# @nodesecure/rc

> NodeSecure runtime configuration

Latest version **5.6.0** (published 2026-03-28) · MIT license · 0 weekly downloads

## Install

```sh
npm install @nodesecure/rc
pnpm add @nodesecure/rc
yarn add @nodesecure/rc
bun add @nodesecure/rc
```

## Health

**Score 70/100 (B)** — status: stable.

Positive: has types; esm support; no vulnerabilities; has provenance; high maintenance score; high quality score.

Warnings: low downloads.

## Facts

| | |
|---|---|
| Version | 5.6.0 |
| Published | 2026-03-28 |
| First published | 2022-02-05 |
| Weekly downloads | 0 |
| License | MIT |
| TypeScript types | bundled |
| Module format | ESM + CommonJS |
| Node | >=20 |
| Dependencies | 7 |
| Unpacked size | 42.9 KB |
| Known vulnerabilities | 0 |
| Install scripts | no |
| Provenance | attested (GitHub Actions) |
| GitHub stars | 40 |
| Author | GENTILHOMME Thomas |
| Maintainers | fraxken, tonygo, pierred, clemgbld |
| Keywords | rc, config, configuration |

## Links

- npm: https://www.npmjs.com/package/@nodesecure/rc
- Repository: https://github.com/NodeSecure/scanner
- Homepage: https://github.com/NodeSecure/tree/master/workspaces/rc#readme
- Issues: https://github.com/NodeSecure/scanner/issues
- npm.io page: https://npm.io/package/@nodesecure/rc

## Dependencies (7)

- [type-fest](https://npm.io/package/type-fest.md) ^5.0.1
- [lodash.merge](https://npm.io/package/lodash.merge.md) ^4.6.2
- [@openally/config](https://npm.io/package/@openally/config.md) ^1.0.1
- [@openally/result](https://npm.io/package/@openally/result.md) 2.0.0
- [@nodesecure/vulnera](https://npm.io/package/@nodesecure/vulnera.md) 3.1.0
- [@nodesecure/js-x-ray](https://npm.io/package/@nodesecure/js-x-ray.md) 15.0.0
- [@nodesecure/npm-types](https://npm.io/package/@nodesecure/npm-types.md) ^1.2.0

## Alternatives

- [jsforce](https://npm.io/package/jsforce.md) — 851.2K weekly downloads
- [react-native-qrcode-svg](https://npm.io/package/react-native-qrcode-svg.md) — 693.5K weekly downloads
- [@salesforce/plugin-data](https://npm.io/package/@salesforce/plugin-data.md) — 394.9K weekly downloads
- [@backstage/plugin-search-common](https://npm.io/package/@backstage/plugin-search-common.md) — 308.5K weekly downloads
- [@chain-registry/types](https://npm.io/package/@chain-registry/types.md) — 38.4K weekly downloads

## Recent versions

- 5.6.0 (latest) — 2026-03-28
- 5.5.0 — 2026-03-18
- 5.4.0 — 2026-02-24
- 5.3.0 — 2026-02-22
- 5.2.0 — 2026-02-14
- 5.1.0 — 2026-01-23
- 5.0.2 — 2026-01-02
- 5.0.1 — 2025-07-01
- 5.0.0 — 2025-06-17
- 4.1.0 — 2025-05-16
- 4.0.1 — 2025-02-17
- 4.0.0 — 2024-08-11
- 3.0.0 — 2024-07-31
- 2.1.0 — 2024-05-29
- 2.0.0 — 2024-05-20
- … 8 more at https://npm.io/package/@nodesecure/rc/versions

## README

<p align="center">
  <img src="https://user-images.githubusercontent.com/4438263/216045720-779bf16d-1d35-409f-a0e6-4019bda8edde.jpg" alt="@nodesecure/rc">
</p>

<p align="center">
  NodeSecure runtime configuration.
</p>

## Requirements

- [Node.js](https://nodejs.org/en/) v24 or higher

## Getting Started

This package is available in the Node Package Repository and can be easily installed with [npm](https://docs.npmjs.com/getting-started/what-is-npm) or [yarn](https://yarnpkg.com).

```bash
$ npm i @nodesecure/rc
# or
$ yarn add @nodesecure/rc
```

## Usage example

read:

```ts
import * as RC from "@nodesecure/rc";

const configurationPayload = (
  await RC.read(void 0, { createIfDoesNotExist: true })
).unwrap();
console.log(configurationPayload);
```

write:

```ts
import assert from "node:assert/strict";
import * as RC from "@nodesecure/rc";

const writeOpts: RC.writeOptions = {
  payload: { version: "2.0.0" },
  partialUpdate: true,
};

const result = (await RC.write(void 0, writeOpts)).unwrap();
assert.strictEqual(result, void 0);
```

memoize/memoized:

```ts
import * as RC from "@nodesecure/rc";
import assert from "node:assert";

const configurationPayload = (
    await RC.read(void 0, { createMode: "ci" })
).unwrap()

RC.memoize(configurationPayload, { overwrite: true });

const memoizedPayload = RC.memoized();
assert.deepEqual(configurationPayload, memoizedPayload);
```

> 👀 .read and .write return Rust like [Result](https://doc.rust-lang.org/std/result/) object.

