Installations
npm install @monodeploy/io
Developer Guide
Typescript
Yes
Module System
CommonJS
Score
60
Supply Chain
64.6
Quality
77.4
Maintenance
100
Vulnerability
99.6
License
Releases
@monodeploy/plugin-github@2.0.2
Published on 02 Jul 2024
monodeploy@5.0.2
Published on 02 Jul 2024
@monodeploy/plugin-github@2.0.1
Published on 14 Nov 2023
monodeploy@5.0.1
Published on 14 Nov 2023
@monodeploy/plugin-github@2.0.0
Published on 09 Nov 2023
monodeploy@5.0.0
Published on 09 Nov 2023
Contributors
Unable to fetch Contributors
Languages
TypeScript (91.87%)
MDX (5.05%)
JavaScript (2.39%)
CSS (0.5%)
Shell (0.11%)
Dockerfile (0.08%)
Developer
Download Statistics
Total Downloads
58,634
Last Day
29
Last Week
126
Last Month
953
Last Year
12,009
GitHub Statistics
106 Stars
869 Commits
7 Forks
2 Watching
7 Branches
14 Contributors
Bundle Size
31.71 kB
Minified
9.56 kB
Minified + Gzipped
Package Meta Information
Latest Version
5.0.2
Package Id
@monodeploy/io@5.0.2
Unpacked Size
36.70 kB
Size
8.82 kB
File Count
19
Publised On
02 Jul 2024
Total Downloads
Cumulative downloads
Total Downloads
58,634
Last day
-59.2%
29
Compared to previous day
Last week
-54.5%
126
Compared to previous week
Last month
-12.2%
953
Compared to previous month
Last year
-52.9%
12,009
Compared to previous year
Daily Downloads
Weekly Downloads
Monthly Downloads
Yearly Downloads
monodeploy
Monodeploy is a powerful tool which aims to simplify the package publishing process for monorepos. It leverages Yarn Berry workspaces to do the heavy lifting, and is a direct replacement for tools such as Lerna and Semantic Release.
Monodeploy only supports projects using Yarn Modern v4+ with the minimum node version set to Node v18.12.0.
Please see the Monodeploy Website for information on how to get started with Monodeploy.
Note About Monodeploy Package Versioning
Only the monodeploy
package is "public" and follows strict semantic versioning. The other packages such as @monodeploy/changelog
are meant for internal use and may change their APIs at any time.
Contributing
See the Contributing Guide for setup instructions, tips, and guidelines.
Contributors
Thanks goes to these wonderful people (emoji key):
This project follows the all-contributors specification. Contributions of any kind welcome!
Credits
Special thanks to Carol Skelly for donating the 'tophat' GitHub organization.
No vulnerabilities found.
Reason
no dangerous workflow patterns detected
Reason
no binaries found in the repo
Reason
license file detected
Details
- Info: project has a license file: LICENSE:0
- Info: FSF or OSI recognized license: Apache License 2.0: LICENSE:0
Reason
dependency not pinned by hash detected -- score normalized to 6
Details
- Warn: containerImage not pinned by hash: e2e-tests/Dockerfile:1: pin your Docker image by updating node:20-slim to node:20-slim@sha256:626b719f38532dfe02d806bc64161d94d951ec4ade80494f5d0407bed08c3f5c
- Warn: downloadThenRun not pinned by hash: .github/codecov.sh:11
- Warn: downloadThenRun not pinned by hash: .github/codecov.sh:13
- Info: 17 out of 17 GitHub-owned GitHubAction dependencies pinned
- Info: 2 out of 2 third-party GitHubAction dependencies pinned
- Info: 0 out of 1 containerImage dependencies pinned
- Info: 0 out of 2 downloadThenRun dependencies pinned
Reason
project is archived
Details
- Warn: Repository is archived.
