Skip to content

Ignore indirect npm package #6876

Closed Answered by knqyf263
amiceli asked this question in Q&A
Jun 7, 2024 · 1 comments · 1 reply
Discussion options

You must be logged in to vote

There is a way to ignore indirect dependency or use pacjage.json instead of package-lock.json with trivy ?

There is no way to do that. We might want to add a flag --relationship so Trivy can show direct dependencies with --relationship direct.

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@amiceli
Comment options

Answer selected by amiceli
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
triage/support Indicates an issue that is a support question.
2 participants