Thanks to visit codestin.com
Credit goes to Github.com

Skip to content

Exclude development or test dependencies for PNPM Package type #4430

@Ajit-15

Description

@Ajit-15

What would you like to be added:
We have file - pnpm-lock.yaml which is having all required and dev dependencies. Syft is giving SBOM which has all dependencies including required and dev dependencies without scope defined. Can we exclude dev and test dependencies and get only the actual one?

Why is this needed:
To have clean and required dependencies for direct and transitive SBOM.

Additional context:

Example : Purl for PNPM = "pkg:npm/[email protected]"

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    Status

    Ready

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions