{"id":26623860,"url":"https://github.com/vanioinformatika/docker-publish","last_synced_at":"2026-04-27T16:32:39.815Z","repository":{"id":17414411,"uuid":"81929756","full_name":"vanioinformatika/docker-publish","owner":"vanioinformatika","description":"Zero-Configuration Docker Publishing from npm","archived":false,"fork":false,"pushed_at":"2022-12-30T18:48:07.000Z","size":224,"stargazers_count":1,"open_issues_count":10,"forks_count":0,"subscribers_count":6,"default_branch":"master","last_synced_at":"2025-10-09T17:09:19.473Z","etag":null,"topics":["docker","nodejs","npm","npm-script"],"latest_commit_sha":null,"homepage":null,"language":"JavaScript","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/vanioinformatika.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2017-02-14T09:42:47.000Z","updated_at":"2019-10-31T09:37:07.000Z","dependencies_parsed_at":"2023-01-11T20:26:34.068Z","dependency_job_id":null,"html_url":"https://github.com/vanioinformatika/docker-publish","commit_stats":null,"previous_names":[],"tags_count":14,"template":false,"template_full_name":null,"purl":"pkg:github/vanioinformatika/docker-publish","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vanioinformatika%2Fdocker-publish","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vanioinformatika%2Fdocker-publish/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vanioinformatika%2Fdocker-publish/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vanioinformatika%2Fdocker-publish/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/vanioinformatika","download_url":"https://codeload.github.com/vanioinformatika/docker-publish/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vanioinformatika%2Fdocker-publish/sbom","scorecard":{"id":916001,"data":{"date":"2025-08-18","repo":{"name":"github.com/vanioinformatika/docker-publish","commit":"e030dd1d60716654f823feaf8c5baac95945cffe"},"scorecard":{"version":"v5.2.1-41-g40576783","commit":"40576783fda6698350fcbbeaea760ff827433034"},"score":1.7,"checks":[{"name":"Dangerous-Workflow","score":-1,"reason":"no workflows found","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/40576783fda6698350fcbbeaea760ff827433034/docs/checks.md#dangerous-workflow"}},{"name":"Code-Review","score":0,"reason":"Found 0/30 approved changesets -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/40576783fda6698350fcbbeaea760ff827433034/docs/checks.md#code-review"}},{"name":"Token-Permissions","score":-1,"reason":"No tokens found","details":null,"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/40576783fda6698350fcbbeaea760ff827433034/docs/checks.md#token-permissions"}},{"name":"Pinned-Dependencies","score":-1,"reason":"no dependencies found","details":null,"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/40576783fda6698350fcbbeaea760ff827433034/docs/checks.md#pinned-dependencies"}},{"name":"SAST","score":0,"reason":"no SAST tool detected","details":["Warn: no pull requests merged into dev branch"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/40576783fda6698350fcbbeaea760ff827433034/docs/checks.md#sast"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/40576783fda6698350fcbbeaea760ff827433034/docs/checks.md#packaging"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/40576783fda6698350fcbbeaea760ff827433034/docs/checks.md#binary-artifacts"}},{"name":"Maintained","score":0,"reason":"0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/40576783fda6698350fcbbeaea760ff827433034/docs/checks.md#maintained"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/40576783fda6698350fcbbeaea760ff827433034/docs/checks.md#cii-best-practices"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/40576783fda6698350fcbbeaea760ff827433034/docs/checks.md#security-policy"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/40576783fda6698350fcbbeaea760ff827433034/docs/checks.md#fuzzing"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: