Installations
npm install monodeploy
Developer Guide
Typescript
No
Module System
CommonJS, ESM
Min. Node Version
>=v14.21.3
Score
41.4
Supply Chain
54.2
Quality
73.1
Maintenance
100
Vulnerability
97.3
License
Releases
@monodeploy/plugin-github@2.0.2
Published on 02 Jul 2024
monodeploy@5.0.2
Published on 02 Jul 2024
@monodeploy/plugin-github@2.0.1
Published on 14 Nov 2023
monodeploy@5.0.1
Published on 14 Nov 2023
@monodeploy/plugin-github@2.0.0
Published on 09 Nov 2023
monodeploy@5.0.0
Published on 09 Nov 2023
Contributors
Unable to fetch Contributors
Languages
TypeScript (91.87%)
MDX (5.05%)
JavaScript (2.39%)
CSS (0.5%)
Shell (0.11%)
Dockerfile (0.08%)
Developer
Download Statistics
Total Downloads
62,755
Last Day
6
Last Week
78
Last Month
844
Last Year
10,977
GitHub Statistics
106 Stars
869 Commits
7 Forks
2 Watching
7 Branches
14 Contributors
Package Meta Information
Latest Version
5.0.2
Package Id
monodeploy@5.0.2
Unpacked Size
49.24 kB
Size
10.96 kB
File Count
19
Publised On
02 Jul 2024
Total Downloads
Cumulative downloads
Total Downloads
62,755
Last day
-78.6%
6
Compared to previous day
Last week
-32.8%
78
Compared to previous week
Last month
-22.4%
844
Compared to previous month
Last year
-55.8%
10,977
Compared to previous year
Daily Downloads
Weekly Downloads
Monthly Downloads
Yearly Downloads
monodeploy
Monodeploy is a powerful tool which aims to simplify the package publishing process for monorepos. It leverages Yarn Berry workspaces to do the heavy lifting, and is a direct replacement for tools such as Lerna and Semantic Release.
Monodeploy only supports projects using Yarn Modern v4+ with the minimum node version set to Node v18.12.0.
Please see the Monodeploy Website for information on how to get started with Monodeploy.
Note About Monodeploy Package Versioning
Only the monodeploy
package is "public" and follows strict semantic versioning. The other packages such as @monodeploy/changelog
are meant for internal use and may change their APIs at any time.
Contributing
See the Contributing Guide for setup instructions, tips, and guidelines.
Contributors
Thanks goes to these wonderful people (emoji key):
This project follows the all-contributors specification. Contributions of any kind welcome!
Credits
Special thanks to Carol Skelly for donating the 'tophat' GitHub organization.
No vulnerabilities found.
Reason
no dangerous workflow patterns detected
Reason
no binaries found in the repo
Reason
license file detected
Details
- Info: project has a license file: LICENSE:0
- Info: FSF or OSI recognized license: Apache License 2.0: LICENSE:0
Reason
dependency not pinned by hash detected -- score normalized to 6
Details
- Warn: containerImage not pinned by hash: e2e-tests/Dockerfile:1: pin your Docker image by updating node:20-slim to node:20-slim@sha256:f44fa8d6d0ef15fe252459ac5d3d178362231a7948d7d07e147bae891006e2e5
- Warn: downloadThenRun not pinned by hash: .github/codecov.sh:11
- Warn: downloadThenRun not pinned by hash: .github/codecov.sh:13
- Info: 17 out of 17 GitHub-owned GitHubAction dependencies pinned
- Info: 2 out of 2 third-party GitHubAction dependencies pinned
- Info: 0 out of 1 containerImage dependencies pinned
- Info: 0 out of 2 downloadThenRun dependencies pinned
Reason
project is archived
Details
- Warn: Repository is archived.
