Schedule icon
Webhook icon
Commands icon
Docker icon
If icon
SlackIncomingWebhook icon
Log icon

Weekly npm Outdated Major-Bump Digest

Weekly npm outdated audit that highlights major-version dependency risk and posts a digest to Slack.

Categories
CloudInfrastructureinfrastructure

Dependabot sends a PR per package; nobody reads sixty of them. A weekly digest of what actually has a major bump pending is the signal you can act on. This blueprint clones your repo, runs npm outdated in a throwaway Node container, splits the results into major versus minor/patch drift, and posts the majors to Slack.

How it works

  1. npm_outdated (io.kestra.plugin.scripts.shell.Commands on Docker) clones the repo, runs npm outdated --json in the subdirectory, and emits total, majors, and the first 10 major-bump details via the ::{"outputs": ...}:: protocol.
  2. check_majors (io.kestra.plugin.core.flow.If) branches: majors pending → post_digest lists the count and total to Slack; otherwise log_fresh records the green week.
  3. The errors block alerts Slack when the clone or npm call fails.
  4. Triggers: weekly Schedule (disabled by default) plus a Webhook for post-merge checks.

What you get

  • One weekly message that separates breaking-risk upgrades from routine drift.
  • A dependency freshness trend in your execution history.
  • A dependency_summary JSON output for dashboards.

Who it's for

  • Frontend teams drowning in Dependabot PRs.
  • Maintainers who only want to hear about majors.
  • Platform teams policing monorepo sub-packages.

Why orchestrate this with Kestra

npm outdated prints a table nobody reads. The flow turns it into a weekly, branched, alerted digest — and the next step (open a tracking issue, pin a Dependabot schedule, gate releases) is one task away.

Prerequisites

  • A reachable git URL for your repo.
  • A Slack webhook.

Secrets

  • SLACK_WEBHOOK_URL: webhook for the digest and failure alerts.

Quick start

  1. Add the Slack webhook secret.
  2. Set repo_url and subdirectory (e.g. ui).
  3. Run once and read dependency_summary.
  4. Enable weekly_digest.

How to extend

  • Add npm audit --json parsing for vulnerability counts.
  • Fan out over multiple subdirectories with a ForEach.
  • Store dependency_summary in KV and alert only on growth.

Links

See How

New to Kestra?

Use blueprints to kickstart your first workflows.