{"id":33229339,"url":"https://github.com/googlearchive/polyup","last_synced_at":"2025-11-21T11:01:21.581Z","repository":{"id":57327217,"uuid":"37877227","full_name":"googlearchive/polyup","owner":"googlearchive","description":"A helpful assistant for migrating from Polymer v0.5 to 1.0. Does many of the boring mechanical parts for you.","archived":true,"fork":false,"pushed_at":"2016-04-28T01:42:36.000Z","size":7424,"stargazers_count":38,"open_issues_count":20,"forks_count":9,"subscribers_count":30,"default_branch":"master","last_synced_at":"2025-09-26T06:39:47.109Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"http://polymerlabs.github.io/polyup/","language":"JavaScript","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"bsd-3-clause","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/googlearchive.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2015-06-22T19:51:48.000Z","updated_at":"2023-01-28T20:59:52.000Z","dependencies_parsed_at":"2022-09-13T19:22:03.393Z","dependency_job_id":null,"html_url":"https://github.com/googlearchive/polyup","commit_stats":null,"previous_names":["polymerlabs/polyup"],"tags_count":11,"template":false,"template_full_name":null,"purl":"pkg:github/googlearchive/polyup","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/googlearchive%2Fpolyup","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/googlearchive%2Fpolyup/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/googlearchive%2Fpolyup/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/googlearchive%2Fpolyup/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/googlearchive","download_url":"https://codeload.github.com/googlearchive/polyup/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/googlearchive%2Fpolyup/sbom","scorecard":{"id":111370,"data":{"date":"2025-08-11","repo":{"name":"github.com/googlearchive/polyup","commit":"f324adedc5bb1dfcb9942059771c6177d3e6d9a6"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":3.2,"checks":[{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Dangerous-Workflow","score":-1,"reason":"no workflows found","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Token-Permissions","score":-1,"reason":"No tokens found","details":null,"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Code-Review","score":1,"reason":"Found 4/26 approved changesets -- score normalized to 1","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"Maintained","score":0,"reason":"project is archived","details":["Warn: Repository is archived."],"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Pinned-Dependencies","score":-1,"reason":"no dependencies found","details":null,"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Vulnerabilities","score":10,"reason":"0 existing vulnerabilities detected","details":null,"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: BSD 3-Clause \"New\" or \"Revised\" License: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":0,"reason":"branch protection not enabled on development/release branches","details":["Warn: branch protection not enabled for branch 'master'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 15 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}}]},"last_synced_at":"2025-08-15T12:19:03.603Z","repository_id":57327217,"created_at":"2025-08-15T12:19:03.603Z","updated_at":"2025-08-15T12:19:03.603Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":285603340,"owners_count":27200013,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","status":"online","status_checked_at":"2025-11-21T02:00:06.175Z","response_time":61,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2025-11-16T17:00:36.411Z","updated_at":"2025-11-21T11:01:21.574Z","avatar_url":"https://github.com/googlearchive.png","language":"JavaScript","funding_links":[],"categories":["Tools"],"sub_categories":[],"readme":"# polyup\n\n### Automates the boring parts of migrating your code from Polymer 0.5 to 1.0.\n\n[![Build Status](https://travis-ci.org/PolymerLabs/polyup.svg?branch=master)](https://travis-ci.org/PolymerLabs/polyup)\n\nThe change from Polymer 0.5 to 1.0 is a large one, as we\ntransitioned from exploratory beta releases to a stable production-ready\nproduct.\n\n`polyup` will parse your HTML and any Javascript in either inline or external scripts and perform a number of automatic transformations to your code.\n\nFor most projects `polyup` won't be able to do everything necessary to upgrade,\nbut its goal is to make it way easier.\n\nTry it out in [the interactive demo](http://polymerlabs.github.io/polyup/).\n\n## Installation\n\n`polyup` is available on npm. We recommend installing `polyup` globally.\n\n    npm install -g polyup\n\nThis will install `polyup` to the bin directory configured when node was\ninstalled. (e.g. `/usr/local/bin/polyup`).  You may need `sudo`\nfor this step.\n\n## Usage\n\nThe command\n\n    polyup photo-lightbox.html\n\nwill parse and transform photo-lightbox and any linked Javascript that `polyup`\ncan find and then print the transformed code back out onto the command line.\n\nIf that looks good, then you can run `polyup` with the `--overwrite` option to\noverwrite your code on disk with the upgraded version. Make sure that you've\ngot your code checked into source control first, as this will in effect delete\nthe v0.5 version of your code!\n\n## Manual Changes\n\npolyup does a lot of stuff! But it doesn't do everything. See the [After Use Guide](AfterUseGuide.md) for common changes that you'll need to make by hand.\n\n## Reporting Bugs\n\n`polyup` is still in early and active development. Since so many people are looking at migrating to 1.0 right now we thought that it was better to get what\nwe have now out there now, even if it won't be right for everyone.\n\nPlease file bugs as you see them! See [CONTRIBUTING.md](CONTRIBUTING.md) for more info.\n\n## Transformations\n\n### HTML\n- [x] `\u003cpolymer-element name='my-elem'\u003e` -\u003e `\u003cdom-module id='my-elem'\u003e`\n- [x] Moves direct `\u003cscript\u003e` children of `\u003cpolymer-element\u003e` elements into\n      siblings.\n- [x] Migrates `\u003cstyle\u003e` children from an element's `\u003ctemplate\u003e` into a direct\n      child of the `\u003cdom-module\u003e`\n- [x] Migrates the `attributes=` attribute off `\u003cpolymer-element\u003e` and into\n      the `properties` block of the corresponding `Polymer({...})` call.\n- [x] Generates a script and `Polymer()` call elements with a `noscript`\n      attribute.\n- [x] Migrates the `extends` attribute on `\u003cpolymer-element\u003e`.\n- [x] Warns on extending a custom element.\n- [x] Does not process extra `\u003ctemplate\u003e` tags.\n- [x] Transforms `\u003ctemplate if='{{x}}'\u003e` into\n      `\u003ctemplate is=\"dom-if\" if=\"{{x}}\"\u003e`\n- [x] Upgrades `\u003ctemplate repeat\u003e`\n  - [x] Transforms `\u003ctemplate repeat='{{x in xs}}'\u003e` into\n        `\u003ctemplate is='dom-repeat' items='{{xs}}' as='{{x}}'\u003e`\n  - [x] Transforms `\u003ctemplate repeat='{{x, i in xs}}'\u003e` into\n        `\u003ctemplate is='dom-repeat' items='{{xs}}' as='{{x}}' index-as='{{i}}'\u003e`\n- [ ] Upgrades/warns on `\u003ctemplate bind\u003e`\n  - [ ] Handles `\u003ctemplate bind='{{x}}'\u003e`\n  - [ ] Handles `\u003ctemplate bind='{{x as y}}'\u003e`\n- [x] Upgrades `\u003ctemplate is='auto-binding'\u003e`\n  - [x] Adds a warning for expressions that are too complex for\n        `\u003ctemplate is='dom-bind'\u003e`\n- [x] Upgrades all template data binding expressions.\n  - [x] Doesn't touch expressions made up only of identifiers, property\n        accesses, or expressions that are just a function call with arguments\n        made of identifiers and property accesses.\n  - [x] Wraps an expression in a \u003cspan\u003e if it is not the only child of an\n        element.\n  - [x] Transforms an attribute made up of a mix of static string and\n        expressions into an anonymous computed property.\n  - [x] Transforms more complicated expressions anywhere into anonymous\n        computed properties.\n  - [x] Handles expressions with filters like {{x | f}}\n  - [x] Upgrades one time bindings [[]] to their best equivilent.