npm outdated with arborist - #1208

Merged
claudiahdz merged 6 commits into
release/v7.0.0-betafrom
feat/npm-outdated
Jun 5, 2020
Merged

npm outdated with arborist#1208
claudiahdz merged 6 commits into
release/v7.0.0-betafrom
feat/npm-outdated

Conversation

@claudiahdz

@claudiahdzclaudiahdz commented Apr 25, 2020

Copy link
Copy Markdown
Contributor

Changes

This PR is a refactor of npm outdated with Arborist. It removes the --depth option flag and introduces a new --all one for displaying all outdated dependencies in a tree. The homepage information of a package is now taken directly from the packument instead of the package.json to avoid displaying outdated information. The location info is now the node.location (it's position on the physical tree) instead of it's position on the logical dependency tree.

A new column Depended by was also added on the default display that shows which package depends on the displayed dependency. This makes the information displayed when --all is on easier to understand.

References

http://github.com/npm/rfcs/pull/133

Examples

➜ arborist git:(master) npm outdated
Package Current Wanted Latest Location Depended by
@npmcli/run-script 1.2.1 1.3.1 1.3.1 node_modules/@npmcli/run-script arborist
minify-registry-metadata 2.1.0 2.2.0 2.2.0 node_modules/minify-registry-metadata arborist
npm-package-arg 8.0.0 8.0.1 8.0.1 node_modules/npm-package-arg arborist
pacote 11.1.0 11.1.7 11.1.7 node_modules/pacote arborist
semver 7.1.2 7.3.2 7.3.2 node_modules/semver arborist
tap 14.10.6 14.10.7 14.10.7 node_modules/tap arborist
tcompare 3.0.4 3.0.4 5.0.2 node_modules/tcompare arborist
treeverse 1.0.2 1.0.3 1.0.3 node_modules/treeverse arborist
➜ arborist git:(master) npm outdated tar
Package Current Wanted Latest Location Depended by
tar 6.0.1 6.0.2 6.0.2 node_modules/tar cacache
tar 6.0.1 6.0.2 6.0.2 node_modules/tar pacote
tar 4.4.13 6.0.2 6.0.2 node_modules/node-gyp/node_modules/tar node-gyp

@claudiahdz
claudiahdz requested a review from isaacsMay 1, 2020 22:28
@claudiahdz
claudiahdz marked this pull request as ready for review May 1, 2020 22:30
@claudiahdz
claudiahdz requested a review from a team as a code ownerMay 1, 2020 22:30

@isaacsisaacs left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

There are some ways to lean on the Edge class to do a bit more work here, and we can optimize the async fetches for packuments to go a little faster.

Areas for further improvement (perhaps outside the scope of this PR):

  • What happens with git deps? It'd be nice if we could detect things other than versions being outdated, but also git deps that are not up to date. We'd have to treat the "wanted" as the resolved value, of course, since a lot of the time, those things won't be on the registry, and the "packument" is fake, so we'd need to look at the manifest._resolved rather than manifest.version.
  • Needs to be updated to handle cases where there are multiple edges that limit what a package can be. If you have a deduped top-level dep that can be updated, with another dep depending on its current version, maybe "wanted" would be a lower version in --all mode? I'm not sure the best way to present that. Showing a separate line for each dependent is pretty noisy.

Comment threadlib/update.js
Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js
@isaacs
isaacsforce-pushed the release/v7.0.0-beta branch from cd6840b to e57a991CompareMay 8, 2020 01:14
@darcyclarkedarcyclarke added this to the OSS - Sprint 8 milestone Jun 1, 2020
@darcyclarkedarcyclarke added Enhancement new feature or improvement Release 7.x work is associated with a specific npm 7 release labels Jun 1, 2020
Comment threadlib/outdated.js
@claudiahdz
claudiahdzforce-pushed the feat/npm-outdated branch 3 times, most recently from 8d8d997 to f17be9aCompareJune 4, 2020 21:50

@isaacsisaacs left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Super minor nit that could be polished to remove the extra name field in the set of objects, and one open question. But the nit really is super minor, and the open question should probably be an RFC anyway (or maybe just a separate issue/PR) since it'd be a deviation from v6 behavior.

LGTM!

Comment threadlib/outdated.js
columns[5] = type
columns[6] = homepage
}
const tree = await arb.loadActual()

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was thinking we might want this to be arb.buildIdealTree() so it finds outdated deps in the virtual tree, falling back to the actual if there's no lockfile. But I wonder if that even makes sense? The current behavior only looks at the actual tree, but it also predates the existence of lockfiles, so I'm not sure how much sense it makes to go based on that.

Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js
if (deps.length !== 0) {
// specific deps
for (let i = 0; i < deps.length; i++) {
const nodes = tree.inventory.query('name', deps[i])

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was initially a little curious as to why you had that in/out switch in getEdges, but it makes sense seeing this. This is a lot more efficient than looping over every node in the tree!

