{"_id":"@competec/yarn-audit-competec","_rev":"1-95c826476c1bf40ffe9f6607dc4f69ff","name":"@competec/yarn-audit-competec","dist-tags":{"latest":"2.0.0"},"versions":{"1.0.0":{"name":"@competec/yarn-audit-competec","version":"1.0.0","keywords":["yarn audit","supressions","competec"],"author":{"name":"Francis C. / Competec"},"license":"MIT","_id":"@competec/yarn-audit-competec@1.0.0","maintainers":[{"name":"teamwebcompetec","email":"teamweb@competec.ch"},{"name":"raphaelh","email":"admin@rhy.pw"}],"homepage":"https://github.com/Competec/yarn-audit-competec.git","bugs":{"url":"https://github.com/Competec/yarn-audit-competec.git/issues"},"bin":{"audit-competec":"bin/yarn-audit-competec.js"},"dist":{"shasum":"ef764eaedcbfc35385ffff218e78bc619ff5d8ef","tarball":"https://registry.npmjs.org/@competec/yarn-audit-competec/-/yarn-audit-competec-1.0.0.tgz","fileCount":12,"integrity":"sha512-0scXO+vw42uip6ovdYYQg4iLbhVxxAOr9TWwqbQql1bw5TiJaXIBc/s1FhjcAN2AmxMI/QXytXCuVTqUtYwhCQ==","signatures":[{"sig":"MEUCIChI6cVGMi/wipjKYUnx9Ydt7qGCYic7KyQMp1nC2HptAiEA+ylMpqEUA1tjBeuQ10RPedxyRcLiRaVIXQGFBib4wdo=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":9517,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJihIwCACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmr3+BAAkiwPcgi8kTnxcxnRKIkO+PM0cR0z0m3QNTIrL5C34zbOliTm\r\nINW/o+Nl6Crv8w+MurW/7AYsXYe6lxGRys+/pnL6Ow+JmoFtnfgcwS9Ox/zW\r\n3C65JQ1Tv+UC9Nt60KeGVag0RWR9J9JE3iV6ue7V3+RSggcIfMZgy2HkCMP2\r\n0J9v1YEaQzZsffBm6BHjBnvK9R6TxO+3GEh86hnwVmmswNWGaT8ApnYOAbzg\r\niJDl8inoUujI0C/K/fslSds8anF3pW3bEDWTxPgPslNKvI5A88ag+MovwK9H\r\nX0e7T56wKsK1UJjF6AWhYZcxcoZZfU8AdxR2Md6TBiLDjmg1Cev/q+HHxX9B\r\nwim45heBi1O6w9g3dY6TUIbFQuLrlvVojb6JjIs1Uqb0shX8m/XCAp04GxC8\r\npLfxdfKrL8wCwtgysBVxskcxCNNr5GCtQtfEGwbcdWq1ifS8EM+cttA5GKeB\r\nJX0jo974Rlg62x66rGgxc9wp3n1fY51A9dCv0Z8522xLxAZ1jQ4kQZeBG4qi\r\n7prpVbrxMGtUulS0z5FFYXMU2RpomH+bHrugbK8S3qZl22ingQMEvPBPGzIi\r\ni5fWXsYy3MhXkdbr8dINiKsSaAXeNMv1ve2quK1/gJIIicZmyrOhc8ozA+8U\r\nm4h1+quQOf1r2W+uZbknV65nSrGog7V5bw8=\r\n=OHO+\r\n-----END PGP SIGNATURE-----\r\n"},"main":"src/utils/index.js","engines":{"npm":">=6.14.4","node":">=14.0.0"},"gitHead":"8b2fd36f71550c3fa7209de40dce9b3a098e15bb","private":false,"scripts":{"lint":"eslint src/*.js","reset":"rm -rf ./node_modules && yarn","audit:competec":"node src"},"_npmUser":{"name":"teamwebcompetec","email":"teamweb@competec.ch"},"repository":{"url":"git+https://github.com/Competec/yarn-audit-competec.git","type":"git"},"_npmVersion":"8.5.5","description":"Competec Audit-Modules","directories":{},"_nodeVersion":"16.15.0","publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^6.3.0","fs-extra":"^10.1.0","@semantic-release/git":"^10.0.1","@semantic-release/exec":"^6.0.3","@semantic-release/github":"^8.0.4","@competec/eslint-config-competec":"^2.5.0"},"_npmOperationalInternal":{"tmp":"tmp/yarn-audit-competec_1.0.0_1652853761876_0.47315091538281684","host":"s3://npm-registry-packages"}},"2.0.0":{"name":"@competec/yarn-audit-competec","version":"2.0.0","description":"Competec Audit-Modules","private":false,"keywords":["yarn audit","supressions","competec"],"bin":{"audit-competec":"bin/yarn-audit-competec.js"},"engines":{"node":">=16.0.0","npm":">=6.14.4"},"author":{"name":"Francis C. / Competec"},"main":"src/utils/index.js","license":"MIT","devDependencies":{"@competec/eslint-config-competec":"^2.5.0","@semantic-release/exec":"^6.0.3","@semantic-release/git":"^10.0.1","@semantic-release/github":"^8.0.4","eslint":"^6.3.0","fs-extra":"^10.1.0"},"scripts":{"reset":"rm -rf ./node_modules && yarn","lint":"eslint src/*.js","audit:competec":"node