IBM / audit-ci
Audit NPM, Yarn, PNPM, and Bun dependencies in continuous integration environments, preventing integration if vulnerabilities are found at or above a configurable threshold while ignoring allowlisted advisories
☆266Updated 6 months ago
Alternatives and similar repositories for audit-ci:
Users that are interested in audit-ci are comparing it to the libraries listed below
- Configurable linter for package.json files☆235Updated last week
- Get details about the current Continuous Integration environment☆332Updated 2 weeks ago
- Lint an npm or yarn lockfile to analyze and detect security issues☆790Updated 6 months ago
- A command line tool for bulk-updating lerna package dependencies☆269Updated last year
- 🍺 dev only postinstall hooks (package.json)☆261Updated 2 years ago
- The missing `yarn audit fix`☆186Updated last week
- ☆123Updated last year
- Suppress existing violations of new eslint rules and get back to building stuff.☆191Updated this week
- GitHub Action for install npm dependencies with caching without any configuration☆662Updated 3 weeks ago
- Detect if the current environment is a CI server☆390Updated 3 months ago
- Additional ESLint rules for directive comments of ESLint.☆365Updated last year
- Keep watch of your bundle size☆424Updated 6 months ago
- semantic-release-plus monorepo to build and publish all semantic-release related repositories☆72Updated 9 months ago
- Build 🛠 and Bundle 📦 your local workspaces. Like Bazel, Buck, Pants and Please but for Yarn Berry. Build any language, mix javascript, …☆329Updated last year
- ✨ JSON schema matcher for Jest☆170Updated 8 months ago
- 📦:🛠✨💥 – fully automated package publishing☆686Updated 11 months ago
- ESLint rules for formatting test suites written for jest.☆154Updated last year
- An eslint plugin to find strings that might be secrets/credentials☆144Updated last month
- The goal of this project is to provide additional features on top of the existing npm audit options☆123Updated 6 months ago
- semantic-release plugin to publish a npm package☆257Updated this week
- A JavaScript library to mock the local timezone☆107Updated 2 years ago
- Report jest test errors directly in pull requests☆106Updated this week
- This module adds [Server-Timing](https://www.w3.org/TR/server-timing/) to response headers, see [example](https://server-timing.now.sh/) …☆126Updated 2 weeks ago
- 📦 🚀 A slack bot for semantic-release notifying release statuses☆116Updated 6 months ago
- A Jest runner that runs tests directly in bare Node.js, without virtualizing the environment.☆236Updated last year
- Get environment variables exposed by CI services☆230Updated this week
- Proof of concept that wraps semantic-release to work with monorepos.☆87Updated 7 months ago
- Fully extendable eslint plugin for JSON i18n translation files.☆184Updated 3 months ago
- Proof of concept that wraps semantic-release to work with monorepos.☆207Updated last week
- 🌐📈 Automatically bump up global Jest thresholds whenever coverage goes above them☆64Updated 6 months ago