sonatype-nexus-community / DevAudit

Open-source, cross-platform, multi-purpose security auditing tool
BSD 3-Clause "New" or "Revised" License
360 stars 74 forks source link

Added Ability to parse NPM files and Visual studio Solution files #135

Closed gmeks closed 4 years ago

gmeks commented 4 years ago

Hey,

Not sure if this is helpfull or wanted, but i thought i should offer it up. If some or all of this is something that would be of interest, il gladly help improve or do adjustments.

Added: Ability to parse Visual Studio .sln files Added: Ability to parse NPM package.json Added: Ability to Export to Html Added: When reading bower files, if version is listed as "latest" i local file, it then check what version the local file is.

Currently its not very polished and the html export is esp ugly.

sonatypecla[bot] commented 4 years ago

Thanks for the contribution! Unfortunately we can't verify if the committer(s), Erling K. Sæterdal erling.saterdal@evry.com, signed the CLA because they have not associated their commits with their GitHub user. Please follow these instructions to associate your commits with your GitHub user. Then sign the Sonatype Contributor License Agreement and this Pull Request will be revalidated.

ken-duck commented 4 years ago

This is awesome.

As you may have noticed, things have been kind of been in limbo here for a while. There has been some churn on the team. A lot of focus has been going on in the back end, and unfortunately some of the clients have fallen behind. We are working on getting a team up and running to take over development here, but it is taking some time (lots of moving parts). Meanwhile I am going to hopefully catch things up a bit,

Thanks for sending in this PR. I am going to push a 3.4.0.0 version up, and then work on rolling in your changes and get a newer version pushed.

Thanks for being awesome!