thankful-stone-5860
04/27/2026, 7:56 PMnpm-audit in your package.json to run your specific commands? You should be able to use the node_run_script(entry_point="npm-audit")
BUILD file symbol in your scripts attribute of the package_json target.
package.json
{
"name": "@my/pkg",
"scripts": {
"npm-audit": "npm audit --audit-level=high"
}
}
BUILD:
package_json(
name="pkg",
scripts=[
node_run_script(entry_point="npm-audit"),
],
)
Then you should be able to run pants run :pkg#npm-audit.bright-orange-25107
04/27/2026, 11:00 PMnpm being invoked is the npm that Pants/corepack installed and manages though, which is my main concern.bright-orange-25107
04/27/2026, 11:01 PMthankful-stone-5860
04/28/2026, 4:04 PMv24.14.1 installed (npm version 11.11.0) but running the version script via pants run :pkg#version yields NodeJS version v24.10.0 with npm version 11.6.2.
package.json:
{
"name": "pkg",
"scripts": {
"version": "node --version && npm --version"
}
}
BUILD:
package_json(
name="pkg",
scripts=[
node_run_script(entry_point="version"),
],
)
pants.toml:
[GLOBAL]
pants_version = "2.31.0"
backend_packages = [
"pants.backend.experimental.javascript"
]
[cli.alias]
all = "::"
lock = "generate-lockfiles"
[python]
interpreter_constraints = ["CPython>=3.12"]
[nodejs]
package_manager = "npm"thankful-stone-5860
04/28/2026, 4:10 PMpackageManager field in the package.json. So, if you set it to "packageManager": "npm@11.13.0" then it will use that version of npm to execute all scripts.bright-orange-25107
04/28/2026, 4:28 PMsalmon-autumn-7981
04/28/2026, 5:05 PM