5 ms·
Show HN: ZPDer – informs you when an NPM package you use is upgraded
- sillysaurus3 10y agoGood execution. Does this scan private repos?
- shaharsol 10y agoYes it does. This is btw why we ask for the "repo" permission and not only for "public-repo" permission.
- rickhanlonii 10y agoLove this idea, but can't connect a private repo to grant access to all our code. Any plans to allow uploading a package.json to achieve the same thing (understanding that it's my responsibility to keep it up to date)?
- shaharsol 10y agono plans for that yet but now that you raised the point...
- orliesaurus 10y agois this related to libraries.io by any chance?
- shaharsol 10y agonot at all. didn't even know it existed...
- itsbits 10y agois it only when a package is have wild cards like *, ^ in versions or all the time?
- shaharsol 10y agoAll the time. Even if you use a specific version, wouldn't you like to be in the know about the latest version, so you may consider upgrading?
- Klathmon 10y agoHow often does it send an email, and where is the changelog pulled from? So if 10 things update tomorrow will it get 10 emails? Can it be setup to run weekly or longer?
- shaharsol 10y agoA good thought. It sends an email on each upgrade, however in my experience it doesn't happen SO often, tops two-three times a day, depends of course on the volume of packages you use. But it's a good idea to have a daily digest, thanks for that.
- Klathmon 10y agoMy only request is that the email "digest" be configurable. Being able to set this up to notify me once per week, or even once per month would be awesome. I could spend that one time to upgrade my deps, then lock them back down again until the next one.
- shaharsol 10y agothe changelog is a link to the changelog or history.md in the github repo
- colemickens 10y agoSeems like https://greenkeeper.io/ https://greenkeeper.io/ is a similar idea with more polish (and with paid options). No affiliation, I've just seen GreenKeeper in action on the Kube Dashboard repo.
- chrisfosterelli 10y ago+1 for this. We've been using Greenkeeper on a number of projects and it's amazing!
- __derek__ 10y agoYes, this. Greenkeeper is excellent and produced by a great team.
- petetnt 10y agoHere's the source code, might be worth linking to on the page too: https://github.com/TikalLab/zpder https://github.com/TikalLab/zpder
- regularfry 10y agoObligatory: dependencyci.com, which does the a very similar thing.
- simlevesque 10y agoI run 'npm-check -u' [1] every morning on my develop branch and then I run my tests. I never thought about automating that part of my workflow. Sadly I don't host on GitHub. 1. https://www.npmjs.com/package/npm-check https://www.npmjs.com/package/npm-check
- eliaspro 10y agoAnd the duct-taping of the NPM ecosystem goes on and on and on...
- awinder 10y agoHow do you mean? There's some simple native support for checking if packages are outdated (npm outdated), and there's additional tooling that ties into various exposed APIs. If this is a comment on npm not just doing everything for everyone as part of the native package then... https://en.wikipedia.org/wiki/Unix_philosophy https://en.wikipedia.org/wiki/Unix_philosophy
- vonklaus 10y agoOne of my frustrations is updating submodule deps. The above link seems interesting, but most projects I work on are small enough that hovering over the dep in pckg.json file in vscode lets me know what is the latest. At the top level, I don't have much trouble managing updatea, however what about deps of deps and so on? It is hard to update these, and sometimes it breaks/is manual. Then it is overwritten when a new npm install ia run.