Open kazigk opened 3 years ago
Please see the release notes. I would highly recommend using:
dependency-check.sh --disableNodeJS -s . -o .
The NodeJS analyzer will be re-worked soon and will be used to only scan the vendors directory if it exists.
In this case the actual bug is that an archive was found that contained a package.json
, dependency-check tries to extract it to a temporary directory for scanning and the warning is thrown because the node_modules directory (if it exists) is not also extracted.
Describe the bug DependencyCheck is looking for files outside of scan directory when bcrypt is one of the npm packages.
Version of dependency-check used
Dependency-Check Core version 6.0.3
Log file
To Reproduce