\n  - [x] For binding to attributes which are not properties like `class` we need\n        to use `x$=\"{{foo}}\"` to bind to the HTML attribute.\n  - [x] Upgrades boolean bindings like `hidden?=\"{{foo}}\"`\n  - [x] Handles bidirectional binding to common attributes of build-in elements\n    - [x] `\u003cinput value\u003e`\n    - [x] `\u003ctextarea value\u003e`\n    - [x] `\u003cselect value\u003e`\n  - [x] Removes curly braces from on-* event handler attributes.\n  - [x] Upgrades expressions using `tokenList`\n- [x] `webcomponents(.min)?.js` -\u003e `webcomponents_lite(.min)?.js`\n- [ ] Upgrades official elements from 0.5 to 1.0 mode.\n  - [x] Upgrades imports to the new element names and paths.\n  - [x] Upgrades references in HTML.\n  - [x] Upgrades attributes to their new names, where changed.\n  - [ ] Warns on use of removed attributes.\n  - [ ] Warns on use or import of elements that do not yet have a polymer\n        version.\n  - [ ] Adds additional imports when necessary.\n  - [ ] Warns on other major breaking changes to elements.\n  - [x] Upgrades official mixins from 0.5 into behaviors of 1.0.\n  - [ ] Renames methods, e.g.\n        `this.$.ajax.go()` -\u003e `this.$.ajax.generateRequest()`\n- [x] Converts calls of Polymer.mixin and Polymer.mixin2 into behavior\n      declarations.\n- [ ] Detects and upgrades user-defined mixins.\n\n### Javascript\n- [x] Infers element name from the context in which a script was loaded.\n- [x] Constructs a `properties` block from information inferred from many\n      sources.\n  - [x] Properties declared in the `publish` block are migrated, with the\n        `notify` attribute set.\n  - [x] Infers a property and its default value from properties directly\n        on the `Polymer({})` declaration\n  - [x] Infers type from default value, where present.\n  - [x] Converts mutable default values like arrays and objects into\n        functions returning that default value.\n  - [x] Discover implicit observers from functions declared with the name\n        `xChanged` where `x` is a previously discovered property.\n  - [x] Migrate explicitly declared observers from an `observe` block.\n    - [ ] Get the arguments right here when there are multiple properties\n          observed by one function. -- needs a test to be sure we're doing this\n          right.\n  - [x] Migrate computed properties from a `computed` block, including\n        moving the body of an expression into a new function on the\n        declaration.\n- [x] Migrate the body of the domReady function into the ready function,\n      creating one if needed.\n- [ ] Rename common methods on all Polymer elements\n  - [x] job -\u003e debounce\n  - [x] resolvePath -\u003e resolveUrl\n  - [ ] Need to generate a complete list of remaining renames.\n- [ ] Mostly preserves comments, but there are a number of places where\n      they're lost currently.\n- [ ] Rename Polymer.import -\u003e Polymer.Base.importHref\n- [ ] Replace `addEventListener('polymer-ready', ...)` with\n      `addEventListener('WebComponentsReady', ...)`\n- [ ] Warns on usage of the removed trackstart and trackend events.\n- [x] Updates `elem.domMethod` to `Polymer.dom(elem).domMethod`\n  - [x] appendChild, insertBefore removeChild, childNodes, parentNode,\n        firstChild, lastChild, firstElementChild, lastElementChild,\n        previousSibling, nextSibling, textContent, innerHTML, querySelector,\n        querySelectorAll, getDistributedNodes, getDestinationInsertionPoints,\n        setAttribute, removeAttribute, classList\n\n### CSS\n- [x] Detect layout attributes in HTML and add them back in to the element's\n      `\u003cstyle\u003e`.\n- [x] Fix `\u003clink rel='stylesheet' href='...'\u003e`\n\n### Other\n- [ ] Upgrades bower.json\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fgooglearchive%2Fpolyup","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fgooglearchive%2Fpolyup","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fgooglearchive%2Fpolyup/lists"}