@claudiahdz
claudiahdz merged commit 05e76ef into release/v7.0.0-betaJun 5, 2020
@claudiahdz
claudiahdz deleted the feat/npm-outdated branch June 5, 2020 21:43
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Enhancementnew feature or improvementRelease 7.xwork is associated with a specific npm 7 release

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@claudiahdz@isaacs@ruyadorno@darcyclarke
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

npm outdated with arborist - #1208

Merged
claudiahdz merged 6 commits into
release/v7.0.0-betafrom
feat/npm-outdated
Jun 5, 2020
Merged

npm outdated with arborist#1208
claudiahdz merged 6 commits into
release/v7.0.0-betafrom
feat/npm-outdated

Conversation

@claudiahdz

@claudiahdzclaudiahdz commented Apr 25, 2020

Copy link
Copy Markdown
Contributor

Changes

This PR is a refactor of npm outdated with Arborist. It removes the --depth option flag and introduces a new --all one for displaying all outdated dependencies in a tree. The homepage information of a package is now taken directly from the packument instead of the package.json to avoid displaying outdated information. The location info is now the node.location (it's position on the physical tree) instead of it's position on the logical dependency tree.

A new column Depended by was also added on the default display that shows which package depends on the displayed dependency. This makes the information displayed when --all is on easier to understand.

References

http://github.com/npm/rfcs/pull/133

Examples

➜ arborist git:(master) npm outdated
Package Current Wanted Latest Location Depended by
@npmcli/run-script 1.2.1 1.3.1 1.3.1 node_modules/@npmcli/run-script arborist
minify-registry-metadata 2.1.0 2.2.0 2.2.0 node_modules/minify-registry-metadata arborist
npm-package-arg 8.0.0 8.0.1 8.0.1 node_modules/npm-package-arg arborist
pacote 11.1.0 11.1.7 11.1.7 node_modules/pacote arborist
semver 7.1.2 7.3.2 7.3.2 node_modules/semver arborist
tap 14.10.6 14.10.7 14.10.7 node_modules/tap arborist
tcompare 3.0.4 3.0.4 5.0.2 node_modules/tcompare arborist
treeverse 1.0.2 1.0.3 1.0.3 node_modules/treeverse arborist
➜ arborist git:(master) npm outdated tar
Package Current Wanted Latest Location Depended by
tar 6.0.1 6.0.2 6.0.2 node_modules/tar cacache
tar 6.0.1 6.0.2 6.0.2 node_modules/tar pacote
tar 4.4.13 6.0.2 6.0.2 node_modules/node-gyp/node_modules/tar node-gyp

@claudiahdz
claudiahdz requested a review from isaacsMay 1, 2020 22:28
@claudiahdz
claudiahdz marked this pull request as ready for review May 1, 2020 22:30
@claudiahdz
claudiahdz requested a review from a team as a code ownerMay 1, 2020 22:30

@isaacsisaacs left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

There are some ways to lean on the Edge class to do a bit more work here, and we can optimize the async fetches for packuments to go a little faster.

Areas for further improvement (perhaps outside the scope of this PR):

  • What happens with git deps? It'd be nice if we could detect things other than versions being outdated, but also git deps that are not up to date. We'd have to treat the "wanted" as the resolved value, of course, since a lot of the time, those things won't be on the registry, and the "packument" is fake, so we'd need to look at the manifest._resolved rather than manifest.version.
  • Needs to be updated to handle cases where there are multiple edges that limit what a package can be. If you have a deduped top-level dep that can be updated, with another dep depending on its current version, maybe "wanted" would be a lower version in --all mode? I'm not sure the best way to present that. Showing a separate line for each dependent is pretty noisy.

Comment threadlib/update.js
Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js
@isaacs
isaacsforce-pushed the release/v7.0.0-beta branch from cd6840b to e57a991CompareMay 8, 2020 01:14
@darcyclarkedarcyclarke added this to the OSS - Sprint 8 milestone Jun 1, 2020
@darcyclarkedarcyclarke added Enhancement new feature or improvement Release 7.x work is associated with a specific npm 7 release labels Jun 1, 2020
Comment threadlib/outdated.js
@claudiahdz
claudiahdzforce-pushed the feat/npm-outdated branch 3 times, most recently from 8d8d997 to f17be9aCompareJune 4, 2020 21:50

@isaacsisaacs left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Super minor nit that could be polished to remove the extra name field in the set of objects, and one open question. But the nit really is super minor, and the open question should probably be an RFC anyway (or maybe just a separate issue/PR) since it'd be a deviation from v6 behavior.

LGTM!

Comment threadlib/outdated.js
columns[5] = type
columns[6] = homepage
}
const tree = await arb.loadActual()

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was thinking we might want this to be arb.buildIdealTree() so it finds outdated deps in the virtual tree, falling back to the actual if there's no lockfile. But I wonder if that even makes sense? The current behavior only looks at the actual tree, but it also predates the existence of lockfiles, so I'm not sure how much sense it makes to go based on that.

Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js
if (deps.length !== 0) {
// specific deps
for (let i = 0; i < deps.length; i++) {
const nodes = tree.inventory.query('name', deps[i])

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was initially a little curious as to why you had that in/out switch in getEdges, but it makes sense seeing this. This is a lot more efficient than looping over every node in the tree!