## API

> [!NOTE]
> If `undefined`, the location will be assigned to `process.cwd()`.

### read(location?: string, options?: readOptions): Promise< Result< RC, NodeJS.ErrnoException > >

```ts
interface CreateReadOptions {
  /**
   * If enabled, the file will be created if it does not exist on disk.
   *
   * @default false
   */
  createIfDoesNotExist?: boolean;
  /**
   * Generate a more or less complete configuration.
   *
   * @default `minimal`
   */
  createMode?: RCGenerationMode | RCGenerationMode[];
  /**
   * Automatically cache the configuration when enabled.
   *
   * @default false
   */
  memoize?: boolean;
}

export type readOptions = RequireAtLeastOne<
  CreateReadOptions,
  "createIfDoesNotExist" | "createMode"
>;
```

The `createIfDoesNotExist` argument can be ignored if `createMode` is provided.

```ts
import * as RC from "@nodesecure/rc";

const configurationPayload = (
  await RC.read(void 0, { createMode: "ci" })
).unwrap();
console.log(configurationPayload);
```

### write(location?: string, options: WriteOptions): Promise< Result< void, NodeJS.ErrnoException > >

By default the write API will overwrite the current payload with the provided one. When the `partialUpdate` option is enabled it will merge the new properties with the existing one.

```ts
/**
 * Overwrite the complete payload. partialUpdate property is mandatory.
 */
export interface WriteCompletePayload {
  payload: RC;
  partialUpdate?: false;
}

/**
 * Partially update the payload. This implies not to rewrite the content of the file when enabled.
 **/
export interface WritePartialPayload {
  payload: Partial<RC>;
  partialUpdate: true;
}

export type WriteOptions = WriteCompletePayload | WritePartialPayload;
```
### memoize(payload: Partial< RC >, options: MemoizeOptions = {}): void
By default, the memory API overwrites the previous stored payload. When the `OVERWRITE` option is `false`, it merges new properties with existing properties.

```ts
export interface MemoizeOptions {
  overwrite?: boolean;
}
```
The `overwrite` option is used to specify whether data should be overwritten or merged.

### memoized(options: MemoizedOptions): Partial< RC > | null
This method returns null, when the default value is null, otherwise, it returns the current value of `memoizedValue`.

```ts
export interface MemoizedOptions {
  defaultValue: Partial<RC>;
}
```
If the `defaultValue` property is at null, then this value will be returned when `memoized` is called.

### maybeMemoized(): Option< Partial< RC > >

Same as memoized but return an Option monad.

```ts
import * as RC from "@nodesecure/rc";

const memoized = RC.maybeMemoized()
  .unwrapOr({}); // Some default RC here
```

### clearMemoized(): void
Clear/reset memoized RC

### homedir(): string

Dedicated directory for NodeSecure to store the configuration in the os HOME directory.

```ts
import * as RC from "@nodesecure/rc";

const homedir = RC.homedir();
```

### CONSTANTS

```ts
import assert from "node:assert/strict";
import * as RC from "@nodesecure/rc";

assert.strictEqual(RC.CONSTANTS.CONFIGURATION_NAME, ".nodesecurerc");
```

### Generation Mode

We provide by default a configuration generation that we consider `minimal`. On the contrary, a `complete` value will indicate the generation with all possible default keys.

```ts
export type RCGenerationMode = "minimal" | "ci" | "report" | "scanner" | "complete";
```

However, depending on the NodeSecure tool you are working on, it can be interesting to generate a configuration with some property sets specific to your needs.

Note that you can combine several modes:

```ts
import * as RC from "@nodesecure/rc";

await RC.read(void 0, { createMode: ["ci", "report"] });
```

## JSON Schema

The runtime configuration is validated using a JSON Schema: `./src/schema/nodesecurerc.json`.

It can be retrieved via API if needed:

```ts
import * as RC from "@nodesecure/rc";

console.log(RC.JSONSchema);
```

The JSON schema is a composition of multiple definitions for each tool:

- [ci](./src/schema/defs/ci.json)
  - [ciWarnings](./src/schema/defs/ciWarnings.json)
  - [contact](./src/schema/defs/contact.json)
- [report](./src/schema/defs/report.json)
  - [reportChart](./src/schema/defs/reportChart.json)
- [scanner](./src/schema/defs/scanner.json)

## License

MIT

---
_Source: https://npm.io/package/@nodesecure/rc · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
