Check Npm

作者 grafana1ccacf29049fApache-2.0279 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫今天更新

Audit a JavaScript/TypeScript repo's npm, yarn, or pnpm configuration for supply-chain hardening: tool version, lifecycle scripts, unsafe dependency protocols, and minimum release age ≥3 days. Use when the user invokes /check-npm or asks to audit package manager security, lifecycle scripts, git dependencies, ignore-scripts, min-release-age, allow-git, approvedGitRepositories, strictDepBuilds, or blockExoticSubdeps in a Grafana plugin or JS/TS project.

僅含說明Security
AI 產生的概覽

對 JS/TS 儲存庫的 npm、yarn 或 pnpm 設定進行唯讀供應鏈強化稽核。

功能
對 JavaScript 或 TypeScript 儲存庫的工作區根目錄執行唯讀稽核,檢查套件管理員版本、是否停用生命週期指令碼、不安全的相依性通訊協定,以及至少三天的發佈最短等待期。它會產生包含偵測到的套件管理員與版本的 PASS/FAIL 報告表格,並為每項未通過的檢查提供可直接貼上的設定修正。它不會修改任何檔案。
適用情境
當使用者呼叫 /check-npm,或要求在 Grafana 外掛或 JS/TS 專案中稽核套件管理員安全性、生命週期指令碼、git 相依性、ignore-scripts、min-release-age、allow-git、approvedGitRepositories、strictDepBuilds 或 blockExoticSubdeps 時使用。
執行需求
需要一個在工作區根目錄包含 package.json 的 JavaScript/TypeScript 專案、可用於回報版本的對應套件管理員命令列工具(npm、yarn 或 pnpm),以及 jq、grep、find 等 shell 工具。它不附帶指令碼,僅為說明文件。

npm / yarn / pnpm supply-chain audit

Read-only audit of the workspace root. Do not modify any files.

0. Detect package manager

bash
test -f package.json || { echo "STOP: no package.json at workspace root"; exit 1; }jq -r '.packageManager // "unset"' package.jsonls -1 yarn.lock package-lock.json pnpm-lock.yaml 2>/dev/null || true

If no package.json, stop. Priority: packageManager → lockfile → default npm.

1. Tool version

bash
npm --version    # required ≥ 11.15.0yarn --version   # required ≥ 4.14.0pnpm --version   # required ≥ 11.0.0

Use semver comparison. Verify pinned packageManager meets threshold.

ManagerMinimum
npm11.15.0
yarn4.14.0
pnpm11.0.0

2. Lifecycle scripts disabled

bash
grep -E '^ignore-scripts=' .npmrc 2>/dev/nullgrep -E 'enableScripts:' .yarnrc.yml 2>/dev/nullgrep -E 'strictDepBuilds:|dangerouslyAllowAllBuilds:|allowBuilds:' pnpm-workspace.yaml 2>/dev/null
ManagerPASSFAIL
npm.npmrc has ignore-scripts=truemissing or false
yarnenableScripts: false or key absentenableScripts: true
pnpm ≥ 11strictDepBuilds unset/true, dangerouslyAllowAllBuilds unset/false, and allowBuilds unset/[]strictDepBuilds: false, dangerouslyAllowAllBuilds: true, or allowBuilds non-empty
pnpm 10.npmrc ignore-scripts=true OR strictDepBuilds: trueneither

pnpm 11+ ignores script settings in .npmrc and package.json#pnpm. pnpm 10 / yarn edge cases: references/managers.md [blocked].

3. Unsafe dependency protocols

Registry:

bash
grep -E '^allow-git=' .npmrc 2>/dev/nullgrep -E 'approvedGitRepositories:' .yarnrc.yml 2>/dev/nullgrep -E 'blockExoticSubdeps:' pnpm-workspace.yaml 2>/dev/null

Scan workspace package.json files (dependencies, devDependencies, optionalDependencies, peerDependencies). Prefer workspace-member discovery (pnpm-workspace.yaml / root workspaces / lerna / rush) per references/protocols.md [blocked], then scan only those manifests. Fallback (may overmatch non-workspace manifests):

find . -name package.json -not -path '*/node_modules/*'

Safe values only: semver range, workspace:, patch:, npm: alias to semver. Flag everything else (git URLs, tarballs, user/repo shorthand, file:, link:, exec:, …) as path → name → value (protocol).