@claudiahdz
claudiahdz merged commit 05e76ef into release/v7.0.0-betaJun 5, 2020
@claudiahdz
claudiahdz deleted the feat/npm-outdated branch June 5, 2020 21:43
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Enhancementnew feature or improvementRelease 7.xwork is associated with a specific npm 7 release

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@claudiahdz@isaacs@ruyadorno@darcyclarke
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

npm outdated with arborist - #1208

Merged
claudiahdz merged 6 commits into
release/v7.0.0-betafrom
feat/npm-outdated
Jun 5, 2020
Merged

npm outdated with arborist#1208
claudiahdz merged 6 commits into
release/v7.0.0-betafrom
feat/npm-outdated

Conversation

@claudiahdz

@claudiahdzclaudiahdz commented Apr 25, 2020

Copy link
Copy Markdown
Contributor

Changes

This PR is a refactor of npm outdated with Arborist. It removes the --depth option flag and introduces a new --all one for displaying all outdated dependencies in a tree. The homepage information of a package is now taken directly from the packument instead of the package.json to avoid displaying outdated information. The location info is now the node.location (it's position on the physical tree) instead of it's position on the logical dependency tree.

A new column Depended by was also added on the default display that shows which package depends on the displayed dependency. This makes the information displayed when --all is on easier to understand.

References

http://github.com/npm/rfcs/pull/133

Examples

➜ arborist git:(master) npm outdated
Package Current Wanted Latest Location Depended by
@npmcli/run-script 1.2.1 1.3.1 1.3.1 node_modules/@npmcli/run-script arborist
minify-registry-metadata 2.1.0 2.2.0 2.2.0 node_modules/minify-registry-metadata arborist
npm-package-arg 8.0.0 8.0.1 8.0.1 node_modules/npm-package-arg arborist
pacote 11.1.0 11.1.7 11.1.7 node_modules/pacote arborist
semver 7.1.2 7.3.2 7.3.2 node_modules/semver arborist
tap 14.10.6 14.10.7 14.10.7 node_modules/tap arborist
tcompare 3.0.4 3.0.4 5.0.2 node_modules/tcompare arborist
treeverse 1.0.2 1.0.3 1.0.3 node_modules/treeverse arborist
➜ arborist git:(master) npm outdated tar
Package Current Wanted Latest Location Depended by
tar 6.0.1 6.0.2 6.0.2 node_modules/tar cacache
tar 6.0.1 6.0.2 6.0.2 node_modules/tar pacote
tar 4.4.13 6.0.2 6.0.2 node_modules/node-gyp/node_modules/tar node-gyp

@claudiahdz
claudiahdz requested a review from isaacsMay 1, 2020 22:28
@claudiahdz
claudiahdz marked this pull request as ready for review May 1, 2020 22:30
@claudiahdz
claudiahdz requested a review from a team as a code ownerMay 1, 2020 22:30

@isaacsisaacs left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

There are some ways to lean on the Edge class to do a bit more work here, and we can optimize the async fetches for packuments to go a little faster.

Areas for further improvement (perhaps outside the scope of this PR):

  • What happens with git deps? It'd be nice if we could detect things other than versions being outdated, but also git deps that are not up to date. We'd have to treat the "wanted" as the resolved value, of course, since a lot of the time, those things won't be on the registry, and the "packument" is fake, so we'd need to look at the manifest._resolved rather than manifest.version.
  • Needs to be updated to handle cases where there are multiple edges that limit what a package can be. If you have a deduped top-level dep that can be updated, with another dep depending on its current version, maybe "wanted" would be a lower version in --all mode? I'm not sure the best way to present that. Showing a separate line for each dependent is pretty noisy.

Comment threadlib/update.js
Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js
@isaacs
isaacsforce-pushed the release/v7.0.0-beta branch from cd6840b to e57a991CompareMay 8, 2020 01:14
@darcyclarkedarcyclarke added this to the OSS - Sprint 8 milestone Jun 1, 2020
@darcyclarkedarcyclarke added Enhancement new feature or improvement Release 7.x work is associated with a specific npm 7 release labels Jun 1, 2020
Comment threadlib/outdated.js
@claudiahdz
claudiahdzforce-pushed the feat/npm-outdated branch 3 times, most recently from 8d8d997 to f17be9aCompareJune 4, 2020 21:50

@isaacsisaacs left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Super minor nit that could be polished to remove the extra name field in the set of objects, and one open question. But the nit really is super minor, and the open question should probably be an RFC anyway (or maybe just a separate issue/PR) since it'd be a deviation from v6 behavior.

LGTM!

Comment threadlib/outdated.js
columns[5] = type
columns[6] = homepage
}
const tree = await arb.loadActual()

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was thinking we might want this to be arb.buildIdealTree() so it finds outdated deps in the virtual tree, falling back to the actual if there's no lockfile. But I wonder if that even makes sense? The current behavior only looks at the actual tree, but it also predates the existence of lockfiles, so I'm not sure how much sense it makes to go based on that.

Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js
if (deps.length !== 0) {
// specific deps
for (let i = 0; i < deps.length; i++) {
const nodes = tree.inventory.query('name', deps[i])

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was initially a little curious as to why you had that in/out switch in getEdges, but it makes sense seeing this. This is a lot more efficient than looping over every node in the tree!

@claudiahdz
claudiahdz merged commit 05e76ef into release/v7.0.0-betaJun 5, 2020
@claudiahdz
claudiahdz deleted the feat/npm-outdated branch June 5, 2020 21:43
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Enhancementnew feature or improvementRelease 7.xwork is associated with a specific npm 7 release

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@claudiahdz@isaacs@ruyadorno@darcyclarke
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

npm outdated with arborist - #1208

Merged
claudiahdz merged 6 commits into
release/v7.0.0-betafrom
feat/npm-outdated
Jun 5, 2020
Merged

npm outdated with arborist#1208
claudiahdz merged 6 commits into
release/v7.0.0-betafrom
feat/npm-outdated

Conversation

@claudiahdz

@claudiahdzclaudiahdz commented Apr 25, 2020

Copy link
Copy Markdown
Contributor

Changes

This PR is a refactor of npm outdated with Arborist. It removes the --depth option flag and introduces a new --all one for displaying all outdated dependencies in a tree. The homepage information of a package is now taken directly from the packument instead of the package.json to avoid displaying outdated information. The location info is now the node.location (it's position on the physical tree) instead of it's position on the logical dependency tree.

A new column Depended by was also added on the default display that shows which package depends on the displayed dependency. This makes the information displayed when --all is on easier to understand.

References

http://github.com/npm/rfcs/pull/133

Examples

➜ arborist git:(master) npm outdated
Package Current Wanted Latest Location Depended by
@npmcli/run-script 1.2.1 1.3.1 1.3.1 node_modules/@npmcli/run-script arborist
minify-registry-metadata 2.1.0 2.2.0 2.2.0 node_modules/minify-registry-metadata arborist
npm-package-arg 8.0.0 8.0.1 8.0.1 node_modules/npm-package-arg arborist
pacote 11.1.0 11.1.7 11.1.7 node_modules/pacote arborist
semver 7.1.2 7.3.2 7.3.2 node_modules/semver arborist
tap 14.10.6 14.10.7 14.10.7 node_modules/tap arborist
tcompare 3.0.4 3.0.4 5.0.2 node_modules/tcompare arborist
treeverse 1.0.2 1.0.3 1.0.3 node_modules/treeverse arborist
➜ arborist git:(master) npm outdated tar
Package Current Wanted Latest Location Depended by
tar 6.0.1 6.0.2 6.0.2 node_modules/tar cacache
tar 6.0.1 6.0.2 6.0.2 node_modules/tar pacote
tar 4.4.13 6.0.2 6.0.2 node_modules/node-gyp/node_modules/tar node-gyp

@claudiahdz
claudiahdz requested a review from isaacsMay 1, 2020 22:28
@claudiahdz
claudiahdz marked this pull request as ready for review May 1, 2020 22:30
@claudiahdz
claudiahdz requested a review from a team as a code ownerMay 1, 2020 22:30

@isaacsisaacs left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

There are some ways to lean on the Edge class to do a bit more work here, and we can optimize the async fetches for packuments to go a little faster.

Areas for further improvement (perhaps outside the scope of this PR):

  • What happens with git deps? It'd be nice if we could detect things other than versions being outdated, but also git deps that are not up to date. We'd have to treat the "wanted" as the resolved value, of course, since a lot of the time, those things won't be on the registry, and the "packument" is fake, so we'd need to look at the manifest._resolved rather than manifest.version.
  • Needs to be updated to handle cases where there are multiple edges that limit what a package can be. If you have a deduped top-level dep that can be updated, with another dep depending on its current version, maybe "wanted" would be a lower version in --all mode? I'm not sure the best way to present that. Showing a separate line for each dependent is pretty noisy.

Comment threadlib/update.js
Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js
@isaacs
isaacsforce-pushed the release/v7.0.0-beta branch from cd6840b to e57a991CompareMay 8, 2020 01:14
@darcyclarkedarcyclarke added this to the OSS - Sprint 8 milestone Jun 1, 2020
@darcyclarkedarcyclarke added Enhancement new feature or improvement Release 7.x work is associated with a specific npm 7 release labels Jun 1, 2020
Comment threadlib/outdated.js
@claudiahdz
claudiahdzforce-pushed the feat/npm-outdated branch 3 times, most recently from 8d8d997 to f17be9aCompareJune 4, 2020 21:50

@isaacsisaacs left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Super minor nit that could be polished to remove the extra name field in the set of objects, and one open question. But the nit really is super minor, and the open question should probably be an RFC anyway (or maybe just a separate issue/PR) since it'd be a deviation from v6 behavior.

LGTM!

Comment threadlib/outdated.js
columns[5] = type
columns[6] = homepage
}
const tree = await arb.loadActual()

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was thinking we might want this to be arb.buildIdealTree() so it finds outdated deps in the virtual tree, falling back to the actual if there's no lockfile. But I wonder if that even makes sense? The current behavior only looks at the actual tree, but it also predates the existence of lockfiles, so I'm not sure how much sense it makes to go based on that.

Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js
if (deps.length !== 0) {
// specific deps
for (let i = 0; i < deps.length; i++) {
const nodes = tree.inventory.query('name', deps[i])

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was initially a little curious as to why you had that in/out switch in getEdges, but it makes sense seeing this. This is a lot more efficient than looping over every node in the tree!

