IBM / audit-ci
Audit NPM, Yarn, PNPM, and Bun dependencies in continuous integration environments, preventing integration if vulnerabilities are found at or above a configurable threshold while ignoring allowlisted advisories
☆269Updated 7 months ago
Alternatives and similar repositories for audit-ci:
Users that are interested in audit-ci are comparing it to the libraries listed below
- Lint an npm or yarn lockfile to analyze and detect security issues☆792Updated 7 months ago
- Configurable linter for package.json files☆235Updated this week
- semantic-release plugin to publish a npm package☆259Updated this week
- ☆124Updated 2 years ago
- Keep watch of your bundle size☆425Updated last week
- A command line tool for bulk-updating lerna package dependencies☆268Updated last year
- Suppress existing violations of new eslint rules and get back to building stuff.☆192Updated last week
- ✨ JSON schema matcher for Jest☆170Updated 8 months ago
- 📦:🛠✨💥 – fully automated package publishing☆686Updated last year
- Proof of concept that wraps semantic-release to work with monorepos.☆208Updated last week
- The goal of this project is to provide additional features on top of the existing npm audit options☆123Updated 7 months ago
- ESLint rules for formatting test suites written for jest.☆154Updated last year
- 🍺 dev only postinstall hooks (package.json)☆261Updated 2 years ago
- The missing `yarn audit fix`☆186Updated 2 weeks ago
- Proof of concept that wraps semantic-release to work with monorepos.☆87Updated 8 months ago
- JSON Schema validation for Human 👨🎤☆237Updated this week
- Report jest test errors directly in pull requests☆106Updated this week
- semantic-release-plus monorepo to build and publish all semantic-release related repositories☆74Updated 10 months ago
- A server for TurboRepo Remote Cache to store cache artefacts in Google Cloud Storage or Amazon S3☆145Updated last year
- Detect if the current environment is a CI server☆390Updated 4 months ago
- Get environment variables exposed by CI services☆231Updated this week
- 🌐📈 Automatically bump up global Jest thresholds whenever coverage goes above them☆64Updated 7 months ago
- Get details about the current Continuous Integration environment☆336Updated last month
- A simple measure of software dependency freshness.☆100Updated this week
- Additional ESLint rules for directive comments of ESLint.☆365Updated last year
- An eslint plugin to find strings that might be secrets/credentials☆147Updated 2 months ago
- Wait for expectation to be true, useful for integration and end to end testing. Integral part of react-testing-library.☆296Updated last year
- ESLint rule that reports usage of deprecated code☆334Updated 6 months ago
- 📦 🚀 A slack bot for semantic-release notifying release statuses☆116Updated 7 months ago
- A Jest reporter that creates compatible junit xml files☆493Updated 4 months ago