BBVA / deeptracy

The Security Dependency Orchestrator Service
88 stars 10 forks source link

Suggestion for capturing more deps #62

Open pombredanne opened 6 years ago

pombredanne commented 6 years ago

Hi there! Excellent tool! I am the maintainer of https://github.com/nexB/scancode-toolkit .... and it does parse a few package manifests including capturing direct (or full locked) deps. You may want to check it out, this is in Python.

Check also https://github.com/heremaps/oss-review-toolkit that has a similar approach to yours to capture deps using package managers as you do, but is in kotlin.

cr0hn commented 6 years ago

Thanks! We'll consider to the one of next milestones