Skip to content

Guardrails

nodejs ​

4 guardrails, all at version v1.

GuardrailDefault severityWhat it checks
nodejs/lockfile-committedwarningThe project commits a lock file, so an install of the same commit resolves the same versions.
nodejs/package-manager-pinnedwarningThe manifest names the package manager and the exact version Corepack should install.
nodejs/single-package-managerwarningThe project commits at most one lock file, so two package managers don't both try to manage the dependency tree.
nodejs/version-declaredwarningThe project declares the Node.js version it is built and run against, and that version is no older than the configured floor.

Shared inputs ​

Every nodejs guardrail declares these inputs. Individual guardrails can add their own.

InputDescriptionDefault
projectDirDirectory holding the project, relative to the directory the CLI runs in..

Shared collectors ​

Every nodejs guardrail receives the facts these collectors gather. Individual guardrails can ask for more collectors of their own.

CollectorGathers
nodejsThe Node.js project in the project directory: its manifest, the Node version and package manager it asks for, every workspace it declares, the dependencies each manifest names and which of them are pinned, and the lock files committed beside them.

You configure every guardrail in this category the same way, in the guardrails.checks array of buildnote.json. Configuring guardrails lists every option, and Guardrails lets you search the whole library.

Buildnote Limited
Registered in England and Wales, Reg: 16140412