maximum age a release may have to be considered. remark:
example:
| |
| minimum | string | “minimum” defines the minimum age a release must have to be considered. remark:
example:
| |
| name | string | “name” defines the npm package name. compatible:
remark:
example:
| |
| npmrcpath | string | “npmrcpath” defines the path of the .npmrc file. compatible:
default: $HOME/.npmrc remark:
| |
| registrytoken | string | “registrytoken” defines the token used to authenticate with the registry set by “url”. compatible:
| |
| url | string | “url” defines the npm registry url. compatible:
default: https://registry.npmjs.org/ remark:
| |
| version | string | “version” defines the package version to check. compatible:
default: the output of the associated source. | |
| versionfilter | object | “versionfilter” defines the version pattern and its kind, such as “regex”, “semver” or “latest”. compatible:
default: latest remark:
| |
| kind | string | “kind” defines the versioning scheme used to select a version. default: latest remark:
example:
| |
| pattern | string | “pattern” defines the version pattern, according to “kind”. default:
remark:
example:
| |
| regex | string | “regex” defines the regular expression extracting the version from each entry. remark:
example:
| |
| replaceall | object | “replaceall” applies a regular expression replacement to each version before filtering. remark:
example: turns “curl-8_15_0” into “curl-8.15.0”. | |
| strict | boolean | “strict” enforces strict semantic versioning rules when parsing versions. default: false remark:
|
nameThe package name, scope included:
@updatecli/updateclias well asexpress.urlDefaults to
https://registry.npmjs.org/.versionCondition only - the version whose existence is being checked.
Version selection
versionfilter behaves differently here than on most resources: with kind: latest, the value is taken from the registry’s own dist-tags.latest, which is what npm install <pkg> would give you (not the highest version number).
Every other filter kind sorts the full version list and applies the pattern. That distinction matters for packages that publish patches for older majors after a new major: latest follows the maintainer’s tag, semver follows the numbering. See the "Version Filtering" page.
Authentication
Private registries are reached in one of two ways.
registrytoken sets the bearer token directly, keep it out of the manifest:
spec:
name: "@acme/widget"
url: "https://npm.acme.example.com"
registrytoken: '{{ requiredEnv "NPM_TOKEN" }}'npmrcpath points at an .npmrc file instead. Its handling has a fallback worth knowing about:
Important | When |
From an .npmrc, Updatecli reads two kinds of entry:
//registry.example.com/:_authToken=xxx- a token per registry@scope:registry=https://registry.example.com- a registry per scope
Example
# updatecli.yaml
name: NPM resource example
sources:
axios:
name: Get latest axios version from npm registry
kind: npm
spec:
name: axios
yaml:
name: get latest yaml version matching ~0
kind: npm
spec:
name: yaml
versionfilter:
kind: semver
pattern: ~0
conditions:
axios:
name: Test that axios version 1.0.0 exists on the NPM registry
kind: npm
disablesourceinput: true
spec:
name: axios
version: 1.0.0
yaml:
name: Test that that YAML version matching ~0 exist on registry
kind: npm
sourceid: yaml
spec:
name: yaml
targets:
# Targets are not supported