Skip to main content

Add npm dependency

org.openrewrite.javascript.AddDependency

Add an npm dependency to package.json and regenerate the lock file by running the package manager. If the dependency already exists in any scope, the recipe is a no-op. Not safe to use as a precondition: invokes the package manager and publishes per-project state shared with other dependency recipes.

Recipe source

GitHub: AddDependency.java, Issue Tracker, Code Genome Project

This recipe is available under the Moderne Source Available License. Moderne customers can download precompiled artifacts from The Code Genome Project. For non-commercial use you can build the artifact from source locally.

Options

TypeNameDescriptionExample
StringpackageNameThe name of the npm package to add (e.g., lodash, @types/node).lodash
StringversionThe version constraint to set (e.g., ^5.0.0, ~2.1.0, 3.0.0).^5.0.0
StringscopeOptional. The dependency scope: dependencies, devDependencies, peerDependencies, or optionalDependencies. Defaults to dependencies. Valid options: dependencies, devDependencies, peerDependencies, optionalDependenciesdependencies

Used by

This recipe is used as part of the following composite recipes:

Usage

This recipe has required configuration parameters. Recipes with required configuration parameters cannot be activated directly (unless you are running them via the Moderne CLI). To activate this recipe you must create a new recipe which fills in the required parameters. In your rewrite.yml create a new recipe with a unique name. For example: com.yourorg.AddDependencyExample. Here's how you can define and customize such a recipe within your rewrite.yml:

rewrite.yml
---
type: specs.openrewrite.org/v1beta/recipe
name: com.yourorg.AddDependencyExample
displayName: Add npm dependency example
recipeList:
- org.openrewrite.javascript.AddDependency:
packageName: lodash
version: ^5.0.0
scope: dependencies

This recipe has no required configuration parameters and comes from a rewrite core library. It can be activated directly without adding any dependencies.

Now that com.yourorg.AddDependencyExample has been defined, activate it in your build file:

OpenRewrite artifacts, including the Maven and Gradle plugins themselves, are distributed through the Code Genome Project repository (https://artifacts.codegenomeproject.org/maven), which requires authentication. Sign in to the Code Genome Project to create a download token; your build authenticates with the email or username you signed in with, plus that token as the password. See the quickstart guide for details.

  1. Put your Code Genome Project credentials in ~/.gradle/gradle.properties, so that they are not committed alongside your build:
    ~/.gradle/gradle.properties
    codeGenomeUsername=you@example.com
    codeGenomeToken=your-download-token
  2. Add the Code Genome Project repository to your settings.gradle file, so that the plugin itself can be resolved:
    settings.gradle
    pluginManagement {
    repositories {
    maven {
    url = "https://artifacts.codegenomeproject.org/maven"
    credentials {
    username = providers.gradleProperty("codeGenomeUsername").get()
    password = providers.gradleProperty("codeGenomeToken").get()
    }
    }
    // Keep the portal for any other plugins your build applies
    gradlePluginPortal()
    }
    }
  3. Add the following to your build.gradle file:
    build.gradle
    plugins {
    id("org.openrewrite.rewrite") version("latest.release")
    }

    rewrite {
    activeRecipe("com.yourorg.AddDependencyExample")
    setExportDatatables(true)
    }

    repositories {
    mavenCentral()
    maven {
    url = "https://artifacts.codegenomeproject.org/maven"
    credentials {
    username = providers.gradleProperty("codeGenomeUsername").get()
    password = providers.gradleProperty("codeGenomeToken").get()
    }
    }
    }
  4. Run gradle rewriteRun to run the recipe.

See how this recipe works across multiple open-source repositories

Run this recipe on OSS repos at scale with the Moderne SaaS.

The community edition of the Moderne platform enables you to easily run recipes across thousands of open-source repositories.

Please contact Moderne for more information about safely running the recipes on your own codebase in a private SaaS.

Data Tables

Node.js lock regeneration failures

org.openrewrite.javascript.table.NodeLockRegenerationFailures

Lock files that could not be regenerated after a dependency edit, and why.

Column NameDescription
Source pathThe path of the package.json whose lock could not be regenerated.
Package nameThe package that caused the failure, when attributable to one.
ReasonThe structured failure reason, e.g. REGISTRY_UNREACHABLE or RESOLUTION_REQUIRED. Absent for unstructured failures.
DetailA human-readable description of the failure.