MIT License: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/40576783fda6698350fcbbeaea760ff827433034/docs/checks.md#license"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/40576783fda6698350fcbbeaea760ff827433034/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":0,"reason":"branch protection not enabled on development/release branches","details":["Warn: branch protection not enabled for branch 'master'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/40576783fda6698350fcbbeaea760ff827433034/docs/checks.md#branch-protection"}},{"name":"Vulnerabilities","score":0,"reason":"24 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GHSA-6chw-6frg-f759","Warn: Project is vulnerable to: GHSA-v88g-cgmw-v5xw","Warn: Project is vulnerable to: GHSA-93q8-gq69-wqmw","Warn: Project is vulnerable to: GHSA-v6h2-p8h4-qcjw","Warn: Project is vulnerable to: GHSA-3xgq-45jj-v275","Warn: Project is vulnerable to: GHSA-gxpj-cx7g-858c","Warn: Project is vulnerable to: GHSA-2j2x-2gpw-g8fm","Warn: Project is vulnerable to: GHSA-4q6p-r6v2-jvc5","Warn: Project is vulnerable to: GHSA-ww39-953v-wcq6","Warn: Project is vulnerable to: GHSA-43f8-2h32-f4cj","Warn: Project is vulnerable to: GHSA-p6mc-m468-83gw","Warn: Project is vulnerable to: GHSA-29mw-wpgm-hmr9","Warn: Project is vulnerable to: GHSA-35jh-r3h4-6jhm","Warn: Project is vulnerable to: GHSA-f8q6-p94x-37v3","Warn: Project is vulnerable to: GHSA-vh95-rmgr-6w4m","Warn: Project is vulnerable to: GHSA-xvch-5gv4-984h","Warn: Project is vulnerable to: GHSA-hj48-42vr-x3v9","Warn: Project is vulnerable to: GHSA-g6ww-v8xp-vmwg","Warn: Project is vulnerable to: GHSA-c2qf-rxjj-qqgw","Warn: Project is vulnerable to: GHSA-4rq4-32rv-6wp6","Warn: Project is vulnerable to: GHSA-64g7-mvw6-v9qj","Warn: Project is vulnerable to: GHSA-52f5-9888-hmc6","Warn: Project is vulnerable to: GHSA-c4w7-xm78-47vh","Warn: Project is vulnerable to: GHSA-p9pc-299p-vxgp"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/40576783fda6698350fcbbeaea760ff827433034/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-24T21:00:33.046Z","repository_id":17414411,"created_at":"2025-08-24T21:00:33.046Z","updated_at":"2025-08-24T21:00:33.046Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":32345802,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-04-26T23:26:28.701Z","status":"online","status_checked_at":"2026-04-27T02:00:06.769Z","response_time":128,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["docker","nodejs","npm","npm-script"],"created_at":"2025-03-24T10:19:23.727Z","updated_at":"2026-04-27T16:32:39.791Z","avatar_url":"https://github.com/vanioinformatika.png","language":"JavaScript","funding_links":[],"categories":[],"sub_categories":[],"readme":"\u003ch1 align=\"left\"\u003e\n  Docker Publish\n  \u003cbr\u003e\n  \u003cbr\u003e\n\u003c/h1\u003e\n\n\u003cp align=\"left\"\u003e\n  \u003ca href=\"https://travis-ci.org/vanioinformatika/docker-publish\"\u003e\u003cimg src=\"https://travis-ci.org/vanioinformatika/docker-publish.svg?branch=master\" alt=\"Travis\"\u003e\u003c/a\u003e\n  \u003ca href=\"http://standardjs.com\"\u003e\u003cimg src=\"https://img.shields.io/badge/code_style-standard-brightgreen.svg\" alt=\"Standard - JavaScript Style Guide\"\u003e\u003c/a\u003e\n  \u003ca href=\"https://www.npmjs.com/package/@vanioinformatika/docker-publish\"\u003e\u003cimg src=\"https://img.shields.io/npm/dm/@vanioinformatika/docker-publish.svg\" alt=\"npm downloads\"\u003e\u003c/a\u003e\n\u003c/p\u003e\n\n\u003ch4 align=\"left\"\u003eSimple Docker tagging and publishing with 'npm version'\u003c/h4\u003e\n\n\u003cbr\u003e\n\n## Prerequisite\n\nDo not forget **installing docker** and running **docker login** before using it!\n\nInstall:\n\n```\nnpm i -D @vanioinformatika/docker-publish\n```\n\n## Best practice\n\n**Using npm run postversion:** building image, creating docker tags and push into Docker Registry with one command.