npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

dependfix

v0.5.0

Published

一个自动化修复 github security 告警的方案

Readme

dependfix

简体中文 | English

自动化处理 GitHub Dependabot / Code Scanning 安全告警的 CLI 工具。

安装

# 全局安装
pnpm add -g dependfix

# 或直接运行(无需安装)
npx dependfix report-only --repo owner/repo --github-token $GITHUB_TOKEN

命令

report-only — 查看告警(默认)

拉取告警并生成 Markdown + JSON 双格式报告,不修改任何文件。

dependfix report-only --repo owner/repo --github-token $GITHUB_TOKEN

fix — 修复告警

执行依赖升级、lockfile 修复和验证(lint / build),修改仅限本地文件,不创建分支或 PR。

dependfix fix --repo owner/repo --github-token $GITHUB_TOKEN --severity-threshold high

fix-and-pr — 修复并创建 PR

执行完整修复流程后,自动创建修复分支、提交变更、推送并创建 Pull Request。

dependfix fix-and-pr --repo owner/repo --github-token $GITHUB_TOKEN

需要 GITHUB_TOKEN 具备 contents: write 和 pull-requests: write 权限。

CLI 参数

| 参数 | 别名 | 说明 | 默认 | |:-----|:-----|:-----|:-----| | mode | (位置参数) | 运行模式:report-only / fix / fix-and-pr | report-only | | --repo | -r, --repository, --repositories | 目标仓库(owner/repo),逗号分隔 | — | | --repos-file | — | 从文件读取仓库列表(每行一个 owner/repo) | — | | --github-token | — | GitHub Personal Access Token | GITHUB_TOKEN 环境变量 | | --severity-threshold | — | 严重级别:critical / high / medium / all | high | | --dry-run | — | 试运行模式,不实际写入文件 | false | | --create-pr | — | 创建 Pull Request(fix-and-pr 模式自动启用) | false | | --commit | — | 修复完成后在本地当前分支直接提交(仅 fix 模式;不推送、不创建 PR) | false | | --max-alerts-per-repository | — | 每仓库最大告警处理数 | 20 | | --commands | — | 自定义验证命令(逗号分隔),覆盖默认的 install/lint/build | — | | --verbose | — | 详细日志输出 | false |

环境变量

| 环境变量 | 说明 | |:---------|:-----| | GITHUB_TOKEN | GitHub 认证 Token |

程序化调用

import { DependfixApp, runCli } from 'dependfix'

// 解析 CLI 参数
const { config } = runCli(process.argv.slice(2))

// 程序化执行
const app = new DependfixApp({ config, verbose: true })
const { result, exitCode } = await app.run()

修复流程

  1. 拉取告警 — 通过 GitHub API 获取 Dependabot alerts
  2. 过滤排序 — 按严重级别过滤、优先级排序、数量限制
  3. 依赖升级 — pnpm update <package> 升级到推荐版本
  4. lockfile 修复 — 检测并修复 pnpm frozen-lockfile 问题
  5. 验证 — 执行 pnpm install --frozen-lockfile → pnpm lint → pnpm build
  6. 分支与 PR — fix-and-pr 模式下,创建分支、commit、push、PR

相关包