dradar
v0.1.1
Published
`apps/cli` is the npm-packable CLI package for Dependency Risk Radar.
Downloads
11
Readme
dradar
apps/cli is the npm-packable CLI package for Dependency Risk Radar.
Package name today: dradar
Binary name: radar
Local dev
From the repo root:
corepack enable
corepack pnpm install
corepack pnpm analyze -- --repo . --base main --head HEADOr run the CLI directly from the workspace:
tsx apps/cli/src/cli.ts analyze --repo . --base main --head HEADPack flow
Use npm pack to inspect what would be shipped to the registry.
cd apps/cli
npm pack --dry-run --json
npm packThe dry run is the fastest way to verify the release surface before you publish:
- check the tarball file list
- confirm the package name and version
- confirm the binary path is what you expect
- catch accidental files before they reach npm
The publish build is designed to ship dist/ only. Before a real publish, verify that the installed package contains runnable JavaScript for the radar binary and not source TypeScript.
Inspect a generated tarball with:
tar -tf dradar-0.1.1.tgzPublish checklist
Before the first real publish, make sure all of these are true:
- You own or administer the npm scope/name you plan to publish under
npm whoamiworks afternpm login- The package version has been bumped to the intended release number
- The tarball contains the files needed to run the CLI after install
- CI, if used, has an npm automation token with publish rights
- The token is injected as
NPM_TOKENand wired into.npmrc
Typical publish command:
npm publish --access publicIf this package is meant to stay private on npm, publish with the access level you actually want and verify the scope policy before release.
Repo layout note
This package currently depends on workspace packages in the monorepo. That is fine for local development and pack inspection. Do not treat the repo checkout itself as the publish artifact; the published package should be validated from the tarball created by npm pack.
