| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
| Name | Name | Last commit date | ||
|---|---|---|---|---|
parent directory.. | ||||
a Node.js CLI to deeply analyze the dependency tree of a given NPM package or Node.js local app
$ npm install @nodesecure/cli -gor, from source (this package lives in the NodeSecure/cli monorepo):
$ git clone https://github.com/NodeSecure/cli.git
$ cd cli
$ npm install
# bundle/compile front-end assets for every workspace
$ npm run build
$ cd workspaces/cli
$ npm linkThen the nsecure binary will be available in your terminal. Give a try with the popular express package. This will automatically open the webpage in your default system browser.
$ nsecure auto expressTip
Setup an npm token to avoid hiting the maximum request limit of the npm registry API.
# Run a scan on the current working dir
# Note: must have a package.json or node_modules directory
$ nsecure cwd
# Run a scan on a remote 'npm' package
$ nsecure from mochaThen a nsecure-result.json will be writted at the current CLI location. To open it on a web page just run
$ nsecure openThe CLI includes built-in documentation accessible with the --help option:
$ nsecure --help
$ nsecure <command> --helpFor complete details on each command, refer to the following documents:
Each link provides access to the full documentation for the command, including additional details, options, and usage examples.
NodeSecure allow you to fetch stats on private npm packages by setting up a NODE_SECURE_TOKEN env variable (which must contains an npm token).
Tip
If you npm link the package by yourself you can create a .env file at the root of the project too.
NodeSecure is capable to work behind a custom private npm registry too by searching the default registry URL in your local npm configuration.
$ npm config get registry
$ npm config set registry "http://your-registry/"Our back-end scanner package is available here.
Flags and emojis legends are documented here.
Press Cmd+K (macOS) or Ctrl+K (Windows/Linux) from the network view to open the search command. It lets you filter the dependency graph using one or more criteria simultaneously.
Type a package name directly to search, or prefix with a filter name followed by : to use a specific filter:
Nodes are highlighted in red when the project/package is flagged with 🔬 hasMinifiedCode or ⚠️ hasWarnings. You can deactivate specific warnings in the options if desired.
The back-end scanner will analyze the complete size of the npm tarball without any filters or specific optimizations. In contrast, Bundlephobia will bundle the package and remove most of the unnecessary files from the tarball, such as documentation and other non-essential items.
Note
We run a weekly Scorecard scan of the 1 million most critical open source projects judged by their direct dependencies and publish the results in a BigQuery public dataset.
MIT
| Back | FazBrowse Home | New Git URL |