@tractorcow/beefup
v1.3.3
Published
Staged, pinned, audited dependency upgrades for npm and pnpm.
Maintainers
Readme
@tractorcow/beefup
CLI for staged, pinned, audited npm/pnpm dependency upgrades. A proposed upgrade is written to .beefup/staged for review; nothing is applied to the live project until a later accept step.
Prerequisites
- Node.js 22+
- pnpm 11.22.0 (see
packageManagerinpackage.json) or npm 12+ - Git
- Aikido Safe Chain wrapping the package manager
Beefup will not run unless Safe Chain is enabled. It looks for aikido-pnpm / aikido-npm, or safe-chain, on PATH. That keeps lockfile updates and security scans behind Safe Chain’s malware checks and minimum package age. Pass --no-safe-chain only when you need to bypass that check and run the raw package manager.
Install Safe Chain
Unix / macOS / Linux (pinned release + installer checksum):
curl -fsSL https://github.com/AikidoSec/safe-chain/releases/download/1.5.15/install-safe-chain.sh -o /tmp/install-safe-chain.sh \
&& echo "de0565e3d6346407a604e84e639e95fea8758748063da2216bbfdca5feda5dd2 /tmp/install-safe-chain.sh" | sha256sum -c - \
&& sh /tmp/install-safe-chain.sh \
&& rm /tmp/install-safe-chain.shOn macOS without sha256sum, use shasum -a 256 -c - instead of sha256sum -c -.
Then restart your shell and verify:
pnpm safe-chain-verify
# or: npm safe-chain-verifyYou should see OK: Safe-chain works!.
If pnpm is already installed, check that its global bin directory is on PATH:
pnpm bin -gIf that command reports the directory is missing from PATH, run pnpm setup and restart the shell.
Install
pnpm add --global @tractorcow/beefup
# or: npm install --global @tractorcow/beefupConfirm:
beefup --version
beefup --helpFrom a git checkout (development)
git clone [email protected]:tractorcow/beefup.git
cd beefup
pnpm install --frozen-lockfile
pnpm run build
pnpm add --global .Or from the repo root: make install && make install-global.
Update
pnpm add --global @tractorcow/beefup@latest
# or: npm install --global @tractorcow/beefup@latestFrom a git checkout:
cd /path/to/beefup
git pull
pnpm install --frozen-lockfile
pnpm run build
pnpm add --global .Or: git pull && make install && make install-global.
Uninstall
pnpm remove --global @tractorcow/beefup
# or: npm uninstall --global @tractorcow/beefupOr: make uninstall-global.
Usage
See docs/index.md, staging, report, accept, revert, and rewind.
beefup stage
beefup stage --mode latest --strategy inplace
beefup stage --format markdown
beefup stage --package-root ./app
beefup stage --package-root ./app --package-root ./api
beefup report
beefup accept
beefup revert
beefup rewind HEAD~1
beefup rewind --debug HEAD~1