@claudiahdz
claudiahdz merged commit 05e76ef into release/v7.0.0-betaJun 5, 2020
@claudiahdz
claudiahdz deleted the feat/npm-outdated branch June 5, 2020 21:43
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Enhancementnew feature or improvementRelease 7.xwork is associated with a specific npm 7 release

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@claudiahdz@isaacs@ruyadorno@darcyclarke
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

npm outdated with arborist - #1208

Merged
claudiahdz merged 6 commits into
release/v7.0.0-betafrom
feat/npm-outdated
Jun 5, 2020
Merged

npm outdated with arborist#1208
claudiahdz merged 6 commits into
release/v7.0.0-betafrom
feat/npm-outdated

Conversation

@claudiahdz

@claudiahdzclaudiahdz commented Apr 25, 2020

Copy link
Copy Markdown
Contributor

Changes

This PR is a refactor of npm outdated with Arborist. It removes the --depth option flag and introduces a new --all one for displaying all outdated dependencies in a tree. The homepage information of a package is now taken directly from the packument instead of the package.json to avoid displaying outdated information. The location info is now the node.location (it's position on the physical tree) instead of it's position on the logical dependency tree.

A new column Depended by was also added on the default display that shows which package depends on the displayed dependency. This makes the information displayed when --all is on easier to understand.

References

http://github.com/npm/rfcs/pull/133

Examples

➜ arborist git:(master) npm outdated
Package Current Wanted Latest Location Depended by
@npmcli/run-script 1.2.1 1.3.1 1.3.1 node_modules/@npmcli/run-script arborist
minify-registry-metadata 2.1.0 2.2.0 2.2.0 node_modules/minify-registry-metadata arborist
npm-package-arg 8.0.0 8.0.1 8.0.1 node_modules/npm-package-arg arborist
pacote 11.1.0 11.1.7 11.1.7 node_modules/pacote arborist
semver 7.1.2 7.3.2 7.3.2 node_modules/semver arborist
tap 14.10.6 14.10.7 14.10.7 node_modules/tap arborist
tcompare 3.0.4 3.0.4 5.0.2 node_modules/tcompare arborist
treeverse 1.0.2 1.0.3 1.0.3 node_modules/treeverse arborist
➜ arborist git:(master) npm outdated tar
Package Current Wanted Latest Location Depended by
tar 6.0.1 6.0.2 6.0.2 node_modules/tar cacache
tar 6.0.1 6.0.2 6.0.2 node_modules/tar pacote
tar 4.4.13 6.0.2 6.0.2 node_modules/node-gyp/node_modules/tar node-gyp

@claudiahdz
claudiahdz requested a review from isaacsMay 1, 2020 22:28
@claudiahdz
claudiahdz marked this pull request as ready for review May 1, 2020 22:30
@claudiahdz
claudiahdz requested a review from a team as a code ownerMay 1, 2020 22:30

@isaacsisaacs left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

There are some ways to lean on the Edge class to do a bit more work here, and we can optimize the async fetches for packuments to go a little faster.

Areas for further improvement (perhaps outside the scope of this PR):

  • What happens with git deps? It'd be nice if we could detect things other than versions being outdated, but also git deps that are not up to date. We'd have to treat the "wanted" as the resolved value, of course, since a lot of the time, those things won't be on the registry, and the "packument" is fake, so we'd need to look at the manifest._resolved rather than manifest.version.
  • Needs to be updated to handle cases where there are multiple edges that limit what a package can be. If you have a deduped top-level dep that can be updated, with another dep depending on its current version, maybe "wanted" would be a lower version in --all mode? I'm not sure the best way to present that. Showing a separate line for each dependent is pretty noisy.

Comment threadlib/update.js
Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js
@isaacs
isaacsforce-pushed the release/v7.0.0-beta branch from cd6840b to e57a991CompareMay 8, 2020 01:14
@darcyclarkedarcyclarke added this to the OSS - Sprint 8 milestone Jun 1, 2020
@darcyclarkedarcyclarke added Enhancement new feature or improvement Release 7.x work is associated with a specific npm 7 release labels Jun 1, 2020
Comment threadlib/outdated.js
@claudiahdz
claudiahdzforce-pushed the feat/npm-outdated branch 3 times, most recently from 8d8d997 to f17be9aCompareJune 4, 2020 21:50

@isaacsisaacs left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Super minor nit that could be polished to remove the extra name field in the set of objects, and one open question. But the nit really is super minor, and the open question should probably be an RFC anyway (or maybe just a separate issue/PR) since it'd be a deviation from v6 behavior.

LGTM!

Comment threadlib/outdated.js
columns[5] = type
columns[6] = homepage
}
const tree = await arb.loadActual()

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was thinking we might want this to be arb.buildIdealTree() so it finds outdated deps in the virtual tree, falling back to the actual if there's no lockfile. But I wonder if that even makes sense? The current behavior only looks at the actual tree, but it also predates the existence of lockfiles, so I'm not sure how much sense it makes to go based on that.

Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js
if (deps.length !== 0) {
// specific deps
for (let i = 0; i < deps.length; i++) {
const nodes = tree.inventory.query('name', deps[i])

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was initially a little curious as to why you had that in/out switch in getEdges, but it makes sense seeing this. This is a lot more efficient than looping over every node in the tree!

