Get the App
SLTechnology News&Howtos  ›  IT Information  › 

The new Python tool can detect "Manifest confusion" problems in NPM packages

Shulou Source: shulou.com Published: 2023-11-24 17:54:15 10月02日 Update

CTOnews.com July 5, Darcy Clarke, former engineering manager of GitHub and NPM, warned last week that there was a "Manifest confusion" problem in NPM packages. System administrator Felix Pankratz recently released a Python-based tool that can help software developers check that NPM packages are consistent.

NPM is the package manager for the JavaScript programming language and the default configuration for the widely used Node.js environment.

The package manager helps project administrators automate the installation, upgrade, and configuration of software packages hosted on npmjs.com 's npm registry database.

Manifest confusion occurs when the maniefest information displayed by the package on the npm registry is inconsistent with the actual "package.json" file in the published npm package tarball used to install the package.

The GitHub page of the tool is attached to CTOnews.com, which can be downloaded by users who need it.

Users need the tool to install the relevant components:

Pip install-r requirements.txt if you just want to check a package, simply add the name of the package at the end of the script, for example:

The $. / npm-manifest-check.py darcyclarke-manifest-pkg feedback will show any mismatches in the versions, dependencies, scripts, and package names between the Manifest and the actual package.json file.

If you want to detect multiple packages, you can first add them to the "packages.list" file, and then use the "check_packages.sh" wrapper script to check.

Tags: Programs administration tools files scripts checks conformance information name actual registry users administrators software configuration problems detection between people just Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Apple macOS NVidia Huawei vpn