Skip to content

release: v1.16.0#351

Merged
sonukapoor merged 1 commit into
mainfrom
release/v1.16.0
May 13, 2026
Merged

release: v1.16.0#351
sonukapoor merged 1 commit into
mainfrom
release/v1.16.0

Conversation

@sonukapoor
Copy link
Copy Markdown
Collaborator

Added

  • --cdx writes a CycloneDX 1.4 JSON SBOM containing all lockfile packages as components, with CVE findings attached as vulnerabilities
  • GitHub Action gains a cdx input
  • Self-scan CI workflow uploads SARIF to GitHub Code Scanning

Fixed

  • --sarif and --cdx now suppress terminal table output, matching --json behaviour

Changed

  • Output file writing extracted into write-outputs.ts dispatcher

Validation

  • npm test
  • npm run build

@sonukapoor sonukapoor merged commit 3c6ef41 into main May 13, 2026
6 checks passed
@sonukapoor sonukapoor deleted the release/v1.16.0 branch May 13, 2026 09:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant