Installations
npm install @monodeploy/versions
Developer Guide
Typescript
Yes
Module System
CommonJS
Score
40.9
Supply Chain
52.2
Quality
75.6
Maintenance
100
Vulnerability
97.3
License
Releases
@monodeploy/plugin-github@2.0.2
Published on 02 Jul 2024
monodeploy@5.0.2
Published on 02 Jul 2024
@monodeploy/plugin-github@2.0.1
Published on 14 Nov 2023
monodeploy@5.0.1
Published on 14 Nov 2023
@monodeploy/plugin-github@2.0.0
Published on 09 Nov 2023
monodeploy@5.0.0
Published on 09 Nov 2023
Contributors
Unable to fetch Contributors
Languages
TypeScript (91.87%)
MDX (5.05%)
JavaScript (2.39%)
CSS (0.5%)
Shell (0.11%)
Dockerfile (0.08%)
Developer
Download Statistics
Total Downloads
56,806
Last Day
13
Last Week
124
Last Month
1,085
Last Year
10,029
GitHub Statistics
106 Stars
869 Commits
7 Forks
2 Watching
7 Branches
14 Contributors
Bundle Size
78.68 kB
Minified
25.57 kB
Minified + Gzipped
Package Meta Information
Latest Version
5.0.2
Package Id
@monodeploy/versions@5.0.2
Unpacked Size
57.93 kB
Size
12.26 kB
File Count
19
Publised On
02 Jul 2024
Total Downloads
Cumulative downloads
Total Downloads
56,806
Last day
-7.1%
13
Compared to previous day
Last week
-68%
124
Compared to previous week
Last month
13.1%
1,085
Compared to previous month
Last year
-61.7%
10,029
Compared to previous year
Daily Downloads
Weekly Downloads
Monthly Downloads
Yearly Downloads
Dependencies
4
Peer Dependencies
11
Dev Dependencies
17
monodeploy
Monodeploy is a powerful tool which aims to simplify the package publishing process for monorepos. It leverages Yarn Berry workspaces to do the heavy lifting, and is a direct replacement for tools such as Lerna and Semantic Release.
Monodeploy only supports projects using Yarn Modern v4+ with the minimum node version set to Node v18.12.0.
Please see the Monodeploy Website for information on how to get started with Monodeploy.
Note About Monodeploy Package Versioning
Only the monodeploy
package is "public" and follows strict semantic versioning. The other packages such as @monodeploy/changelog
are meant for internal use and may change their APIs at any time.
Contributing
See the Contributing Guide for setup instructions, tips, and guidelines.
Contributors
Thanks goes to these wonderful people (emoji key):
This project follows the all-contributors specification. Contributions of any kind welcome!
Credits
Special thanks to Carol Skelly for donating the 'tophat' GitHub organization.
No vulnerabilities found.
Reason
no dangerous workflow patterns detected
Reason
no binaries found in the repo
Reason
license file detected
Details
- Info: project has a license file: LICENSE:0
- Info: FSF or OSI recognized license: Apache License 2.0: LICENSE:0
Reason
dependency not pinned by hash detected -- score normalized to 6
Details
- Warn: containerImage not pinned by hash: e2e-tests/Dockerfile:1: pin your Docker image by updating node:20-slim to node:20-slim@sha256:f44fa8d6d0ef15fe252459ac5d3d178362231a7948d7d07e147bae891006e2e5
- Warn: downloadThenRun not pinned by hash: .github/codecov.sh:11
- Warn: downloadThenRun not pinned by hash: .github/codecov.sh:13
- Info: 17 out of 17 GitHub-owned GitHubAction dependencies pinned
- Info: 2 out of 2 third-party GitHubAction dependencies pinned
- Info: 0 out of 1 containerImage dependencies pinned
- Info: 0 out of 2 downloadThenRun dependencies pinned
Reason
project is archived
Details
- Warn: Repository is archived.
