Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions check.js
Original file line number Diff line number Diff line change
Expand Up @@ -11,6 +11,9 @@ function auditOk(issues) {
if (argv.yarn) {
pkgFacade.addImplementation('yarn', require('./src/pkgmanagers/yarn'))
pkgFacade.setActiveImplementation('yarn')
} else if (argv.pnpm) {
pkgFacade.addImplementation('pnpm', require('./src/pkgmanagers/pnpm'))
pkgFacade.setActiveImplementation('pnpm')
} else {
pkgFacade.addImplementation('npm', require('./src/pkgmanagers/npm'))
pkgFacade.setActiveImplementation('npm')
Expand Down
3 changes: 3 additions & 0 deletions resolve.js
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,9 @@ const auditResolver = require('./src/resolve/auditResolver')
if (argv.yarn) {
pkgFacade.addImplementation('yarn', require('./src/pkgmanagers/yarn'))
pkgFacade.setActiveImplementation('yarn')
} else if (argv.pnpm) {
pkgFacade.addImplementation('pnpm', require('./src/pkgmanagers/pnpm'))
pkgFacade.setActiveImplementation('pnpm')
} else {
pkgFacade.addImplementation('npm', require('./src/pkgmanagers/npm'))
pkgFacade.setActiveImplementation('npm')
Expand Down
47 changes: 47 additions & 0 deletions src/pkgmanagers/pnpm.js
Original file line number Diff line number Diff line change
@@ -0,0 +1,47 @@
const unparse = require('../unparse')
const skipArgs = require('../skipArgs')

function getCommand(action) {
// Derived from pnpm-audit-report
// TODO: share the code
Copy link
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This looks familiar. Is this comment section true?

if (action.action === 'install') {
const isDev = action.resolves[0].dev
return `pnpm install ${isDev ? '--save-dev ' : ''}${action.module}@${action.target}`
} else {
return `pnpm update ${action.module} --depth ${action.depth}`
}
}

module.exports = {
Copy link
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Doesn't look like it's any different from npm. Is this just 'p' added to every 'npm' in the code, or I missed the changes?

Is that enough for it to work?

Copy link
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@naugtur PNPM commands are almost similar to NPM. It works. We are using my fork in production.

version: 1,
getAudit({ promiseCommand, argv, shellOptions }) {
const unparsed = unparse(argv, skipArgs)

return promiseCommand(`pnpm audit --json ${unparsed}`, shellOptions)
.then(output => {
try {
return JSON.parse(output)
} catch (e) {
console.error('failed to parse output')
console.error(output)
throw e;
}
})
.then(parsed => {
if (parsed.error) {
throw Error(`'pnpm audit' failed with ${parsed.error.code}. Check the log above for more details.`);
}
return parsed
})
//TODO: retries on ENOAUDIT
},
fix({ promiseCommand, argv, shellOptions, action }) {

return promiseCommand(getCommand(action), shellOptions)
},
remove({ promiseCommand, argv, shellOptions, names }) {
//TODO: include the fact that some of them are dev dependencies and we don't know which, because we shouldn't have to at this point
//FIXME: this command might not delete everything as expected
return promiseCommand(`pnpm rm ${names.join(' ')}`, shellOptions)
}
}
2 changes: 1 addition & 1 deletion src/skipArgs.js
Original file line number Diff line number Diff line change
@@ -1 +1 @@
module.exports = ['json', 'migrate', 'yarn', 'mock', 'fix']
module.exports = ['json', 'migrate', 'yarn', 'pnpm', 'mock', 'fix']