@claudiahdz
claudiahdz merged commit 05e76ef into release/v7.0.0-betaJun 5, 2020
@claudiahdz
claudiahdz deleted the feat/npm-outdated branch June 5, 2020 21:43
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Enhancementnew feature or improvementRelease 7.xwork is associated with a specific npm 7 release

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@claudiahdz@isaacs@ruyadorno@darcyclarke
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

npm outdated with arborist - #1208

Merged
claudiahdz merged 6 commits into
release/v7.0.0-betafrom
feat/npm-outdated
Jun 5, 2020
Merged

npm outdated with arborist#1208
claudiahdz merged 6 commits into
release/v7.0.0-betafrom
feat/npm-outdated

Conversation

@claudiahdz

@claudiahdzclaudiahdz commented Apr 25, 2020

Copy link
Copy Markdown
Contributor

Changes

This PR is a refactor of npm outdated with Arborist. It removes the --depth option flag and introduces a new --all one for displaying all outdated dependencies in a tree. The homepage information of a package is now taken directly from the packument instead of the package.json to avoid displaying outdated information. The location info is now the node.location (it's position on the physical tree) instead of it's position on the logical dependency tree.

A new column Depended by was also added on the default display that shows which package depends on the displayed dependency. This makes the information displayed when --all is on easier to understand.

References

http://github.com/npm/rfcs/pull/133

Examples

➜ arborist git:(master) npm outdated
Package Current Wanted Latest Location Depended by
@npmcli/run-script 1.2.1 1.3.1 1.3.1 node_modules/@npmcli/run-script arborist
minify-registry-metadata 2.1.0 2.2.0 2.2.0 node_modules/minify-registry-metadata arborist
npm-package-arg 8.0.0 8.0.1 8.0.1 node_modules/npm-package-arg arborist
pacote 11.1.0 11.1.7 11.1.7 node_modules/pacote arborist
semver 7.1.2 7.3.2 7.3.2 node_modules/semver arborist
tap 14.10.6 14.10.7 14.10.7 node_modules/tap arborist
tcompare 3.0.4 3.0.4 5.0.2 node_modules/tcompare arborist
treeverse 1.0.2 1.0.3 1.0.3 node_modules/treeverse arborist
➜ arborist git:(master) npm outdated tar
Package Current Wanted Latest Location Depended by
tar 6.0.1 6.0.2 6.0.2 node_modules/tar cacache
tar 6.0.1 6.0.2 6.0.2 node_modules/tar pacote
tar 4.4.13 6.0.2 6.0.2 node_modules/node-gyp/node_modules/tar node-gyp

@claudiahdz
claudiahdz requested a review from isaacsMay 1, 2020 22:28
@claudiahdz
claudiahdz marked this pull request as ready for review May 1, 2020 22:30
@claudiahdz
claudiahdz requested a review from a team as a code ownerMay 1, 2020 22:30

@isaacsisaacs left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

There are some ways to lean on the Edge class to do a bit more work here, and we can optimize the async fetches for packuments to go a little faster.

Areas for further improvement (perhaps outside the scope of this PR):

  • What happens with git deps? It'd be nice if we could detect things other than versions being outdated, but also git deps that are not up to date. We'd have to treat the "wanted" as the resolved value, of course, since a lot of the time, those things won't be on the registry, and the "packument" is fake, so we'd need to look at the manifest._resolved rather than manifest.version.
  • Needs to be updated to handle cases where there are multiple edges that limit what a package can be. If you have a deduped top-level dep that can be updated, with another dep depending on its current version, maybe "wanted" would be a lower version in --all mode? I'm not sure the best way to present that. Showing a separate line for each dependent is pretty noisy.

Comment threadlib/update.js
Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js
@isaacs
isaacsforce-pushed the release/v7.0.0-beta branch from cd6840b to e57a991CompareMay 8, 2020 01:14
@darcyclarkedarcyclarke added this to the OSS - Sprint 8 milestone Jun 1, 2020
@darcyclarkedarcyclarke added Enhancement new feature or improvement Release 7.x work is associated with a specific npm 7 release labels Jun 1, 2020
Comment threadlib/outdated.js
@claudiahdz
claudiahdzforce-pushed the feat/npm-outdated branch 3 times, most recently from 8d8d997 to f17be9aCompareJune 4, 2020 21:50

@isaacsisaacs left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Super minor nit that could be polished to remove the extra name field in the set of objects, and one open question. But the nit really is super minor, and the open question should probably be an RFC anyway (or maybe just a separate issue/PR) since it'd be a deviation from v6 behavior.

LGTM!

Comment threadlib/outdated.js
columns[5] = type
columns[6] = homepage
}
const tree = await arb.loadActual()

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was thinking we might want this to be arb.buildIdealTree() so it finds outdated deps in the virtual tree, falling back to the actual if there's no lockfile. But I wonder if that even makes sense? The current behavior only looks at the actual tree, but it also predates the existence of lockfiles, so I'm not sure how much sense it makes to go based on that.

Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js
if (deps.length !== 0) {
// specific deps
for (let i = 0; i < deps.length; i++) {
const nodes = tree.inventory.query('name', deps[i])

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was initially a little curious as to why you had that in/out switch in getEdges, but it makes sense seeing this. This is a lot more efficient than looping over every node in the tree!

