{"_id":"@efuture/bpr-npm-audit","name":"@efuture/bpr-npm-audit","dist-tags":{"latest":"1.5.0"},"versions":{"1.5.0":{"name":"@efuture/bpr-npm-audit","version":"1.5.0","description":"Bitbucket Pipelines report for \"npm audit\".","bin":{"bpr-npm-audit":"index.js"},"repository":{"type":"git","url":"git+https://github.com/efuturetoday/bpr-npm-audit.git"},"keywords":["bitbucket","pipelines","report","npm","audit","security"],"author":{"name":"Tobias Davis","email":"tobias@davistobias.com","url":"https://davistobias.com"},"license":"SEE LICENSE IN LICENSE.md","bugs":{"url":"https://github.com/efuturetoday/bpr-npm-audit/issues"},"homepage":"https://github.com/efuturetoday/bpr-npm-audit#readme","gitHead":"d5ab7e0dfe044dfe36b0a5bb62b98e76e891e879","_id":"@efuture/bpr-npm-audit@1.5.0","_nodeVersion":"18.13.0","_npmVersion":"9.6.4","dist":{"integrity":"sha512-shn9HIwEY44R/KZMi2RO5cdW7Fe9VVKCVXFliUwPfxPLJhshEgY6OVmHlYrsDB2JL8JxMZ8AP26UkroOwEoFBw==","shasum":"d14fcf5f6ca292a6c07e2c308ce09fa545dd938b","tarball":"https://registry.npmjs.org/@efuture/bpr-npm-audit/-/bpr-npm-audit-1.5.0.tgz","fileCount":22,"unpackedSize":82466,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCpQztHX/kMqRLI+V4l+FB6xpVoGeuGoy1U+TbU6rs4uAIhAL2LPt13V79zvIOxlY4hw+ieXOkjdlcv8p1suiI5K74W"}]},"_npmUser":{"name":"efuture","email":"oliver.koeln@gmail.com"},"directories":{},"maintainers":[{"name":"efuture","email":"oliver.koeln@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/bpr-npm-audit_1.5.0_1684832766014_0.16669240546992636"},"_hasShrinkwrap":false}},"time":{"created":"2023-05-23T09:06:05.938Z","1.5.0":"2023-05-23T09:06:06.251Z","modified":"2023-05-23T09:06:06.424Z"},"maintainers":[{"name":"efuture","email":"oliver.koeln@gmail.com"}],"description":"Bitbucket Pipelines report for \"npm audit\".","homepage":"https://github.com/efuturetoday/bpr-npm-audit#readme","keywords":["bitbucket","pipelines","report","npm","audit","security"],"repository":{"type":"git","url":"git+https://github.com/efuturetoday/bpr-npm-audit.git"},"author":{"name":"Tobias Davis","email":"tobias@davistobias.com","url":"https://davistobias.com"},"bugs":{"url":"https://github.com/efuturetoday/bpr-npm-audit/issues"},"license":"SEE LICENSE IN LICENSE.md","readme":"# bpr-npm-audit\n\nBitbucket Pipelines added [reports](https://confluence.atlassian.com/bitbucket/code-insights-994316785.html) as a feature in pull requests.\n\nWith this module, you can get the results of `npm audit` as a report, with *zero configuration*, using `npx`:\n\n```yaml\npipelines:\n  my-pipeline:\n    - step:\n        script:\n          - npx bpr-npm-audit\n```\n\nHave a look at this [example pull request](https://bitbucket.org/saibotsivad/test-bpr-npm-audit/pull-requests/1/fix-maybe-setting-the-proxy-is-better), which generates a report like this:\n\n![Example report image](./example-report.png)\n\n## Security\n\nThis module has zero dependencies (outside of NodeJS), and is simple enough to audit yourself.\n\nIf you are very paranoid, I recommend forking this repository, auditing the forked code, and then using `npx` pointed to your fork:\n\n```yaml\npipelines:\n  my-pipeline:\n    - step:\n        script:\n          - npx username/bpr-npm-audit\n```\n\n(Where `username` is your Github username.)\n\n## Configure\n\nParameters are passed in as environment variables. For example:\n\n```yaml\npipelines:\n  my-pipeline:\n    - step:\n        script:\n          - BPR_NAME=\"My Report\" BPR_ID=\"myid\" BPR_LEVEL=\"low\" BPR_MAX_BUFFER_SIZE=\"20971520\" npx bpr-npm-audit\n```\n\n### Authentication\nConfigure by setting the environment variable `BITBUCKET_AUTH`.\nThe content will be sent as Authorization header withing the requests.\n\n### Report Name\n\nConfigure by setting the environment variable `BPR_NAME`.\n\nDefault: `Security: npm audit`\n\n### Report ID\n\nConfigure by setting the environment variable `BPR_ID`.\n\nDefault: `npmaudit`\n\n### Fail Condition\n\nConfigure by setting the environment variable `BPR_LEVEL` to one of these options:\n\n* `low`\n* `moderate`\n* `high` (the default)\n* `critical`\n\nIf there are any vulnerabilities at that level or higher, the report will be marked as failed.\n\n### Reporting Level\n\nConfigure by setting the environment `BPR_LOG` to any of the `BPR_LEVEL` values.\n\nIf this is not set, all audit log entries will be included in the Pipeline Report.\n\nSetting this property will limit the Report to contain only audit log entries at this level or higher.\n\n### Max Buffer Size\n\nConfigure by setting the environment variable `BPR_MAX_BUFFER_SIZE` to desired value in bytes.\n\nDefault: `10485760` (10 MB)\n\nThe value shouldn't be changed unless you run into problems with `npm audit` output being too large to handle\n(usually signalled by `Unexpected end of JSON input` error).\n\n## License\n\nThis project is published and released under the [Very Open License](http://veryopenlicense.com).\n\n---\n\n(Made with ❤️ by [Tobias Davis](https://davistobias.com).)\n","readmeFilename":"README.md"}