opensbom-generator / parsers

Language and ecosystem parsers
Apache License 2.0
6 stars 10 forks source link

npm quality assessment #7

Open puerco opened 1 year ago

puerco commented 1 year ago

Assess the parser to ensure the data looks as expected

Related issues: https://github.com/opensbom-generator/parsers/issues/20

nishakm commented 1 year ago

Different lock files info: No version provided: an "ancient" shrinkwrap file from a version of npm prior to npm v5. 1: The lockfile version used by npm v5 and v6. 2: The lockfile version used by npm v7, which is backwards compatible to v1 lockfiles. 3: The lockfile version used by npm v7, without backwards compatibility affordances. This is used for the hidden lockfile at node_modules/.package-lock.json, and will likely be used in a future version of npm, once support for npm v6 is no longer relevant.