naugtur / npm-audit-resolver

Apache License 2.0
119 stars 28 forks source link

Feature request: indicate if it's a dev dependency #73

Open stevendarby opened 1 year ago

stevendarby commented 1 year ago

Include whether a vulnerability stems from dependencies or devDependencies. I believe this used to be a feature in previous versions. If possible, please consider adding it back, as it would greatly help us decide on the resolution.

e.g.

vulnerable versions <0.5.0 found in:
 - devDependencies: @angular-devkit/build-angular>protractor>selenium-webdriver>xml2js