Reason
Found 0/25 approved changesets -- score normalized to 0
Reason
detected GitHub workflow tokens with excessive permissions
Details
- Warn: no topLevel permission defined: .github/workflows/pull-request.yml:1
- Warn: no topLevel permission defined: .github/workflows/release.yml:1
- Info: no jobLevel write permissions found
Reason
no effort to earn an OpenSSF best practices badge detected
Reason
security policy file not detected
Details
- Warn: no security policy file detected
- Warn: no security file to analyze
- Warn: no security file to analyze
- Warn: no security file to analyze
Reason
project is not fuzzed
Details
- Warn: no fuzzer integrations found
Reason
SAST tool is not run on all commits -- score normalized to 0
Details
- Warn: 0 commits out of 28 are checked with a SAST tool
Reason
35 existing vulnerabilities detected
Details
- Warn: Project is vulnerable to: GHSA-wf5p-g6vw-rhxx
- Warn: Project is vulnerable to: GHSA-qwcr-r2fm-qrc7
- Warn: Project is vulnerable to: GHSA-grv7-fg5c-xmjg
- Warn: Project is vulnerable to: GHSA-pxg6-pf52-xh8x
- Warn: Project is vulnerable to: GHSA-3xgq-45jj-v275
- Warn: Project is vulnerable to: GHSA-q9mw-68c2-j6m5
- Warn: Project is vulnerable to: GHSA-4gmj-3p3h-gm8h
- Warn: Project is vulnerable to: GHSA-rv95-896h-c2vc
- Warn: Project is vulnerable to: GHSA-qw6h-vgh9-j6wx
- Warn: Project is vulnerable to: GHSA-jchw-25xp-jwwc
- Warn: Project is vulnerable to: GHSA-cxjh-pqwp-8mfp
- Warn: Project is vulnerable to: GHSA-pfrx-2q88-qq97
- Warn: Project is vulnerable to: GHSA-78xj-cgh5-2h22
- Warn: Project is vulnerable to: GHSA-2p57-rm9w-gvfp
- Warn: Project is vulnerable to: GHSA-35jh-r3h4-6jhm
- Warn: Project is vulnerable to: GHSA-952p-6rrq-rcjv
- Warn: Project is vulnerable to: GHSA-7hpj-7hhx-2fgx
- Warn: Project is vulnerable to: GHSA-mwcw-c2x4-8c55
- Warn: Project is vulnerable to: GHSA-9wv6-86v2-598j
- Warn: Project is vulnerable to: GHSA-rhx6-c78j-4q9w
- Warn: Project is vulnerable to: GHSA-7fh5-64p2-3v2j
- Warn: Project is vulnerable to: GHSA-rjqq-98f6-6j3r
- Warn: Project is vulnerable to: GHSA-mjxr-4v3x-q3m4
- Warn: Project is vulnerable to: GHSA-cgfm-xwp7-2cvr
- Warn: Project is vulnerable to: GHSA-rm97-x556-q36h
- Warn: Project is vulnerable to: GHSA-c2qf-rxjj-qqgw
- Warn: Project is vulnerable to: GHSA-m6fv-jmcg-4jfg
- Warn: Project is vulnerable to: GHSA-cm22-4g7w-348p
- Warn: Project is vulnerable to: GHSA-54xq-cgqr-rpm3
- Warn: Project is vulnerable to: GHSA-25hc-qcg6-38wj
- Warn: Project is vulnerable to: GHSA-f5x3-32g6-xq36
- Warn: Project is vulnerable to: GHSA-cf4h-3jhx-xvhq
- Warn: Project is vulnerable to: GHSA-4vvj-4cpr-p986
- Warn: Project is vulnerable to: GHSA-wr3j-pwj9-hqq6
- Warn: Project is vulnerable to: GHSA-3h5v-q93c-6h6q
Score
3.2
/10
Last Scanned on 2025-01-27
The Open Source Security Foundation is a cross-industry collaboration to improve the security of open source software (OSS). The Scorecard provides security health metrics for open source projects.
Learn More