Reason
Found 0/25 approved changesets -- score normalized to 0
Reason
detected GitHub workflow tokens with excessive permissions
Details
- Warn: no topLevel permission defined: .github/workflows/pull-request.yml:1
- Warn: no topLevel permission defined: .github/workflows/release.yml:1
- Info: no jobLevel write permissions found
Reason
no effort to earn an OpenSSF best practices badge detected
Reason
security policy file not detected
Details
- Warn: no security policy file detected
- Warn: no security file to analyze
- Warn: no security file to analyze
- Warn: no security file to analyze
Reason
project is not fuzzed
Details
- Warn: no fuzzer integrations found
Reason
SAST tool is not run on all commits -- score normalized to 0
Details
- Warn: 0 commits out of 28 are checked with a SAST tool
Reason
35 existing vulnerabilities detected
Details
- Warn: Project is vulnerable to: GHSA-wf5p-g6vw-rhxx
- Warn: Project is vulnerable to: GHSA-qwcr-r2fm-qrc7
- Warn: Project is vulnerable to: GHSA-grv7-fg5c-xmjg
- Warn: Project is vulnerable to: GHSA-pxg6-pf52-xh8x
- Warn: Project is vulnerable to: GHSA-3xgq-45jj-v275
- Warn: Project is vulnerable to: GHSA-q9mw-68c2-j6m5
- Warn: Project is vulnerable to: GHSA-4gmj-3p3h-gm8h
- Warn: Project is vulnerable to: GHSA-rv95-896h-c2vc
- Warn: Project is vulnerable to: GHSA-qw6h-vgh9-j6wx
- Warn: Project is vulnerable to: GHSA-jchw-25xp-jwwc
- Warn: Project is vulnerable to: GHSA-cxjh-pqwp-8mfp
- Warn: Project is vulnerable to: GHSA-pfrx-2q88-qq97
- Warn: Project is vulnerable to: GHSA-78xj-cgh5-2h22
- Warn: Project is vulnerable to: GHSA-2p57-rm9w-gvfp
- Warn: Project is vulnerable to: GHSA-35jh-r3h4-6jhm
- Warn: Project is vulnerable to: GHSA-952p-6rrq-rcjv
- Warn: Project is vulnerable to: GHSA-7hpj-7hhx-2fgx
- Warn: Project is vulnerable to: GHSA-mwcw-c2x4-8c55
- Warn: Project is vulnerable to: GHSA-9wv6-86v2-598j
- Warn: Project is vulnerable to: GHSA-rhx6-c78j-4q9w
- Warn: Project is vulnerable to: GHSA-7fh5-64p2-3v2j
- Warn: Project is vulnerable to: GHSA-rjqq-98f6-6j3r
- Warn: Project is vulnerable to: GHSA-mjxr-4v3x-q3m4
- Warn: Project is vulnerable to: GHSA-cgfm-xwp7-2cvr
- Warn: Project is vulnerable to: GHSA-rm97-x556-q36h
- Warn: Project is vulnerable to: GHSA-c2qf-rxjj-qqgw
- Warn: Project is vulnerable to: GHSA-m6fv-jmcg-4jfg
- Warn: Project is vulnerable to: GHSA-cm22-4g7w-348p
- Warn: Project is vulnerable to: GHSA-54xq-cgqr-rpm3
- Warn: Project is vulnerable to: GHSA-25hc-qcg6-38wj
- Warn: Project is vulnerable to: GHSA-f5x3-32g6-xq36
- Warn: Project is vulnerable to: GHSA-cf4h-3jhx-xvhq
- Warn: Project is vulnerable to: GHSA-4vvj-4cpr-p986
- Warn: Project is vulnerable to: GHSA-wr3j-pwj9-hqq6
- Warn: Project is vulnerable to: GHSA-3h5v-q93c-6h6q
Score
3.2
/10
Last Scanned on 2024-12-16
The Open Source Security Foundation is a cross-industry collaboration to improve the security of open source software (OSS). The Scorecard provides security health metrics for open source projects.
Learn More