Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Audit should provide info if it affects dev dependency or production #67

Open
florianbader opened this issue Jan 28, 2022 · 3 comments
Open
Labels
help wanted Extra attention is needed

Comments

@florianbader
Copy link

florianbader commented Jan 28, 2022

Really like the package. The only thing that kind of bothers me that running the audit doesn't show you if it affects a dev dependency or a production dependency. When running the audit it would be great to have a separate column that indicates if the found vulnerability only affects a dev dependency or also a production dependency.
This makes it easier to decide if it should be excluded e.g. high severity on dev dependency is probably not as problematic as on production dependencies.

@jeemok jeemok added the help wanted Extra attention is needed label Feb 3, 2022
@bencivjan
Copy link

@jeemok Hey! Is help still needed on this issue?

@jeemok
Copy link
Owner

jeemok commented Apr 12, 2022

hey @bencivjan, yes please! :)

@dchahuan
Copy link

dchahuan commented May 12, 2022

@jeemok Hey would you like this to be added as a column or a another table?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
help wanted Extra attention is needed
Projects
None yet
Development

No branches or pull requests

4 participants