4 ms·
Now's as good a time as any to ask: What tools do you folks use to monitor your node dependencies and make sure you are keeping everything up to date?
by libertymcateer 9y ago
Now's as good a time as any to ask:
What tools do you folks use to monitor your node dependencies and make sure you are keeping everything up to date?
- djslakor 9y agonpm outdated -l
- ronjouch 9y agoBut in addition to that, how do you "update all and bump relevant package.json entries, dependencies _and_ devDependencies as appropriate" ? `npm update --save` or `npm update --save-dev` say explicitly "save updates to `dependencies` resp. `devDependencies`", which causes duplication between dependencies and devDependencies. (Say you have a dep foo and a devDep bar and both are outdated: `npm update --save` will bork package.json with an additional incorrect dep bar, and `npm update --save-dev` will bork it with an additional incorrect devDep foo :-/ ) Am I missing something? I understand there are 3rd-party packages providing such functionality, but is there any reason to not cover this feature in npm?
- Osiris 9y agoI use npm-check-updates[1] which will update the package.json file with the latest versions of each dependency. [1] https://www.npmjs.com/package/npm-check-updates https://www.npmjs.com/package/npm-check-updates
- ronjouch 9y agoYeah that's the package I meant with "3rd-party packages providing such functionality", thanks for pointing it out :) ! Was wondering if there was a reason other than "because no one developed it" for such a feature not being in npm core.
- ameesdotme 9y agoI just regularly run `yarn upgrade-interactive` in my projects. I was thinking of making dependency-updates part of the CI-pipeline, using a 'allow_failure'-flag. However, if you decide not to upgrade a dep for some reason, this will cause each and every build to throw a warning.
- Androider 9y agohttps://www.npmjs.com/package/npm-check-updates https://www.npmjs.com/package/npm-check-updates is a small command line utility that will report which dependencies are out of date, and can also upgrade your package.json from the CLI while maintaining your existing semantic versioning policies and ranges across an upgrade (instead of just bumping for every minor update). Mostly I just really like the compact output, and the short "ncu" command which I run every day to check what's available :)
- workerIbe 9y agoDefinitely something to the addage "if it ain't broke don't fix it". Some of our less critical modules are set to latest others are updated with care. Our modules are not under source control so are refreshed on deployment. We use Snyk to monitor for vulnerabilities, works pretty well.
- allover 9y agoAre you at least checking in your npm-shrinkwrap.json? (If not you've got pain waiting to happen, that you won't find out about until deploy time)!
- rubber_duck 9y agoThis so much - shrinkwrap before it bites you when a CI kicks off a deploy that fails because it pulled latest minor dep release that broke everything (happened even in big lib like Angular 2 for us after stable 2.2 !) while your local box is running fine with a cached older version.
- kevinmannix 9y agoYes. I've had an app break due to a dependency's dependency update. Was the night before a big product launch. Learned to rely on npm-shrinkwrap the hard way.