What tools do you folks use to monitor your node dependencies and make sure you are keeping everything up to date?
What tools do you folks use to monitor your node dependencies and make sure you are keeping everything up to date?
I was thinking of making dependency-updates part of the CI-pipeline, using a 'allow_failure'-flag. However, if you decide not to upgrade a dep for some reason, this will cause each and every build to throw a warning.
Mostly I just really like the compact output, and the short "ncu" command which I run every day to check what's available :)
`npm update --save` or `npm update --save-dev` say explicitly "save updates to `dependencies` resp. `devDependencies`", which causes duplication between dependencies and devDependencies. (Say you have a dep foo and a devDep bar and both are outdated: `npm update --save` will bork package.json with an additional incorrect dep bar, and `npm update --save-dev` will bork it with an additional incorrect devDep foo :-/ )
Am I missing something? I understand there are 3rd-party packages providing such functionality, but is there any reason to not cover this feature in npm?