@claudiahdz
claudiahdz merged commit 05e76ef into release/v7.0.0-betaJun 5, 2020
@claudiahdz
claudiahdz deleted the feat/npm-outdated branch June 5, 2020 21:43
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Enhancementnew feature or improvementRelease 7.xwork is associated with a specific npm 7 release

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@claudiahdz@isaacs@ruyadorno@darcyclarke
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

npm outdated with arborist - #1208

Merged
claudiahdz merged 6 commits into
release/v7.0.0-betafrom
feat/npm-outdated
Jun 5, 2020
Merged

npm outdated with arborist#1208
claudiahdz merged 6 commits into
release/v7.0.0-betafrom
feat/npm-outdated

Conversation

@claudiahdz

@claudiahdzclaudiahdz commented Apr 25, 2020

Copy link
Copy Markdown
Contributor

Changes

This PR is a refactor of npm outdated with Arborist. It removes the --depth option flag and introduces a new --all one for displaying all outdated dependencies in a tree. The homepage information of a package is now taken directly from the packument instead of the package.json to avoid displaying outdated information. The location info is now the node.location (it's position on the physical tree) instead of it's position on the logical dependency tree.

A new column Depended by was also added on the default display that shows which package depends on the displayed dependency. This makes the information displayed when --all is on easier to understand.

References

http://github.com/npm/rfcs/pull/133

Examples

➜ arborist git:(master) npm outdated
Package Current Wanted Latest Location Depended by
@npmcli/run-script 1.2.1 1.3.1 1.3.1 node_modules/@npmcli/run-script arborist
minify-registry-metadata 2.1.0 2.2.0 2.2.0 node_modules/minify-registry-metadata arborist
npm-package-arg 8.0.0 8.0.1 8.0.1 node_modules/npm-package-arg arborist
pacote 11.1.0 11.1.7 11.1.7 node_modules/pacote arborist
semver 7.1.2 7.3.2 7.3.2 node_modules/semver arborist
tap 14.10.6 14.10.7 14.10.7 node_modules/tap arborist
tcompare 3.0.4 3.0.4 5.0.2 node_modules/tcompare arborist
treeverse 1.0.2 1.0.3 1.0.3 node_modules/treeverse arborist
➜ arborist git:(master) npm outdated tar
Package Current Wanted Latest Location Depended by
tar 6.0.1 6.0.2 6.0.2 node_modules/tar cacache
tar 6.0.1 6.0.2 6.0.2 node_modules/tar pacote
tar 4.4.13 6.0.2 6.0.2 node_modules/node-gyp/node_modules/tar node-gyp

@claudiahdz
claudiahdz requested a review from isaacsMay 1, 2020 22:28
@claudiahdz
claudiahdz marked this pull request as ready for review May 1, 2020 22:30
@claudiahdz
claudiahdz requested a review from a team as a code ownerMay 1, 2020 22:30

@isaacsisaacs left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

There are some ways to lean on the Edge class to do a bit more work here, and we can optimize the async fetches for packuments to go a little faster.

Areas for further improvement (perhaps outside the scope of this PR):

  • What happens with git deps? It'd be nice if we could detect things other than versions being outdated, but also git deps that are not up to date. We'd have to treat the "wanted" as the resolved value, of course, since a lot of the time, those things won't be on the registry, and the "packument" is fake, so we'd need to look at the manifest._resolved rather than manifest.version.
  • Needs to be updated to handle cases where there are multiple edges that limit what a package can be. If you have a deduped top-level dep that can be updated, with another dep depending on its current version, maybe "wanted" would be a lower version in --all mode? I'm not sure the best way to present that. Showing a separate line for each dependent is pretty noisy.

Comment threadlib/update.js
Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js
@isaacs
isaacsforce-pushed the release/v7.0.0-beta branch from cd6840b to e57a991CompareMay 8, 2020 01:14
@darcyclarkedarcyclarke added this to the OSS - Sprint 8 milestone Jun 1, 2020
@darcyclarkedarcyclarke added Enhancement new feature or improvement Release 7.x work is associated with a specific npm 7 release labels Jun 1, 2020
Comment threadlib/outdated.js
@claudiahdz
claudiahdzforce-pushed the feat/npm-outdated branch 3 times, most recently from 8d8d997 to f17be9aCompareJune 4, 2020 21:50

@isaacsisaacs left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Super minor nit that could be polished to remove the extra name field in the set of objects, and one open question. But the nit really is super minor, and the open question should probably be an RFC anyway (or maybe just a separate issue/PR) since it'd be a deviation from v6 behavior.

LGTM!

Comment threadlib/outdated.js
columns[5] = type
columns[6] = homepage
}
const tree = await arb.loadActual()

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was thinking we might want this to be arb.buildIdealTree() so it finds outdated deps in the virtual tree, falling back to the actual if there's no lockfile. But I wonder if that even makes sense? The current behavior only looks at the actual tree, but it also predates the existence of lockfiles, so I'm not sure how much sense it makes to go based on that.

Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js
if (deps.length !== 0) {
// specific deps
for (let i = 0; i < deps.length; i++) {
const nodes = tree.inventory.query('name', deps[i])

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was initially a little curious as to why you had that in/out switch in getEdges, but it makes sense seeing this. This is a lot more efficient than looping over every node in the tree!

