CycloneDX/cyclonedx-node-yarn

feat: Support external manifests

开放

#246 创建于 2025年1月11日

 (3 条评论) (0 个反应) (0 位负责人)JavaScript (10 个派生)auto 404
enhancementhacktoberfesthelp wanted

仓库指标

星标
 (27 个星标)
PR 合并指标
 (PR 指标待抓取)

描述

Is your feature request related to a problem? Please describe.

As part of the Cyber Resilience Act we are required to add SBOM to all of your projects. Me make extensive use of CI pipelines for analysis and deployments. For every repository we need to add and maintain cyclonedx-node-yarn as additional dev-dependency.

Describe the solution you'd like

Similar to cyclonedx-node-npm we would like cyclonedx-node-yarn to support external manifests:

cyclonedx-yarn [options] [--] [<package-manifest>]

This would enable this project to be used as a Docker container, which can easily added to every CI pipeline and maintained centrally, instead of per-project.

Additionally, in mono-repositories the dependency would have to be added to every single sub-project currently.

Describe alternatives you've considered

Wrapping up the current version into a Docker container, which does not help, as it only works on the current project.

贡献者指南