Skip to content

Conversation

DmitriyLewen
Copy link
Contributor

@DmitriyLewen DmitriyLewen commented Mar 3, 2023

Description

yarn.lock files don't have information about dev dependencies.
This PR parses package.json alongside yarn.lock and remove dev dependencies.

Related issues

Related PRs

Checklist

  • I've read the guidelines for contributing to this repository.
  • I've followed the conventions in the PR title.
  • I've added tests that prove my fix is effective or that my feature works.
  • I've updated the documentation with the relevant information (if needed).
  • I've added usage information (if the PR introduces new options)
  • I've included a "before" and "after" example to the description (if the PR is a user interface change).

@knqyf263 knqyf263 marked this pull request as ready for review March 21, 2023 14:14
@knqyf263 knqyf263 merged commit 6445309 into aquasecurity:main Mar 21, 2023
@DmitriyLewen DmitriyLewen deleted the feat/remove-dev-dep-yarn branch March 22, 2023 03:13
atombrella pushed a commit to atombrella/trivy that referenced this pull request Mar 25, 2023
AnaisUrlichs pushed a commit to AnaisUrlichs/trivy that referenced this pull request Mar 27, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Trivy detecting vulnerabilities in yarn devDependencies
2 participants