npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@flavor-code/update-plugin

v0.1.2

Published

更新插件

Readme

update-plugin

flavor-code 插件(apiVersion 1):执行 npx --yes @flavor-code/plugin-manager 更新全部插件。 零第三方依赖,只使用 node: 内置模块。

能力

  • 命令 /update-plugin:默认运行 npx --yes @flavor-code/plugin-manager --all -y --force,更新目录中的全部插件(顶级 --all 一次安装全部;--force 覆盖已安装版本——不带它时已安装插件会直接报"已安装"退出;-y 跳过交互确认)。
  • /update-plugin <args...>:把参数原样透传给 plugin-manager(参数数组执行,不经过 shell)。
  • /update-plugin help:显示用法。

清单

{
  "name": "update-plugin",
  "version": "0.1.0",
  "apiVersion": "1",
  "main": "index.js",
  "permissions": ["process"],        // 需要派生子进程执行 npx
  "contributes": {
    "commands": [{ "name": "update-plugin" }],
    "tools": [], "hooks": [], "skillRoots": [], "modelAdapters": []
  }
}

实现要点

  • Node 自 CVE-2024-27980 修复起(18.20.2 / 20.12.2 / 21.7.0+),禁止在 shell: false 下直接 spawn .cmd/.bat,Windows 上 spawn("npx.cmd") 会报 EINVAL。因此:
    • Windows:优先用当前 node.exe 直接执行 npm 自带的 npx-cli.js(保持 shell: false,零注入面);找不到时回退 cmd.exe /d /s /c,全部参数做 cmd 双引号转义(内嵌双引号翻倍)。
    • macOS/Linux:npx 是带 shebang 的可执行脚本,直接 spawn("npx", argv)。
  • spawn 始终以参数数组执行,不经过 shell 字符串拼接,避免命令行注入。
  • plugin-manager v1.0 真机验证的参数契约:--all 是顶级选项(add --all 会进入 交互多选,无 stdin 时直接报"非交互环境中请指定插件名或使用 --all");已安装 插件默认不覆盖而是报错退出,更新必须带 --force;-y 跳过确认。如需其它 参数,用 /update-plugin <真实参数...> 透传覆盖,或修改 index.js 顶部的 DEFAULT_UPDATE_ARGS。
  • 非标准 npm 安装布局可通过插件配置 npxCliPath 显式指定 npx-cli.js 路径。
  • 超时默认 120 秒(可通过插件配置 timeoutMs 调整);插件卸载时终止仍在运行的子进程。
  • activate 仅做同步注册,无 I/O;输出截断至 1 MiB。

安装与运行

把插件目录放到以下任意位置,重启 flavor-code 即自动加载:

  • 项目插件:<workspace>/.flavor/plugins/update-plugin/
  • 全局插件:~/.flavor-code/plugins/update-plugin/

检查

node scripts/check.mjs .

通过条件:清单结构合法、入口存在、activate 可执行、disposer 可执行、清单声明与注册一致。