Open prabhu opened 3 months ago
pnpm outdated
┌───────────────┬─────────┬────────┐
│ Package │ Current │ Latest │
├───────────────┼─────────┼────────┤
│ packageurl-js │ 1.0.2 │ 2.0.0 │
├───────────────┼─────────┼────────┤
│ tar │ 6.2.1 │ 7.4.3 │
└───────────────┴─────────┴────────┘
Only packageurl-js is left.
Current list looks like this.
The issue is the need for testing after updating. For example, to update babel we need a sample list of javascript and typescript repos and run cdxgen with
--profile research
, then compare the occurrence and callstack evidence. May be there is an opportunity to enhance the custom-json-diff tool to handle evidence attributes?For tar, we need to test with a range of oci images (both container and tar versions). Note that v7 is so different (and buggy) that even the maintainer hasn't made them the default yet.
packageurl-js had a number of breaking changes and was failing for container images when I tried it the last time.
Not sure about ajv and cheerio.