Skip to content

chore(sbom-tools): add tests, readme and clean up COMPASS-6851#70

Merged
mcasimir merged 8 commits intomainfrom
support-monorepo-artifacts
May 22, 2023
Merged

chore(sbom-tools): add tests, readme and clean up COMPASS-6851#70
mcasimir merged 8 commits intomainfrom
support-monorepo-artifacts

Conversation

@mcasimir
Copy link
Copy Markdown
Collaborator

@mcasimir mcasimir commented May 22, 2023

Implements COMPASS-6851 cause non 3rd party modules are now never reported

@mcasimir mcasimir changed the title Support monorepo artifacts chore(sbom-tools): Add tests, readme and clean up May 22, 2023
@mcasimir mcasimir changed the title chore(sbom-tools): Add tests, readme and clean up chore(sbom-tools): Add tests, readme and clean up COMPASS-6851 May 22, 2023
@addaleax addaleax changed the title chore(sbom-tools): Add tests, readme and clean up COMPASS-6851 chore(sbom-tools): add tests, readme and clean up COMPASS-6851 May 22, 2023
Copy link
Copy Markdown
Collaborator

@addaleax addaleax left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

(All comments completely optional!)

Comment thread packages/sbom-tools/test/helpers.ts Outdated
Comment thread packages/sbom-tools/test/helpers.ts Outdated
Comment thread packages/sbom-tools/src/webpack-dependencies-plugin.spec.ts Outdated
Comment thread packages/sbom-tools/src/webpack-dependencies-plugin.spec.ts Outdated
@mcasimir mcasimir merged commit 787637e into main May 22, 2023
@mcasimir mcasimir deleted the support-monorepo-artifacts branch May 22, 2023 14:17
github-actions Bot added a commit that referenced this pull request Apr 29, 2026
…-v6h2-p8h4-qcjw

Add npm overrides to force safe versions of transitive brace-expansion:
- brace-expansion@1 → 1.1.13 (was 1.1.11)
- brace-expansion@2 → 2.0.3 (was 2.0.1/2.0.2)
- brace-expansion@5 → 5.0.5 (was 5.0.2)

Fixes Dependabot alerts #198, #188, #187, #70, #69
CVE-2026-33750 (GHSA-f886-m6hf-6m8v), CVE-2025-5889 (GHSA-v6h2-p8h4-qcjw)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants