safedep / vet

Tool to achieve policy driven vetting of open source dependencies
https://safedep.io
Apache License 2.0
235 stars 22 forks source link

Support PHP Composer as a Lockfile Format #257

Open abhisek opened 1 month ago

abhisek commented 1 month ago

vet currently does not support scanning PHP projects. We can start by supporting composer.json based projects.

Example repository to test against: https://github.com/mollie/mollie-api-php