CycloneDX/cyclonedx-node-yarn

feat: detail runtime dependencies

Open

#448 opened on Dec 7, 2025

 (2 comments) (0 reactions) (0 assignees)JavaScript (10 forks)auto 404
enhancementhacktoberfesthelp wanted

Repository metrics

Stars
 (27 stars)
PR merge metrics
 (PR metrics pending)

Description

Is your feature request related to a problem? Please describe.

i am detailing my runtime tonode via package.json::engines - see https://docs.npmjs.com/cli/v11/configuring-npm/package-json#engines

{
  "engines": {
    "node": ">=0.10.3 <15"
  }
}

I want this information being detailed in the SBOM generated by this very tool.

Describe the solution you'd like

the sourced information may stem from package manifest (package.json) or from lockfile or from npm-ls

Describe alternatives you've considered

none

Additional context

docs:

Contribution

  • I am willing to provide an implementation
  • I will wait until somebody else implements it

Contributor guide