Check Npm

grafana/skills/skills/grafana-plugins/check-npm

作者 grafana1ccacf29049fApache-2.0279 个星标收录于 2026年10月8日更新于 2026年10月8日仓库今天更新

Audit a JavaScript/TypeScript repo's npm, yarn, or pnpm configuration for supply-chain hardening: tool version, lifecycle scripts, unsafe dependency protocols, and minimum release age ≥3 days. Use when the user invokes /check-npm or asks to audit package manager security, lifecycle scripts, git dependencies, ignore-scripts, min-release-age, allow-git, approvedGitRepositories, strictDepBuilds, or blockExoticSubdeps in a Grafana plugin or JS/TS project.

仅含说明Security
AI 生成的概览

对 JS/TS 仓库的 npm、yarn 或 pnpm 配置进行只读供应链加固审计。

功能
对 JavaScript 或 TypeScript 仓库的工作区根目录执行只读审计,检查包管理器版本、是否禁用生命周期脚本、不安全的依赖协议,以及至少三天的发布最短等待期。它会生成包含检测到的包管理器及版本的 PASS/FAIL 报告表格,并为每项未通过的检查提供可直接粘贴的配置修复。它不会修改任何文件。
适用场景
当用户调用 /check-npm,或要求在 Grafana 插件或 JS/TS 项目中审计包管理器安全性、生命周期脚本、git 依赖、ignore-scripts、min-release-age、allow-git、approvedGitRepositories、strictDepBuilds 或 blockExoticSubdeps 时使用。
运行要求
需要一个在工作区根目录包含 package.json 的 JavaScript/TypeScript 项目、可用于报告版本的相应包管理器命令行工具(npm、yarn 或 pnpm),以及 jq、grep、find 等 shell 工具。它不附带脚本,仅为说明文档。

npm / yarn / pnpm supply-chain audit

Read-only audit of the workspace root. Do not modify any files.

0. Detect package manager

bash
test -f package.json || { echo "STOP: no package.json at workspace root"; exit 1; }jq -r '.packageManager // "unset"' package.jsonls -1 yarn.lock package-lock.json pnpm-lock.yaml 2>/dev/null || true

If no package.json, stop. Priority: packageManager → lockfile → default npm.

1. Tool version

bash
npm --version    # required ≥ 11.15.0yarn --version   # required ≥ 4.14.0pnpm --version   # required ≥ 11.0.0

Use semver comparison. Verify pinned packageManager meets threshold.

ManagerMinimum
npm11.15.0
yarn4.14.0
pnpm11.0.0

2. Lifecycle scripts disabled

bash
grep -E '^ignore-scripts=' .npmrc 2>/dev/nullgrep -E 'enableScripts:' .yarnrc.yml 2>/dev/nullgrep -E 'strictDepBuilds:|dangerouslyAllowAllBuilds:|allowBuilds:' pnpm-workspace.yaml 2>/dev/null
ManagerPASSFAIL
npm.npmrc has ignore-scripts=truemissing or false
yarnenableScripts: false or key absentenableScripts: true
pnpm ≥ 11strictDepBuilds unset/true, dangerouslyAllowAllBuilds unset/false, and allowBuilds unset/[]strictDepBuilds: false, dangerouslyAllowAllBuilds: true, or allowBuilds non-empty
pnpm 10.npmrc ignore-scripts=true OR strictDepBuilds: trueneither

pnpm 11+ ignores script settings in .npmrc and package.json#pnpm. pnpm 10 / yarn edge cases: references/managers.md [blocked].

3. Unsafe dependency protocols

Registry:

bash
grep -E '^allow-git=' .npmrc 2>/dev/nullgrep -E 'approvedGitRepositories:' .yarnrc.yml 2>/dev/nullgrep -E 'blockExoticSubdeps:' pnpm-workspace.yaml 2>/dev/null

Scan workspace package.json files (dependencies, devDependencies, optionalDependencies, peerDependencies). Prefer workspace-member discovery (pnpm-workspace.yaml / root workspaces / lerna / rush) per references/protocols.md [blocked], then scan only those manifests. Fallback (may overmatch non-workspace manifests):

find . -name package.json -not -path '*/node_modules/*'

Safe values only: semver range, workspace:, patch:, npm: alias to semver. Flag everything else (git URLs, tarballs, user/repo shorthand, file:, link:, exec:, …) as path → name → value (protocol).

