sonatype-nexus-community / auditjs

Audits an NPM package.json file to identify known vulnerabilities.
https://www.npmjs.com/package/auditjs
Apache License 2.0
224 stars 53 forks source link

auditjs-4-0-33 submits lodash dev-dependency to nexus iq #249

Open FelixWernerSTR opened 2 years ago

FelixWernerSTR commented 2 years ago

with this package.json configuration below. Auditjs in version 4.0.33 submits lodash dev-dependency to nexus iq server. But should not. node_modules/auditjs/bin/index.js iq -a AGDB-UI -s build -h http://nxiq.pr.sv.loc -u xxxxx -p xxxxx

See also Screenshots please.

"dependencies": { "axios": "0.21.4", "base64toblob": "0.0.2", "bootstrap": "4.6.0", "bootstrap-vue": "2.20.1", "core-js": "3.9.1", "date-and-time": "0.14.2", "deep-object-diff": "1.1.0", "eslint-plugin-import": "2.22.1", "file-saver": "2.0.5", "js-base64": "3.6.0", "liquor-tree": "0.2.70", "qs": "6.9.6", "sync-pom-version-to-package": "1.6.1", "vee-validate": "3.4.5", "vue": "2.6.12", "vue-multiselect": "2.1.6", "vue-router": "3.5.1", "vue-the-mask": "0.11.1", "vuex": "3.6.2" }, "devDependencies": { "@vue/cli-plugin-babel": "4.5.11", "@vue/cli-plugin-eslint": "4.5.11", "@vue/cli-plugin-router": "4.5.11", "@vue/cli-plugin-unit-jest": "4.5.11", "@vue/cli-plugin-vuex": "4.5.11", "@vue/cli-service": "4.5.11", "@vue/eslint-config-prettier": "6.0.0", "@vue/test-utils": "1.1.3", "babel-eslint": "10.1.0", "eslint": "6.8.0", "eslint-plugin-prettier": "3.3.1", "eslint-plugin-vue": "6.2.2", "less": "3.13.1", "less-loader": "7.3.0", "prettier": "2.2.1", "vue-template-compiler": "2.6.12"

npm-ls-lodash nexus-iq }

FelixWernerSTR commented 2 years ago

Notable Info. If i move "eslint-plugin-import": "2.22.1" to devDependencies, the problem seems to be solved.