# @team-supercharge/audit-ci-wrapper

> ![Node.js Package](https://github.com/team-supercharge/audit-ci-wrapper/workflows/Node.js%20Package/badge.svg)

Latest version **3.1.3** (published 2024-01-10) · ISC license · 0 weekly downloads

## Install

```sh
npm install @team-supercharge/audit-ci-wrapper
pnpm add @team-supercharge/audit-ci-wrapper
yarn add @team-supercharge/audit-ci-wrapper
bun add @team-supercharge/audit-ci-wrapper
```

Provides the command `audit-ci-wrapper`.

## Health

**Score 25/100 (F)** — status: abandoned.

Positive: has types; no vulnerabilities; high quality score.

Warnings: low downloads; no esm support.

Negative: abandoned; low maintenance score.

## Facts

| | |
|---|---|
| Version | 3.1.3 |
| Published | 2024-01-10 |
| First published | 2020-10-08 |
| Weekly downloads | 0 |
| License | ISC |
| TypeScript types | bundled |
| Module format | CommonJS |
| Dependencies | 3 |
| Unpacked size | 27.9 KB |
| Known vulnerabilities | 0 |
| Install scripts | no |
| Maintainers | kisfejes, rashan86, sc-gitlab-ci, martontoth-sc, exoszajzbuk, martontoth-deploy, csutorasr |

## Links

- npm: https://www.npmjs.com/package/@team-supercharge/audit-ci-wrapper
- npm.io page: https://npm.io/package/@team-supercharge/audit-ci-wrapper

## Dependencies (3)

- [chalk](https://npm.io/package/chalk.md) 4.1.0
- [semver](https://npm.io/package/semver.md) 7.5.3
- [argparse](https://npm.io/package/argparse.md) 2.0.1

## Recent versions

- 3.1.3 (latest) — 2024-01-10
- 3.1.2 — 2023-08-24
- 3.1.1 — 2023-07-05
- 3.1.0 — 2023-05-11
- 3.0.0 — 2023-03-24
- 2.2.0 — 2023-03-24
- 2.1.0 — 2022-07-01
- 2.0.0 — 2022-05-03
- 1.0.2 — 2020-12-02
- 1.0.1 — 2020-12-02
- 1.0.0 — 2020-10-08

## README

# @team-supercharge/audit-ci-wrapper

![Node.js Package](https://github.com/team-supercharge/audit-ci-wrapper/workflows/Node.js%20Package/badge.svg)

## Features

This package wraps the result of `npm audit` and creates a report.

`json` and `text` report types currently supported.

Fails with exit code 1 if any package has vulnerabilities that matches the criteria.

The text reporter writes `probable root cause` text to the output, if that package is the one that causes the error.

## NPM version support

This package requires at least NPM 7 since `>3.0.0`. If you want to use it with NPM 6, then install the latest [`1.x`](https://github.com/team-supercharge/audit-ci-wrapper/tree/v1.x) version.

## Running

It can run without installation.

```bash
npx @team-supercharge/audit-ci-wrapper
```

Or can be added to the project.

```bash
npx @team-supercharge/audit-ci-wrapper --install
npm install --save-dev @team-supercharge/audit-ci-wrapper
npm run audit
```

It can be done manually. Install, generate an auditconfig file and add to the project.

```bash
npm install --save-dev @team-supercharge/audit-ci-wrapper
npx @team-supercharge/audit-ci-wrapper --generate-config
```

```json
{
  "scripts": {
    "audit": "npx @team-supercharge/audit-ci-wrapper --config auditconfig.json"
  }
}
```

```bash
npm run audit
```

## Options

```
usage: @team-supercharge/audit-ci-wrapper [-h] [-c CONFIG] [-gc] [-i] [-q] [-v]

Audit wrapper application for npm.

optional arguments:
  -h, --help            show this help message and exit
  -c CONFIG, --config CONFIG
                        The config json file for auditing.
  -gc, --generate-config
                        Generates config file.
  -i, --install         Generates config file and add script to package.json.
  -q, --quiet           Turns off verbose logging.
  -v, --version         show program's version number and exit
```

## Configfile

The schema for the configfile can be found at `configschema.json`.

| Fieldname | Description | Values |
| --- | --- | --- |
| `severity` | Level of severity that makes audit fail. | `critical`, `high`, `moderate`, `low` |
| `ignoreDevelopmentDependencies` | If true development dependencies will be ignored. | `true`, `false` |
| `reportType` | The type of the output. | `text`, `json` |
| `npmExtraParams` | Extra parameters can be passed to `npm audit`, like `['--registry', '<URL>']` | `string[]` |
| `whitelist` | Object like `dependencies` of package.json. Key specifies a package name, the value is the whitelisted versions in semver format. | `Record<string, string>` |

## Contribution

To develop run `npm install`, `npm link` and `npm start`. This will run currently compiled version.

To run the test run `npm test` or `npm test:dev` to watch for changes.

## Release

In order to properly generate changelog and version tags, run `npm run release` once `master` is ready for it. Publish action will be triggered when newly created tag is released manually on Github UI.

---
_Source: https://npm.io/package/@team-supercharge/audit-ci-wrapper · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
