ossillate-inc / packj

Packj stops :zap: Solarwinds-, ESLint-, and PyTorch-like attacks by flagging malicious/vulnerable open-source dependencies ("weak links") in your software supply-chain
https://packj.dev
GNU Affero General Public License v3.0
647 stars 36 forks source link

Support for maven/Java #83

Open so87 opened 1 year ago

so87 commented 1 year ago

Many enterprises use java and maven. I think adding support for that would make this tool more popular.

so87 commented 1 year ago

After looking more at the code it looks like it support maven and serveral others but when i run i get an error pypi = 'pypi' npmjs = 'npmjs' rubygems = 'rubygems' maven = 'maven' jcenter = 'jcenter' jitpack = 'jitpack' nuget = 'nuget' packagist = 'packagist' dockerhub = 'dockerhub' rust = 'cargo' php = 'packagist'

ashishbijlani commented 11 months ago

What error do you get? Please provide more details on how you're running it and on what system. Thanks!

ODB686 commented 9 months ago

docker run -v /tmp:/tmp/packj -it ossillate/packj:latest audit --trace -p maven:swagger-annotations Failed to parse input "maven:swagger-annotations:" Package manager maven is not supported. Ignoring

aydinnyunus commented 7 months ago

Failed to parse input "maven:spray-http:" Package manager maven is not supported. Ignoring

How maven is supported which is mentioned in Readme