sandworm-hq / sandworm-audit

Security & License Compliance For Your App's Dependencies 🪱
https://sandworm.dev
MIT License
471 stars 5 forks source link

Audit hangs on retrieving vulnerabilities for pnpm workspace #130

Closed gabidobo closed 1 year ago

gabidobo commented 1 year ago

I tried to run it on my production project, but sandworm just stuck on Getting vulnerability report from pnpm stage for some reason 🤔

image

Originally posted by @acherkashin in https://github.com/sandworm-hq/sandworm-audit/discussions/101#discussioncomment-6819820

gabidobo commented 1 year ago

@acherkashin weird behaviour 🤔

Could you please also try running pnpm audit --json in the same directory, see if that also hangs or errors out?

gabidobo commented 1 year ago

I was able to replicate this with pnpm 8.7.4 - looks connected to this pnpm issue.

acherkashin commented 1 year ago

Sorry for the late reply.

pnpm audit --json works well and doesn't print any errors

My pnpm version is 7.17.1

github-actions[bot] commented 1 year ago

This issue is stale because it has been open for 30 days with no activity.

github-actions[bot] commented 1 year ago

This issue was closed because it has been inactive for 14 days since being marked as stale.