Description

The npm crawler looks recursively for all npm dependencies updates from a specific root directory. Then for each of them, it tries to update them.

Manifest

Parameters

NameTypeDescriptionRequired
ignorearrayIgnore allows to specify rule to ignore autodiscovery a specific NPM based on a rule
    hasversionconstraintbooleanHasVersionConstraint indicates whether the matching rule should match any version constraint or not.
    packagesobjectPackages specifies the list of NPM packages to check
    pathstringPath specifies a package.json path pattern, the pattern requires to match all of name, not just a substring.
ignoreversionconstraintsboolean

IgnoreVersionConstraints indicates whether to respect version constraints defined in package.json or not. When set to true, Updatecli will ignore version constraints and update to the latest version available in the registry according to the specified version filter. Default is false.

Remark:

  • If set to false, Updatecli will try to convert version constrains to valid semantic version so we can use versionFilter to retrieve the last Major/Minor/Patch version but in case of complex version constraints, such as >=1.0.0 <2.0.0, Updatecli will convert it to the first version it detects such as 1.0.0 in our example
npmrcpathstringNpmrcPath defines the path to the .npmrc file to use for all discovered packages. This will be propagated to all generated npm resource specs.
onlyarrayOnly allows to specify rule to only autodiscover manifest for a specific NPM based on a rule
    hasversionconstraintbooleanHasVersionConstraint indicates whether the matching rule should match any version constraint or not.
    packagesobjectPackages specifies the list of NPM packages to check
    pathstringPath specifies a package.json path pattern, the pattern requires to match all of name, not just a substring.
registrytokenstringRegistryToken defines the token to use when connecting to the registry. This will be propagated to all generated npm resource specs.
rootdirstringRootDir defines the root directory used to recursively search for npm packages.json
urlstringURL defines the registry url (defaults to https://registry.npmjs.org/). This will be propagated to all generated npm resource specs.
versionfilterobject

versionfilter provides parameters to specify the version pattern used when generating manifest.

kind - semver versionfilter of kind semver uses semantic versioning as version filtering pattern accepts one of: prerelease - Updatecli tries to identify the latest prerelease whatever it means patch - Updatecli only handles patch version update minor - Updatecli handles patch AND minor version update minoronly - Updatecli handles minor version only major - Updatecli handles patch, minor, AND major version update majoronly - Updatecli only handles major version update a version constraint such as >= 1.0.0

kind - regex versionfilter of kind regex uses regular expression as version filtering pattern accepts a valid regular expression

example:

  versionfilter:
    kind: semver
    pattern: minor

and its type like regex, semver, or just latest.

More examples can be found at https://www.updatecli.io/docs/core/versionfilter/

    kindstringspecifies the version kind such as semver, regex, or latest
    patternstringspecifies the version pattern according the version kind for semver, it is a semver constraint for regex, it is a regex pattern for time, it is a date format
    regexstringspecifies the regex pattern, used for regex/semver and regex/time. Output of the first capture group will be used.
    replaceallobjectreplaceAll applies a regex replacement to version strings before filtering. This is useful for transforming versions (e.g., curl-8_15_0 to curl-8.15.0) before regex extraction.
        patternstringPattern specifies the regex pattern to match for replacement
        replacementstringReplacement specifies the replacement string (supports $1, $2, etc. for captured groups)
    strictbooleanstrict enforce strict versioning rule. Only used for semantic versioning at this time
⚠ This table is generated from the Updatecli codebase and may contain inaccurate data. Feel free to report them on github.com/updatecli/updatecli

Example

Basic Example
# updatecli.d/npm.yaml
autodiscovery:
  crawlers:
    npm:
      rootdir: "."
      versionfilter:
        kind: semver
        pattern: minor
Private Registry Example

The following example shows how to configure npm autodiscovery to work with a private npm registry:

# updatecli.d/npm-private.yaml
autodiscovery:
  crawlers:
    npm:
      rootdir: "."
      # URL of your private npm registry
      url: "https://npm.example.com"
      # Authentication token (use environment variables for security)
      registrytoken: "${NPM_TOKEN}"
      # Optional: path to custom .npmrc file
      npmrcpath: "/path/to/.npmrc"
      versionfilter:
        kind: semver
        pattern: ">=1.0.0"
Note
The url, registrytoken, and npmrcpath parameters are propagated to all generated npm resource specs, allowing consistent authentication across all discovered dependencies.