Reason
Found 0/25 approved changesets -- score normalized to 0
Reason
detected GitHub workflow tokens with excessive permissions
Details
- Warn: no topLevel permission defined: .github/workflows/pull-request.yml:1
- Warn: no topLevel permission defined: .github/workflows/release.yml:1
- Info: no jobLevel write permissions found
Reason
no effort to earn an OpenSSF best practices badge detected
Reason
security policy file not detected
Details
- Warn: no security policy file detected
- Warn: no security file to analyze
- Warn: no security file to analyze
- Warn: no security file to analyze
Reason
project is not fuzzed
Details
- Warn: no fuzzer integrations found
Reason
SAST tool is not run on all commits -- score normalized to 0
Details
- Warn: 0 commits out of 28 are checked with a SAST tool
Reason
35 existing vulnerabilities detected
Details
- Warn: Project is vulnerable to: GHSA-wf5p-g6vw-rhxx
- Warn: Project is vulnerable to: GHSA-qwcr-r2fm-qrc7
- Warn: Project is vulnerable to: GHSA-grv7-fg5c-xmjg
- Warn: Project is vulnerable to: GHSA-pxg6-pf52-xh8x
- Warn: Project is vulnerable to: GHSA-3xgq-45jj-v275
- Warn: Project is vulnerable to: GHSA-q9mw-68c2-j6m5
- Warn: Project is vulnerable to: GHSA-4gmj-3p3h-gm8h
- Warn: Project is vulnerable to: GHSA-rv95-896h-c2vc
- Warn: Project is vulnerable to: GHSA-qw6h-vgh9-j6wx
- Warn: Project is vulnerable to: GHSA-jchw-25xp-jwwc
- Warn: Project is vulnerable to: GHSA-cxjh-pqwp-8mfp
- Warn: Project is vulnerable to: GHSA-pfrx-2q88-qq97
- Warn: Project is vulnerable to: GHSA-78xj-cgh5-2h22
- Warn: Project is vulnerable to: GHSA-2p57-rm9w-gvfp
- Warn: Project is vulnerable to: GHSA-35jh-r3h4-6jhm
- Warn: Project is vulnerable to: GHSA-952p-6rrq-rcjv
- Warn: Project is vulnerable to: GHSA-7hpj-7hhx-2fgx
- Warn: Project is vulnerable to: GHSA-mwcw-c2x4-8c55
- Warn: Project is vulnerable to: GHSA-9wv6-86v2-598j
- Warn: Project is vulnerable to: GHSA-rhx6-c78j-4q9w
- Warn: Project is vulnerable to: GHSA-7fh5-64p2-3v2j
- Warn: Project is vulnerable to: GHSA-rjqq-98f6-6j3r
- Warn: Project is vulnerable to: GHSA-mjxr-4v3x-q3m4
- Warn: Project is vulnerable to: GHSA-cgfm-xwp7-2cvr
- Warn: Project is vulnerable to: GHSA-rm97-x556-q36h
- Warn: Project is vulnerable to: GHSA-c2qf-rxjj-qqgw
- Warn: Project is vulnerable to: GHSA-m6fv-jmcg-4jfg
- Warn: Project is vulnerable to: GHSA-cm22-4g7w-348p
- Warn: Project is vulnerable to: GHSA-54xq-cgqr-rpm3
- Warn: Project is vulnerable to: GHSA-25hc-qcg6-38wj
- Warn: Project is vulnerable to: GHSA-f5x3-32g6-xq36
- Warn: Project is vulnerable to: GHSA-cf4h-3jhx-xvhq
- Warn: Project is vulnerable to: GHSA-4vvj-4cpr-p986
- Warn: Project is vulnerable to: GHSA-wr3j-pwj9-hqq6
- Warn: Project is vulnerable to: GHSA-3h5v-q93c-6h6q
Score
3.2
/10
Last Scanned on 2024-12-16
The Open Source Security Foundation is a cross-industry collaboration to improve the security of open source software (OSS). The Scorecard provides security health metrics for open source projects.
Learn More