<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Monde kim</title>
    <description>The latest articles on DEV Community by Monde kim (@rad1092).</description>
    <link>https://dev.to/rad1092</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3881867%2Fe2e02ace-0f34-4232-92a6-ac34ccc77f67.png</url>
      <title>DEV Community: Monde kim</title>
      <link>https://dev.to/rad1092</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/rad1092"/>
    <language>en</language>
    <item>
      <title>Launching gh-dep-risk: a GitHub CLI extension for npm dependency PR review</title>
      <dc:creator>Monde kim</dc:creator>
      <pubDate>Thu, 16 Apr 2026 07:31:32 +0000</pubDate>
      <link>https://dev.to/rad1092/gh-dep-risk-a-github-cli-extension-for-npm-pr-dependency-risk-review-410j</link>
      <guid>https://dev.to/rad1092/gh-dep-risk-a-github-cli-extension-for-npm-pr-dependency-risk-review-410j</guid>
      <description>&lt;h1&gt;
  
  
  Launching gh-dep-risk
&lt;/h1&gt;

&lt;p&gt;I built &lt;code&gt;gh-dep-risk&lt;/code&gt; to make npm dependency pull request review faster.&lt;/p&gt;

&lt;p&gt;It is a precompiled GitHub CLI extension that summarizes dependency risk on demand, so the workflow stays inside &lt;code&gt;gh&lt;/code&gt; instead of requiring a server, webhook receiver, database, queue, or dashboard.&lt;/p&gt;

&lt;h2&gt;
  
  
  What it does
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;summarizes npm dependency changes in a PR&lt;/li&gt;
&lt;li&gt;renders human, JSON, and markdown output&lt;/li&gt;
&lt;li&gt;can upsert a single PR timeline marker comment with &lt;code&gt;--comment&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;supports &lt;code&gt;--fail-level&lt;/code&gt; for CI and workflow gating&lt;/li&gt;
&lt;li&gt;supports monorepo and workspace target selection with &lt;code&gt;--path&lt;/code&gt; and &lt;code&gt;--list-targets&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;supports a manual GitHub Actions workflow for no-local-install runs&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Why this shape
&lt;/h2&gt;

&lt;p&gt;I wanted something reviewers can run only when they need it, with existing GitHub auth and without more infrastructure to operate.&lt;/p&gt;

&lt;h2&gt;
  
  
  Install
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;gh extension &lt;span class="nb"&gt;install &lt;/span&gt;rad1092/gh-dep-risk
gh dep-risk version
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  Example
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;gh dep-risk &lt;span class="nb"&gt;pr &lt;/span&gt;123
gh dep-risk &lt;span class="nb"&gt;pr &lt;/span&gt;123 &lt;span class="nt"&gt;--format&lt;/span&gt; json
gh dep-risk &lt;span class="nb"&gt;pr &lt;/span&gt;123 &lt;span class="nt"&gt;--comment&lt;/span&gt;
gh dep-risk &lt;span class="nb"&gt;pr &lt;/span&gt;123 &lt;span class="nt"&gt;--fail-level&lt;/span&gt; high
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  Scope
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;npm-only&lt;/li&gt;
&lt;li&gt;supports &lt;code&gt;package.json&lt;/code&gt; and &lt;code&gt;package-lock.json&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;one Go binary&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Links
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;GitHub repo: &lt;a href="https://github.com/rad1092/gh-dep-risk" rel="noopener noreferrer"&gt;https://github.com/rad1092/gh-dep-risk&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Latest release: &lt;a href="https://github.com/rad1092/gh-dep-risk/releases/latest" rel="noopener noreferrer"&gt;https://github.com/rad1092/gh-dep-risk/releases/latest&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Launch discussion: &lt;a href="https://github.com/rad1092/gh-dep-risk/discussions/1" rel="noopener noreferrer"&gt;https://github.com/rad1092/gh-dep-risk/discussions/1&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The current public release is &lt;code&gt;v0.1.5&lt;/code&gt;. It includes the MIT license, release-ready docs, install smoke coverage, and real PR validation.&lt;/p&gt;

&lt;p&gt;Feedback, issues, and edge cases are welcome.&lt;/p&gt;

</description>
      <category>github</category>
      <category>cli</category>
      <category>security</category>
      <category>npm</category>
    </item>
  </channel>
</rss>