@claudiahdz
claudiahdz merged commit 05e76ef into release/v7.0.0-betaJun 5, 2020
@claudiahdz
claudiahdz deleted the feat/npm-outdated branch June 5, 2020 21:43
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Enhancementnew feature or improvementRelease 7.xwork is associated with a specific npm 7 release

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@claudiahdz@isaacs@ruyadorno@darcyclarke
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

npm outdated with arborist - #1208

Merged
claudiahdz merged 6 commits into
release/v7.0.0-betafrom
feat/npm-outdated
Jun 5, 2020
Merged

npm outdated with arborist#1208
claudiahdz merged 6 commits into
release/v7.0.0-betafrom
feat/npm-outdated

Conversation

@claudiahdz

@claudiahdzclaudiahdz commented Apr 25, 2020

Copy link
Copy Markdown
Contributor

Changes

This PR is a refactor of npm outdated with Arborist. It removes the --depth option flag and introduces a new --all one for displaying all outdated dependencies in a tree. The homepage information of a package is now taken directly from the packument instead of the package.json to avoid displaying outdated information. The location info is now the node.location (it's position on the physical tree) instead of it's position on the logical dependency tree.

A new column Depended by was also added on the default display that shows which package depends on the displayed dependency. This makes the information displayed when --all is on easier to understand.

References

http://github.com/npm/rfcs/pull/133

Examples

➜ arborist git:(master) npm outdated
Package Current Wanted Latest Location Depended by
@npmcli/run-script 1.2.1 1.3.1 1.3.1 node_modules/@npmcli/run-script arborist
minify-registry-metadata 2.1.0 2.2.0 2.2.0 node_modules/minify-registry-metadata arborist
npm-package-arg 8.0.0 8.0.1 8.0.1 node_modules/npm-package-arg arborist
pacote 11.1.0 11.1.7 11.1.7 node_modules/pacote arborist
semver 7.1.2 7.3.2 7.3.2 node_modules/semver arborist
tap 14.10.6 14.10.7 14.10.7 node_modules/tap arborist
tcompare 3.0.4 3.0.4 5.0.2 node_modules/tcompare arborist
treeverse 1.0.2 1.0.3 1.0.3 node_modules/treeverse arborist
➜ arborist git:(master) npm outdated tar
Package Current Wanted Latest Location Depended by
tar 6.0.1 6.0.2 6.0.2 node_modules/tar cacache
tar 6.0.1 6.0.2 6.0.2 node_modules/tar pacote
tar 4.4.13 6.0.2 6.0.2 node_modules/node-gyp/node_modules/tar node-gyp

@claudiahdz
claudiahdz requested a review from isaacsMay 1, 2020 22:28
@claudiahdz
claudiahdz marked this pull request as ready for review May 1, 2020 22:30
@claudiahdz
claudiahdz requested a review from a team as a code ownerMay 1, 2020 22:30

@isaacsisaacs left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

There are some ways to lean on the Edge class to do a bit more work here, and we can optimize the async fetches for packuments to go a little faster.

Areas for further improvement (perhaps outside the scope of this PR):

  • What happens with git deps? It'd be nice if we could detect things other than versions being outdated, but also git deps that are not up to date. We'd have to treat the "wanted" as the resolved value, of course, since a lot of the time, those things won't be on the registry, and the "packument" is fake, so we'd need to look at the manifest._resolved rather than manifest.version.
  • Needs to be updated to handle cases where there are multiple edges that limit what a package can be. If you have a deduped top-level dep that can be updated, with another dep depending on its current version, maybe "wanted" would be a lower version in --all mode? I'm not sure the best way to present that. Showing a separate line for each dependent is pretty noisy.

Comment threadlib/update.js
Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js
@isaacs
isaacsforce-pushed the release/v7.0.0-beta branch from cd6840b to e57a991CompareMay 8, 2020 01:14
@darcyclarkedarcyclarke added this to the OSS - Sprint 8 milestone Jun 1, 2020
@darcyclarkedarcyclarke added Enhancement new feature or improvement Release 7.x work is associated with a specific npm 7 release labels Jun 1, 2020
Comment threadlib/outdated.js
@claudiahdz
claudiahdzforce-pushed the feat/npm-outdated branch 3 times, most recently from 8d8d997 to f17be9aCompareJune 4, 2020 21:50

@isaacsisaacs left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Super minor nit that could be polished to remove the extra name field in the set of objects, and one open question. But the nit really is super minor, and the open question should probably be an RFC anyway (or maybe just a separate issue/PR) since it'd be a deviation from v6 behavior.

LGTM!

Comment threadlib/outdated.js
columns[5] = type
columns[6] = homepage
}
const tree = await arb.loadActual()

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was thinking we might want this to be arb.buildIdealTree() so it finds outdated deps in the virtual tree, falling back to the actual if there's no lockfile. But I wonder if that even makes sense? The current behavior only looks at the actual tree, but it also predates the existence of lockfiles, so I'm not sure how much sense it makes to go based on that.

Comment threadlib/outdated.js Outdated
Comment threadlib/outdated.js
if (deps.length !== 0) {
// specific deps
for (let i = 0; i < deps.length; i++) {
const nodes = tree.inventory.query('name', deps[i])

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was initially a little curious as to why you had that in/out switch in getEdges, but it makes sense seeing this. This is a lot more efficient than looping over every node in the tree!

@claudiahdz
claudiahdz merged commit 05e76ef into release/v7.0.0-betaJun 5, 2020
@claudiahdz
claudiahdz deleted the feat/npm-outdated branch June 5, 2020 21:43
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Enhancementnew feature or improvementRelease 7.xwork is associated with a specific npm 7 release

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@claudiahdz@isaacs@ruyadorno@darcyclarke