naugtur / npm-audit-resolver

Apache License 2.0
119 stars 28 forks source link

Suggestion - check-audit argument to ignore dev dependencies? #32

Closed stevendarby closed 3 years ago

stevendarby commented 4 years ago

What is the feasibility / likelihood of this feature? Use case: never wanting audit problems with dev dependencies to cause CI issues. Review of dev dependency issues can be done manually at regular intervals.

naugtur commented 4 years ago

It's already there. --production is passed to npm command underneath. Actually, all switches that this app doesn't consume are passed down

stevendarby commented 4 years ago

Thanks @naugtur, I'll try it out. I didn't spot any documentation for it. edit: Just got that you meant it's an npm audit feature. Thanks again.