Someone more knowledgeable than me, please correct...
# general
t
Someone more knowledgeable than me, please correct me if I'm wrong, but couldn't you create a script named
npm-audit
in your
package.json
to run your specific commands? You should be able to use the
node_run_script(entry_point="npm-audit")
BUILD file symbol in your
scripts
attribute of the
package_json
target. package.json
Copy code
{
  "name": "@my/pkg",
  "scripts": {
    "npm-audit": "npm audit --audit-level=high"
  }
}
BUILD:
Copy code
package_json(
    name="pkg",
    scripts=[
        node_run_script(entry_point="npm-audit"),
    ],
)
Then you should be able to run
pants run :pkg#npm-audit
.
b
@thankful-stone-5860 interesting idea! I don't think that would guarantee the
npm
being invoked is the
npm
that Pants/corepack installed and manages though, which is my main concern.
IIUC, that example would still just search for the npm command on the system PATH.
t
It appears to use the corepack version installed by pants and not the system version. I have
v24.14.1
installed (
npm
version
11.11.0
) but running the
version
script via
pants run :pkg#version
yields NodeJS version
v24.10.0
with
npm
version
11.6.2
. package.json:
Copy code
{
  "name": "pkg",
  "scripts": {
    "version": "node --version && npm --version"
  }
}
BUILD:
Copy code
package_json(
    name="pkg",
    scripts=[
        node_run_script(entry_point="version"),
    ],
)
pants.toml:
Copy code
[GLOBAL]
pants_version = "2.31.0"
backend_packages = [
    "pants.backend.experimental.javascript"
]

[cli.alias]
all = "::"
lock = "generate-lockfiles"

[python]
interpreter_constraints = ["CPython>=3.12"]

[nodejs]
package_manager = "npm"
🙌 2
It's also worth noting that pants respects the
packageManager
field in the
package.json
. So, if you set it to
"packageManager": "npm@11.13.0"
then it will use that version of
npm
to execute all scripts.
b
thanks @thankful-stone-5860!! I see, not that I need to know 😅... I'm assuming this works by Pants modifying the PATH on the fly so its package manager is seen first. this should work for our needs though, thank you for confirming
👍 1
➕ 1
s
thanks Casey!
👍 1