Skip to main content

Change npm dependency

org.openrewrite.javascript.ChangeDependency

Renames an npm dependency in package.json and optionally updates its version constraint. After modifying the package.json, the lock file is regenerated by running the package manager. Not safe to use as a precondition: invokes the package manager and publishes per-project state shared with other dependency recipes.

Recipe source

GitHub: ChangeDependency.java, Issue Tracker, Code Genome Project

This recipe is available under the Moderne Source Available License. Moderne customers can download precompiled artifacts from The Code Genome Project. For non-commercial use you can build the artifact from source locally.

Options

TypeNameDescriptionExample
StringoldPackageNameThe current name of the npm package to rename.lodash
StringnewPackageNameThe new name to use for the package.lodash-es
StringnewVersionOptional. Optional new version constraint to set on the renamed package.^5.0.0
StringscopeOptional. The dependency scope: dependencies, devDependencies, etc. When omitted, all scopes are searched. Valid options: dependencies, devDependencies, peerDependencies, optionalDependencies, bundledDependenciesdependencies

Usage

This recipe has required configuration parameters. Recipes with required configuration parameters cannot be activated directly (unless you are running them via the Moderne CLI). To activate this recipe you must create a new recipe which fills in the required parameters. In your rewrite.yml create a new recipe with a unique name. For example: com.yourorg.ChangeDependencyExample. Here's how you can define and customize such a recipe within your rewrite.yml:

rewrite.yml
---
type: specs.openrewrite.org/v1beta/recipe
name: com.yourorg.ChangeDependencyExample
displayName: Change npm dependency example
recipeList:
- org.openrewrite.javascript.ChangeDependency:
oldPackageName: lodash
newPackageName: lodash-es
newVersion: ^5.0.0
scope: dependencies

This recipe has no required configuration parameters and comes from a rewrite core library. It can be activated directly without adding any dependencies.

Now that com.yourorg.ChangeDependencyExample has been defined, activate it in your build file:

OpenRewrite artifacts, including the Maven and Gradle plugins themselves, are distributed through the Code Genome Project repository (https://artifacts.codegenomeproject.org/maven), which requires authentication. Sign in to the Code Genome Project to create a download token; your build authenticates with the email or username you signed in with, plus that token as the password. See the quickstart guide for details.

  1. Put your Code Genome Project credentials in ~/.gradle/gradle.properties, so that they are not committed alongside your build:
    ~/.gradle/gradle.properties
    codeGenomeUsername=you@example.com
    codeGenomeToken=your-download-token
  2. Add the Code Genome Project repository to your settings.gradle file, so that the plugin itself can be resolved:
    settings.gradle
    pluginManagement {
    repositories {
    maven {
    url = "https://artifacts.codegenomeproject.org/maven"
    credentials {
    username = providers.gradleProperty("codeGenomeUsername").get()
    password = providers.gradleProperty("codeGenomeToken").get()
    }
    }
    // Keep the portal for any other plugins your build applies
    gradlePluginPortal()
    }
    }
  3. Add the following to your build.gradle file:
    build.gradle
    plugins {
    id("org.openrewrite.rewrite") version("latest.release")
    }

    rewrite {
    activeRecipe("com.yourorg.ChangeDependencyExample")
    setExportDatatables(true)
    }

    repositories {
    mavenCentral()
    maven {
    url = "https://artifacts.codegenomeproject.org/maven"
    credentials {
    username = providers.gradleProperty("codeGenomeUsername").get()
    password = providers.gradleProperty("codeGenomeToken").get()
    }
    }
    }
  4. Run gradle rewriteRun to run the recipe.

See how this recipe works across multiple open-source repositories

Run this recipe on OSS repos at scale with the Moderne SaaS.

The community edition of the Moderne platform enables you to easily run recipes across thousands of open-source repositories.

Please contact Moderne for more information about safely running the recipes on your own codebase in a private SaaS.

Data Tables

Node.js lock regeneration failures

org.openrewrite.javascript.table.NodeLockRegenerationFailures

Lock files that could not be regenerated after a dependency edit, and why.

Column NameDescription
Source pathThe path of the package.json whose lock could not be regenerated.
Package nameThe package that caused the failure, when attributable to one.
ReasonThe structured failure reason, e.g. REGISTRY_UNREACHABLE or RESOLUTION_REQUIRED. Absent for unstructured failures.
DetailA human-readable description of the failure.