Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

update from @CycloneDX/cyclonedx-node-yarn project #1632

Closed
jkowalleck opened this issue Jul 15, 2024 · 2 comments
Closed

update from @CycloneDX/cyclonedx-node-yarn project #1632

jkowalleck opened this issue Jul 15, 2024 · 2 comments
Labels
question Any question about leshan

Comments

@jkowalleck
Copy link

Question

see

// Generate SBOM for yarn with trivy
// Ideally we would like to use a specific integrated tools like : https://github.com/CycloneDX/cyclonedx-node-yarn
// But project is not really active and is searching for contributor : https://github.com/CycloneDX/cyclonedx-node-yarn/issues/12

Just wanted to let you know, that the @CycloneDX/cyclonedx-node-yarn project was backed, and is actively maintained for a while, now.
Please let us know if you find any issues :D

@jkowalleck jkowalleck added the question Any question about leshan label Jul 15, 2024
@sbernard31
Copy link
Contributor

@jkowalleck thx for letting me know that 🙏

I decided to test it some weeks ago but I was stopped quickly because cyclonedx-node-yarn does not support yarn 1.x. ( >v3 is required). I understand that you maybe don't want to target a so old version of yarn. (so I didn't provide you any feedback about that)

On our side, this is maybe not so easy to migrate from yarn classic (v1) to modern yarn (v3 or v4) : #1550

@sbernard31
Copy link
Contributor

As we already have an issue (#1550) to track that, so I think we can close this.
For completeness I added a comment to that issue : #1550 (comment)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
question Any question about leshan
Projects
None yet
Development

No branches or pull requests

2 participants