ManagerPASSFAIL
npmallow-git=none or rootmissing or all
yarnapprovedGitRepositories: [] or grafana-scoped list, or omitted with policy comment + clean scanunsafe entries or broad allow-list
pnpm ≥ 11blockExoticSubdeps unset/truefalse
pnpm 10.xblockExoticSubdeps: trueunset (default false) or false

Protocol detection order and yarn posture details: references/protocols.md [blocked].

4. Minimum release age ≥ 3 days

3 days = 4320 minutes. npm uses days; yarn and pnpm use minutes.

bash
grep -E '^min(imum)?-release-age=' .npmrc 2>/dev/nullgrep -E 'npmMinimalAgeGate:' .yarnrc.yml 2>/dev/nullgrep -E 'minimumReleaseAge:|minimumReleaseAgeStrict:' pnpm-workspace.yaml 2>/dev/null
ManagerPASSFAIL
npmmin-release-age ≥ 3missing
yarnnpmMinimalAgeGate ≥ 4320 minmissing or below
pnpm ≥ 11minimumReleaseAge ≥ 4320unset (default 1440) or below
pnpm 10minimum-release-age / minimumReleaseAge ≥ 4320missing

Flag minimumReleaseAgeStrict: false on pnpm 11.

5. Report

#CheckStatusDetail
0Package manager(npm / yarn / pnpm)version: x.y.z (pinned: y.y.y if set)
1Tool version ≥ thresholdPASS / FAILactual vs required
2Scripts disabledPASS / FAILconfig line or "missing"
3Unsafe dep protocolsPASS / FAILregistry state + flagged entries
4Min release age ≥ 3 daysPASS / FAILconfig + value

Use PASS / FAIL only — no emojis.

For each FAIL, one paste-ready fix:

ini
# npm — .npmrcignore-scripts=trueallow-git=nonemin-release-age=3
yaml
# pnpm 11 — pnpm-workspace.yamlstrictDepBuilds: truedangerouslyAllowAllBuilds: falseallowBuilds: []minimumReleaseAge: 4320blockExoticSubdeps: true
yaml
# yarn — .yarnrc.ymlnpmMinimalAgeGate: 4320

More fixes (tool upgrades, yarn git allow-list, pnpm 10): references/fix-snippets.md [blocked].

If all PASS: "All checks passed." and stop.

来源与署名

来源:grafana/skills位于skills/grafana-plugins/check-npm提交1ccacf2

许可证: Apache-2.0

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架

更多来自 grafana/skills 的技能

React 19 Plugin Migration

grafana

指导将 Grafana 插件迁移至 React 19 兼容,按顺序完成构建、依赖与源码修改步骤。

Software Development279今天更新

Plugin Bundle Size

grafana

指导使用 React.lazy、Suspense 和 webpack 代码分割来优化 Grafana 应用插件包体积。

Software Development279今天更新

Grafana Scenes

grafana

使用 @grafana/scenes 框架构建 Grafana 插件页面,涵盖场景、面板、变量与下钻导航。

Software Development279今天更新

Mimir

grafana

指导搭建和运维 Grafana Mimir,用于可扩展、多租户、长期的 Prometheus 与 OTLP 指标存储。

DevOps & Cloud279今天更新

K6 Trend Analysis

grafana

Analyze Grafana Cloud k6 test run trends over time. Detects slow metric drift (e.g., P95 latency creeping up while still passing thresholds), computes headroom to thresholds, flags anomalies, and recommends threshold tightening. Use when the user asks about test performance trends, wants to know if metrics are degrading, asks whether thresholds should be tightened, or wants a health check across recent runs for a specific test. Trigger on phrases like "how is my test trending", "is P95 getting worse", "check for performance regression", "should I tighten thresholds", "are my tests degrading", "show me trends for test X", "analyze my k6 test runs", or "is my test getting slower". Also trigger when a user asks to check all tests in a project -- run this skill once per test and synthesize.

待分类279今天更新

K6 Test Maintenance

grafana

维护和改进现有 k6 负载测试脚本:收紧阈值、版本迁移、重构以及最佳实践审计。

Software Development279今天更新