79585120

Date: 2025-04-21 18:36:01
Score: 4
Natty:
Report link

Do you have an openly available example repository to reproduce this on? In my experience, syft works well with package.json (not sure if I tried it with package.lock). However, note that syft by default does not include development dependencies. That was one pitfall I encountered. There is a configuration variable for toggling that behaviour, if you need it.

Reasons:
  • RegEx Blacklisted phrase (2.5): Do you have an
  • No code block (0.5):
  • Contains question mark (0.5):
  • Low reputation (0.5):
Posted by: The Comamba