Get details about the current Continuous Integration environment
Installations
npm install ci-info
Developer
watson
Developer Guide
Module System
CommonJS
Min. Node Version
>=8
Typescript Support
No
Node Version
22.11.0
NPM Version
10.9.0
Statistics
325 Stars
194 Commits
50 Forks
9 Watching
1 Branches
30 Contributors
Updated on 25 Nov 2024
Languages
JavaScript (100%)
Total Downloads
Cumulative downloads
Total Downloads
8,825,622,815
Last day
-1.5%
11,658,598
Compared to previous day
Last week
4.7%
62,781,623
Compared to previous week
Last month
21.5%
245,427,945
Compared to previous month
Last year
7.2%
2,419,622,669
Compared to previous year
Daily Downloads
Weekly Downloads
Monthly Downloads
Yearly Downloads
Dev Dependencies
4
ci-info
Get details about the current Continuous Integration environment.
Please open an issue if your CI server isn't properly detected :)
Installation
1npm install ci-info --save
Usage
1var ci = require('ci-info') 2 3if (ci.isCI) { 4 console.log('The name of the CI server is:', ci.name) 5} else { 6 console.log('This program is not running on a CI server') 7}
Supported CI tools
Officially supported CI servers:
Name | Constant | isPR |
---|---|---|
Agola CI | ci.AGOLA | ✅ |
Appcircle | ci.APPCIRCLE | ✅ |
AppVeyor | ci.APPVEYOR | ✅ |
AWS CodeBuild | ci.CODEBUILD | ✅ |
Azure Pipelines | ci.AZURE_PIPELINES | ✅ |
Bamboo by Atlassian | ci.BAMBOO | 🚫 |
Bitbucket Pipelines | ci.BITBUCKET | ✅ |
Bitrise | ci.BITRISE | ✅ |
Buddy | ci.BUDDY | ✅ |
Buildkite | ci.BUILDKITE | ✅ |
CircleCI | ci.CIRCLE | ✅ |
Cirrus CI | ci.CIRRUS | ✅ |
Codefresh | ci.CODEFRESH | ✅ |
Codeship | ci.CODESHIP | 🚫 |
Drone | ci.DRONE | ✅ |
dsari | ci.DSARI | 🚫 |
Earthly CI | ci.EARTHLY | 🚫 |
Expo Application Services | ci.EAS | 🚫 |
Gerrit CI | ci.GERRIT | 🚫 |
GitHub Actions | ci.GITHUB_ACTIONS | ✅ |
GitLab CI | ci.GITLAB | ✅ |
Gitea Actions | ci.GITEA_ACTIONS | 🚫 |
GoCD | ci.GOCD | 🚫 |
Google Cloud Build | ci.GOOGLE_CLOUD_BUILD | 🚫 |
Harness CI | ci.HARNESS | 🚫 |
Heroku | ci.HEROKU | 🚫 |
Hudson | ci.HUDSON | 🚫 |
Jenkins CI | ci.JENKINS | ✅ |
LayerCI | ci.LAYERCI | ✅ |
Magnum CI | ci.MAGNUM | 🚫 |
Netlify CI | ci.NETLIFY | ✅ |
Nevercode | ci.NEVERCODE | ✅ |
Prow | ci.PROW | 🚫 |
ReleaseHub | ci.RELEASEHUB | 🚫 |
Render | ci.RENDER | ✅ |
Sail CI | ci.SAIL | ✅ |
Screwdriver | ci.SCREWDRIVER | ✅ |
Semaphore | ci.SEMAPHORE | ✅ |
Sourcehut | ci.SOURCEHUT | 🚫 |
Strider CD | ci.STRIDER | 🚫 |
TaskCluster | ci.TASKCLUSTER | 🚫 |
TeamCity by JetBrains | ci.TEAMCITY | 🚫 |
Travis CI | ci.TRAVIS | ✅ |
Vela | ci.VELA | ✅ |
Vercel | ci.VERCEL | ✅ |
Visual Studio App Center | ci.APPCENTER | 🚫 |
Woodpecker | ci.WOODPECKER | ✅ |
API
ci.name
Returns a string containing name of the CI server the code is running on.
If CI server is not detected, it returns null
.
Don't depend on the value of this string not to change for a specific
vendor. If you find your self writing ci.name === 'Travis CI'
, you
most likely want to use ci.TRAVIS
instead.
ci.isCI
Returns a boolean. Will be true
if the code is running on a CI server,
otherwise false
.
Some CI servers not listed here might still trigger the ci.isCI
boolean to be set to true
if they use certain vendor neutral
environment variables. In those cases ci.name
will be null
and no
vendor specific boolean will be set to true
.
ci.isPR
Returns a boolean if PR detection is supported for the current CI server. Will
be true
if a PR is being tested, otherwise false
. If PR detection is
not supported for the current CI server, the value will be null
.
ci.<VENDOR-CONSTANT>
A vendor specific boolean constant is exposed for each support CI
vendor. A constant will be true
if the code is determined to run on
the given CI server, otherwise false
.
Examples of vendor constants are ci.TRAVIS
or ci.APPVEYOR
. For a
complete list, see the support table above.
Ports
ci-info has been ported to the following languages
Language | Repository |
---|---|
Go | https://github.com/hofstadter-io/cinful |
Rust | https://github.com/sagiegurari/ci_info |
Kotlin | https://github.com/cloudflightio/ci-info |
License
No vulnerabilities found.
Reason
no dangerous workflow patterns detected
Reason
15 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 10
Reason
no binaries found in the repo
Reason
0 existing vulnerabilities detected
Reason
license file detected
Details
- Info: project has a license file: LICENSE:0
- Info: FSF or OSI recognized license: MIT License: LICENSE:0
Reason
detected GitHub workflow tokens with excessive permissions
Details
- Warn: no topLevel permission defined: .github/workflows/tests.yml:1
- Info: no jobLevel write permissions found
Reason
Found 1/30 approved changesets -- score normalized to 0
Reason
dependency not pinned by hash detected -- score normalized to 0
Details
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/watson/ci-info/tests.yml/master?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/watson/ci-info/tests.yml/master?enable=pin
- Warn: npmCommand not pinned by hash: .github/workflows/tests.yml:23
- Info: 0 out of 2 GitHub-owned GitHubAction dependencies pinned
- Info: 0 out of 1 npmCommand dependencies pinned
Reason
no effort to earn an OpenSSF best practices badge detected
Reason
security policy file not detected
Details
- Warn: no security policy file detected
- Warn: no security file to analyze
- Warn: no security file to analyze
- Warn: no security file to analyze
Reason
project is not fuzzed
Details
- Warn: no fuzzer integrations found
Reason
branch protection not enabled on development/release branches
Details
- Warn: branch protection not enabled for branch 'master'
Reason
SAST tool is not run on all commits -- score normalized to 0
Details
- Warn: 0 commits out of 1 are checked with a SAST tool
Score
4.4
/10
Last Scanned on 2024-11-18
The Open Source Security Foundation is a cross-industry collaboration to improve the security of open source software (OSS). The Scorecard provides security health metrics for open source projects.
Learn More