# @csense/npm-token

> Public package to inject NPM_TOKEN environment variable from a given store

Latest version **0.0.2** (published 2018-09-03) · ISC license · 0 weekly downloads

## Install

```sh
npm install @csense/npm-token
pnpm add @csense/npm-token
yarn add @csense/npm-token
bun add @csense/npm-token
```

## Health

**Score 15/100 (F)** — status: abandoned.

Positive: no vulnerabilities.

Warnings: low downloads; no types; no esm support; pre 1.0.

Negative: abandoned; low maintenance score.

## Facts

| | |
|---|---|
| Version | 0.0.2 |
| Published | 2018-09-03 |
| First published | 2018-09-03 |
| Weekly downloads | 0 |
| License | ISC |
| TypeScript types | none |
| Module format | CommonJS |
| Dependencies | 2 |
| Unpacked size | 5.7 KB |
| Known vulnerabilities | 0 (+1 in 1 direct dependencies) |
| Install scripts | no |
| Maintainers | csense |

## Links

- npm: https://www.npmjs.com/package/@csense/npm-token
- npm.io page: https://npm.io/package/@csense/npm-token

## Dependencies (2)

- [aws-sdk](https://npm.io/package/aws-sdk.md) ^2.302.0
- [fs-promise](https://npm.io/package/fs-promise.md) ^2.0.3

## Recent versions

- 0.0.2 (latest) — 2018-09-03
- 0.0.1 — 2018-09-03

## README

This package is published as **public** and should never contain sensitive information or expose resources.

This is a module that is used to set your ~/.npm_token file and NPM_TOKEN to the correct current version of the NPM_TOKEN which is stored in the parameter store.

Usage withing any rep will be ```AWS_PROFILE=[dev | staging] . update-token```  see 2) for more details

1) In you ~/.bash_profile make sure you have a line as follows  

```. "$HOME/.npm_token"```   
 
The . is very important   

2) From any api run ```AWS_PROFILE=[dev | staging] . update-token```

Now the **current** terminal and all **new** terminals will have the new NPM_TOKEN set correctly.  For any other terminals that you have open, want to keep open and have the new NPM_TOKEN you will need to ```AWS_PROFILE=dev . update-token```

## Getting api's and repos  to use prodigy-npm-token
Copy update-token.tmpl and rename it to update-token

## Read vs Write Tokens
Almost everyone should have the read token

If you need the write token it means you intend to publish from your local machine as opposed to having a pipeline do it automatically for you.  This is almost never desired but if you do need the write token make sure 

```export NPM_REQUEST_WRITE_TOKEN=true```  

is set in your ```./bash_profile```  and you have sourced it ```. ~/.bash_profile```

# For Devops

## app-local
app-local will need the build to be as follows

## Stage
app-stage will need something similar

## Dockerfile
Every Dockerfile will need 

```
ARG NPM_TOKEN=
ENV NPM_TOKEN=${NPM_TOKEN}
```

## Codebuild:

All codebuilds should have their environment include ```/_global/npm_read_token``` or ```/_global/npm_write_token``` from the parameter store as ```NPM_TOKEN``` evironment variable.  Which to choose depends on whether the codebuild needs to publish

Buildspec for codebuild will need to have an NPM_TOKEN build arg  
```--build-arg NPM_TOKEN=$NPM_TOKEN```

---
_Source: https://npm.io/package/@csense/npm-token · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
