npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2024 – Pkg Stats / Ryan Hefner

@amanda-mitchell/semantic-release-notify-dependabot

v1.0.8

Published

A semantic-release plugin to notify dependabot of private package releases.

Downloads

33

Readme

@amanda-mitchell/semantic-release-notify-dependabot

This is a plugin for Semantic Release that notifies Dependabot of package updates in private registries.

Installation

yarn add --dev @amanda-mitchell/semantic-release-notify-dependabot

Usage

The plugin can be configured in the semantic-release configuration file:

{
  "plugins": [
    "@semantic-release/commit-analyzer",
    "@semantic-release/release-notes-generator",
    "@amanda-mitchell/semantic-release-notify-dependabot"
  ]
}

Configuration

By default, this plugin will assume that you are publishing an npm package and will inspect the package.json in the current working directory for the package name.

Authentication

Authentication configuration is required and can be set via environment variables.

Dependabot uses GitHub personal access tokens for authentication (docs). This plugin will use DEPENDABOT_TOKEN if it is set, but will fall back to either GITHUB_TOKEN or GH_TOKEN if it is missing.

Environment variable

| Variable | Description | | ------------------------------------------------- | ------------------------------------------------------------- | | DEPENDABOT_TOKEN, GITHUB_TOKEN, or GH_TOKEN | Required. The token used to authenticate with Dependabot. |

Options

| Option | Description | Default | | ---------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------- | | packageManager | The package manager to which this package belongs. At the time of this writing, must be one of bundler, composer, docker, maven, npm_and_yarn, elm, submodules, hex, cargo, gradle, nuget, dep, go_modules, pip, terraform or github_actions (From the Dependabot API docs) | npm_and_yarn | | packageRoot | The directory holding the package.json for this package. (Ignored unless packageManager is npm_and_yarn) | Current working directory. | | packageName | The package name that should be sent to Dependabot. | The name field from package.json. |