\n\nIn package.json set _postversion:_\n\n```\n\"preversion\": \"docker -v \u0026\u0026 git push \u0026\u0026 npm install \u0026\u0026 npm test\",\n\"version\": \"\",\n\"postversion\": \"git push \u0026\u0026 git push --tags \u0026\u0026 docker build -t $npm_package_config_docker_ns/$npm_package_name:latest . \u0026\u0026 docker-publish\"\n```\n\nor with hands:\n\n```\ndocker build -t namespace/appname:latest .\nnode ./node_modules/.bin/docker-publish\n```\n\n## Configuration\n\nThere is **zero configuration.** All parameters comes from package.json: *$npm_package_name* and *$npm_package_version* variable (name and version properties).\n\n_* Maybe you want to use your own private docker repository, in this case please see the next chapter._\n\n### Customization\n\nOptionally, in package.json you can customize your docker properties:\n\n```json\n\"version\": \"1.3.5\",\n\"name\": \"docker-publish\",\n\"config\": {\n  \"docker\": {\n    \"ns\": \"namespace\",\n    \"url\": \"docker.yourcompany.com:5000\",\n    \"name\": \"myapp\",\n    \"skip\": false,\n    \"silence\": false,\n    \"strictSemver\": false\n  }\n}\n```\n\nCLI parameters could overwites package.json properties (except version number).\n\n- **DOCKER_NS:** your namespace for image; _namespace/imagename:tag_ Default: empty\n\n- **DOCKER_URL:** your private docker repository URL; _docker.yourcompany.com:5000_\n\n- **DOCKER_NAME:** overwrite image name. Default: package.json _name_ properties\n\n- **DOCKER_SKIP:** Skip Docker tag and push commands (dry run with logging). Default: false\n\n- **DOCKER_SILENCE:** Do not logging. Default: false\n\n- **DOCKER_STRICT_SEMVER:** Strict semantic versioning tag. Default: false. If it is true, then only one tag will be created on docker image as https://semver.org defined and there is no 'v' before version number.\n\n## Releasing\n\n**Best practice:** _postversion_ contains **image building** and **docker-publish,** and running **npm version**\n\nOutput:\n\n```\ndocker tag docker-publish:latest docker-publish:v1\ndocker tag docker-publish:latest docker-publish:v1.3\ndocker tag docker-publish:latest docker-publish:v1.3.5\ndocker tag docker-publish:latest docker-publish:v1.3.5-RELEASE-g993df1b\ndocker tag docker-publish:latest docker-publish:latest\ndocker push docker-publish:v1\ndocker push docker-publish:v1.3\ndocker push docker-publish:v1.3.5\ndocker push docker-publish:v1.3.5-RELEASE-g993df1b\ndocker push docker-publish:latest\n```\n\n*v1.3.5-RELEASE-g993df1b:* v1.3.5 - your version number from project.json, g993df1b - git commit ID (7 chars)\n\nIf DOCKER_STRICT_SEMVER, strictSemver is *true,* then:\n\n```\ndocker tag docker-publish:latest docker-publish:1.3.5\ndocker push docker-publish:1.3.5\n```\n\n## Snapshot\n\nIf you want to publish a _snapshot_, the image will be tagged with git commit id, and the commit's number since last version, and pushed. If DOCKER_STRICT_SEMVER, strictSemver is *true,* then snapshot is not available.\n\nOutput:\n```\n\ndocker tag docker-publish:latest docker-publish:v1.3.4-5-gb4c008b\ndocker push docker-publish:v1.3.4-1-gb4c008b\n\n```\n\n*v1.3.5-RELEASE-g993df1b:* v1.3.5 - your version number from project.json, 5 - commit's number since v1.3.4 tag, gb4c008b - last (fifth) git commit ID (7 chars\n\nIf you have never tagged git commit, then tag shows:\n\n```\nskipped: docker tag docker-publish:latest docker-publish:0bd4c74\nskipped: docker push docker-publish:0bd4c74\n```\n\nWhere _0bd4c74_ is the last commit id.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fvanioinformatika%2Fdocker-publish","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fvanioinformatika%2Fdocker-publish","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fvanioinformatika%2Fdocker-publish/lists"}