Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Scan and report dependency groups of vulnerabilities for Yarn #799

Open
Ais8Ooz8 opened this issue Feb 13, 2024 · 4 comments
Open

Scan and report dependency groups of vulnerabilities for Yarn #799

Ais8Ooz8 opened this issue Feb 13, 2024 · 4 comments
Labels
backlog Important but currently unprioritized enhancement New feature or request

Comments

@Ais8Ooz8
Copy link

Need the same mechanism #655 using dependencies and devDependencies from package.json

@cuixq cuixq self-assigned this Feb 14, 2024
@cuixq cuixq added the enhancement New feature or request label Feb 14, 2024
@cuixq
Copy link
Contributor

cuixq commented Feb 14, 2024

@Ais8Ooz8 thank you for your feedback!

For Yarn, devDependencies are specified in pacakge.json and osv-scanner currently scans yarn.lock for vulnerabilities. We can report dependency groups for Yarn once we support scanning package.json.

@Ais8Ooz8
Copy link
Author

Up

@cuixq
Copy link
Contributor

cuixq commented Jun 3, 2024

Related issue to support manifest scanning: #416

@cuixq cuixq removed their assignment Jun 3, 2024
Copy link

github-actions bot commented Aug 2, 2024

This issue has not had any activity for 60 days and will be automatically closed in two weeks

@github-actions github-actions bot added the stale The issue or PR is stale and pending automated closure label Aug 2, 2024
@oliverchang oliverchang added backlog Important but currently unprioritized and removed stale The issue or PR is stale and pending automated closure labels Aug 2, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
backlog Important but currently unprioritized enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

3 participants