ManagerPASSFAIL
npmallow-git=none or rootmissing or all
yarnapprovedGitRepositories: [] or grafana-scoped list, or omitted with policy comment + clean scanunsafe entries or broad allow-list
pnpm ≥ 11blockExoticSubdeps unset/truefalse
pnpm 10.xblockExoticSubdeps: trueunset (default false) or false

Protocol detection order and yarn posture details: references/protocols.md [blocked].

4. Minimum release age ≥ 3 days

3 days = 4320 minutes. npm uses days; yarn and pnpm use minutes.

bash
grep -E '^min(imum)?-release-age=' .npmrc 2>/dev/nullgrep -E 'npmMinimalAgeGate:' .yarnrc.yml 2>/dev/nullgrep -E 'minimumReleaseAge:|minimumReleaseAgeStrict:' pnpm-workspace.yaml 2>/dev/null
ManagerPASSFAIL
npmmin-release-age ≥ 3missing
yarnnpmMinimalAgeGate ≥ 4320 minmissing or below
pnpm ≥ 11minimumReleaseAge ≥ 4320unset (default 1440) or below
pnpm 10minimum-release-age / minimumReleaseAge ≥ 4320missing

Flag minimumReleaseAgeStrict: false on pnpm 11.

5. Report

#CheckStatusDetail
0Package manager(npm / yarn / pnpm)version: x.y.z (pinned: y.y.y if set)
1Tool version ≥ thresholdPASS / FAILactual vs required
2Scripts disabledPASS / FAILconfig line or "missing"
3Unsafe dep protocolsPASS / FAILregistry state + flagged entries
4Min release age ≥ 3 daysPASS / FAILconfig + value

Use PASS / FAIL only — no emojis.

For each FAIL, one paste-ready fix:

ini
# npm — .npmrcignore-scripts=trueallow-git=nonemin-release-age=3
yaml
# pnpm 11 — pnpm-workspace.yamlstrictDepBuilds: truedangerouslyAllowAllBuilds: falseallowBuilds: []minimumReleaseAge: 4320blockExoticSubdeps: true
yaml
# yarn — .yarnrc.ymlnpmMinimalAgeGate: 4320

More fixes (tool upgrades, yarn git allow-list, pnpm 10): references/fix-snippets.md [blocked].

If all PASS: "All checks passed." and stop.

來源與署名

來源:grafana/skills位於skills/grafana-plugins/check-npm提交1ccacf2

授權條款: Apache-2.0

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架

更多來自 grafana/skills 的技能

React 19 Plugin Migration

grafana

指導將 Grafana 外掛遷移至 React 19 相容,依序完成建置、相依性與原始碼修改步驟。

Software Development279今天更新

Plugin Bundle Size

grafana

指導使用 React.lazy、Suspense 與 webpack 程式碼分割來最佳化 Grafana 應用程式外掛的打包體積。

Software Development279今天更新

Grafana Scenes

grafana

使用 @grafana/scenes 框架建置 Grafana 外掛頁面,涵蓋場景、面板、變數與下鑽導覽。

Software Development279今天更新

Mimir

grafana

指導架設與維運 Grafana Mimir,用於可擴充、多租戶、長期的 Prometheus 與 OTLP 指標儲存。

DevOps & Cloud279今天更新

K6 Trend Analysis

grafana

Analyze Grafana Cloud k6 test run trends over time. Detects slow metric drift (e.g., P95 latency creeping up while still passing thresholds), computes headroom to thresholds, flags anomalies, and recommends threshold tightening. Use when the user asks about test performance trends, wants to know if metrics are degrading, asks whether thresholds should be tightened, or wants a health check across recent runs for a specific test. Trigger on phrases like "how is my test trending", "is P95 getting worse", "check for performance regression", "should I tighten thresholds", "are my tests degrading", "show me trends for test X", "analyze my k6 test runs", or "is my test getting slower". Also trigger when a user asks to check all tests in a project -- run this skill once per test and synthesize.

待分類279今天更新

K6 Test Maintenance

grafana

維護與改善現有 k6 負載測試指令碼:收緊閾值、版本移轉、重構以及最佳實務稽核。

Software Development279今天更新