Installations
npm install create-npm
Developer Guide
Typescript
No
Module System
ESM
Node Version
22.8.0
NPM Version
10.5.0
Score
66.3
Supply Chain
76.2
Quality
77
Maintenance
100
Vulnerability
100
License
Releases
Contributors
Unable to fetch Contributors
Languages
JavaScript (100%)
Love this project? Help keep it running — sponsor us today! 🚀
Developer
vinsonchuong
Download Statistics
Total Downloads
41,101
Last Day
45
Last Week
299
Last Month
1,130
Last Year
9,641
GitHub Statistics
MIT License
380 Commits
2 Watchers
5 Branches
1 Contributors
Updated on Feb 14, 2025
Package Meta Information
Latest Version
1.5.1
Package Id
create-npm@1.5.1
Unpacked Size
19.72 kB
Size
6.55 kB
File Count
39
NPM Version
10.5.0
Node Version
22.8.0
Published on
Sep 15, 2024
Total Downloads
Cumulative downloads
Total Downloads
41,101
Last Day
50%
45
Compared to previous day
Last Week
16.3%
299
Compared to previous week
Last Month
45.1%
1,130
Compared to previous month
Last Year
22.1%
9,641
Compared to previous year
Daily Downloads
Weekly Downloads
Monthly Downloads
Yearly Downloads
create-npm
Bootstrap npm packages.
Usage
1yarn create npm github-user/my-pkg
Running the above command will:
- Bootstrap a JavaScript project with:
- Package management using Yarn Classic
- Testing via AVA
- Linting via XO
- Create a GitHub repository for the project
- Enable continuous integration and deployment via GitHub Actions and semantic-release
- Automatic updates of dependencies using Dependabot
- Security updates
- Versions of
dependencies
anddevDependencies
Prerequisites
To use create-npm
, the following tools must be installed:
The following credentials must be given as environment variables:
NPM_TOKEN
GITHUB_TOKEN
The GitHub token is used to add the NPM token to your newly created repository.

No vulnerabilities found.
Reason
no binaries found in the repo
Reason
license file detected
Details
- Info: project has a license file: LICENSE:0
- Info: FSF or OSI recognized license: MIT License: LICENSE:0
Reason
11 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 9
Reason
3 existing vulnerabilities detected
Details
- Warn: Project is vulnerable to: GHSA-xx4v-prfh-6cgc
- Warn: Project is vulnerable to: GHSA-2p57-rm9w-gvfp
- Warn: Project is vulnerable to: GHSA-c2qf-rxjj-qqgw
Reason
Found 0/2 approved changesets -- score normalized to 0
Reason
detected GitHub workflow tokens with excessive permissions
Details
- Warn: no topLevel permission defined: .github/workflows/ci.yml:1
- Warn: no topLevel permission defined: .github/workflows/dependabot.yml:1
- Info: no jobLevel write permissions found
Reason
dangerous workflow patterns detected
Details
- Warn: untrusted code checkout '${{ github.event.pull_request.head.sha }}': .github/workflows/dependabot.yml:8
Reason
no effort to earn an OpenSSF best practices badge detected
Reason
project is not fuzzed
Details
- Warn: no fuzzer integrations found
Reason
security policy file not detected
Details
- Warn: no security policy file detected
- Warn: no security file to analyze
- Warn: no security file to analyze
- Warn: no security file to analyze
Reason
branch protection not enabled on development/release branches
Details
- Warn: branch protection not enabled for branch 'master'
Reason
SAST tool is not run on all commits -- score normalized to 0
Details
- Warn: 0 commits out of 28 are checked with a SAST tool
Reason
dependency not pinned by hash detected -- score normalized to 0
Details
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:10: update your workflow using https://app.stepsecurity.io/secureworkflow/vinsonchuong/create-npm/ci.yml/master?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/vinsonchuong/create-npm/ci.yml/master?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/dependabot.yml:8: update your workflow using https://app.stepsecurity.io/secureworkflow/vinsonchuong/create-npm/dependabot.yml/master?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/dependabot.yml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/vinsonchuong/create-npm/dependabot.yml/master?enable=pin
- Info: 0 out of 4 GitHub-owned GitHubAction dependencies pinned
Score
2.8
/10
Last Scanned on 2025-02-10
The Open Source Security Foundation is a cross-industry collaboration to improve the security of open source software (OSS). The Scorecard provides security health metrics for open source projects.
Learn More