jfrog / jfrog-cli-core

Apache License 2.0
33 stars 58 forks source link

jfrog audit scan command fails while finding existing packages #1107

Open jashan05 opened 7 months ago

jashan05 commented 7 months ago

Hello Team,

We are using jfrog audit scan using cli. It fails while running scan for a package which is a dependency of a dependency and is available in Artifactory. It seems it is not able to find that package. Could you please guide me on this.

Details:

16:53:38 [Info] Running SCA scan for yarn vulnerable dependencies in /azp/_work/1/s/CheckedOutSource directory...
16:53:38 [Info] Calculating Yarn dependencies...
16:53:39 [Warn] An error occurred while collecting dependencies info:
{"type":"warning","data":"Lockfile has incorrect entry for \"axios@^0.26.1\". Ignoring it."}
{"type":"error","data":"Couldn't find package \"axios@^0.26.1\" required by \"@nn-sls/core@^2.2.2\" on the \"npm\" registry."}

16:53:39 [Warn] An error was thrown while collecting dependencies info: exit status 1
Command output:
{"type":"info","data":"Visit https://yarnpkg.com/en/docs/cli/list for documentation about this command."}

Package in our Artifactory:

image

EyalDelarea commented 4 months ago

Hey @jashan05 ,

Could you please share some additional details that will help us investigate the issue?