src","test":"jest"},"repository":{"type":"git","url":"git+https://github.com/Competec/yarn-audit-competec.git"},"bugs":{"url":"https://github.com/Competec/yarn-audit-competec.git/issues"},"homepage":"https://github.com/Competec/yarn-audit-competec.git","publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"dependencies":{"jest":"^29.3.1"},"_id":"@competec/yarn-audit-competec@2.0.0","gitHead":"166345cca6857fc74e6d76ad6f2772f0fa05f678","_nodeVersion":"20.17.0","_npmVersion":"10.8.3","dist":{"integrity":"sha512-vDnEiAiZIAk0GAjcRQOC33/kc3764CAypIcCJVhfSJCeLgBlwIPj64hCuyehNJZPGfF2MRwItTj60kl9CqGHVQ==","shasum":"70f938bf1a06d1dcd3dab7d08c4dee7130abd5f1","tarball":"https://registry.npmjs.org/@competec/yarn-audit-competec/-/yarn-audit-competec-2.0.0.tgz","fileCount":15,"unpackedSize":14006,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIB7DxH/hHM1zRphZFKMemGnIFylgHppzeyDL2m7yIhdXAiBC9vqvmZtQkNip1Hj4mkUWnwUR9dhubRw0NSUKm+frng=="}]},"_npmUser":{"name":"teamwebcompetec","email":"teamweb@competec.ch"},"directories":{},"maintainers":[{"name":"teamwebcompetec","email":"teamweb@competec.ch"},{"name":"raphaelh","email":"admin@rhy.pw"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/yarn-audit-competec_2.0.0_1726232960299_0.3607349455483786"},"_hasShrinkwrap":false}},"time":{"created":"2022-05-18T06:02:41.802Z","modified":"2024-09-13T13:09:20.870Z","1.0.0":"2022-05-18T06:02:42.020Z","2.0.0":"2024-09-13T13:09:20.546Z"},"bugs":{"url":"https://github.com/Competec/yarn-audit-competec.git/issues"},"author":{"name":"Francis C. / Competec"},"license":"MIT","homepage":"https://github.com/Competec/yarn-audit-competec.git","keywords":["yarn audit","supressions","competec"],"repository":{"type":"git","url":"git+https://github.com/Competec/yarn-audit-competec.git"},"description":"Competec Audit-Modules","maintainers":[{"name":"teamwebcompetec","email":"teamweb@competec.ch"},{"name":"raphaelh","email":"admin@rhy.pw"}],"readme":"This module is built on the original yarn audit command `yarn audit`. With the following additional features:\n\n1. End with a non-zero code, if audit advisories exists for packages in your node-modules\n2. Allow suppression of specified advisories for any given module\n3. Generate a json file containing the yarn audit summary\n\n## Installation\n\n1. Install the npm audit module (`yarn add yarn-audit-competec`)\n2. Add the suppression file\n3. Add the following script to your package.json\n\n```\n\"audit:competec\": \"yarn audit-competec\",\n```\n\n## Suppression file\n\nThe suppression file `~/.yarn-audit-competec/suppressions.js` should be places in the folder `.yarn-audit-competec`, which should be located at the root of your project and structured as follows:\n\n```\nmodule.exports = {\n    list: [\n        {\n            githubAdvisoryId: 'GHSA-hjp8-2cm3-cc45',\n            suppress: {\n                until: '2022-12-31Z',\n                reason: 'Third party',\n            },\n        },\n        ...more suppression entries\n    ],\n}\n```\n* githubAdvisoryId: The Github Advisory ID of the entry you wish to suppress\n* suppress.until: The validity of the grace period until this audit is finished with error\n* suppress.reason: A note for yourself, to remember why you are suppressing this advisory\n\n\n## Audit summary\nAn audit summary is generated in JSON format and is structured as follows:\n\n* ts: The timestamp at which the audit took place\n* summary.vulnerabilities: a map of all severity levels found and the frequencies\n* summary.dependencies: the number of modules with advisories in the dependencies\n* summary.devDependencies: the number of modules with advisories in the devDependencies\n* summary.optionalDependencies: the number of modules with advisories in the optionalDependencies\n* summary.totalDependencies: the total number of modules with advisories\n\nExample of audit summary:\n```\n{\n  \"ts\": 1652107729515,\n  \"summary\": {\n    \"vulnerabilities\": {\n      \"info\": 0,\n      \"low\": 0,\n      \"moderate\": 0,\n      \"high\": 0,\n      \"critical\": 0\n    },\n    \"dependencies\": 4,\n    \"devDependencies\": 0,\n    \"optionalDependencies\": 0,\n    \"totalDependencies\": 4\n  }\n}\n```\n\nVersion history\n\n* 1.0.0: Initial release\n* 1.0.1: Ignore licence check\n* 1.0.2: Treat \"Unknown error\" as failure\n* 2.0.0: removed `githubAadvisoryId` in favor of `githubAdvisoryId` in `suppressions.js` file\n","readmeFilename":"README.md"}