3 ms·
There is a ‘npm audit’ command but that checks for known versions of a package that have a vulnerability so it’s not a static analyzer as far as I know.
by styfle 8y ago
There is a ‘npm audit’ command but that checks for known versions of a package that have a vulnerability so it’s not a static analyzer as far as I know.
- _greim_ 8y agoYeah I am thinking more something like linting+ for packages. And for published code, not code from the git repo. % analyze-some-npm-package some-package@2.1.1 → some-package/foo.js contains a syntax error → some-package/bar.js calls eval() on line blah blah → sub-dependency@2.3.4 is only 2 hours old ...that sort of thing. I suppose it would be a pretty big undertaking.
- styfle 8y agoI think all of those cases are possible today, you just need the right tools. For example: 1. contains a syntax error: this is solved with TypeScript or flow which can run against a .js file 2. calls to eval(): this is solved by linting the .js file 3. only 2 hours old: this is solved by looking at npm publish date for the package version...take a look at the "time" key here: https://registry.npmjs.com/eslint-scope https://registry.npmjs.com/eslint-scope