Added
- The GitHub Action takes an
sbominput, so SPDX output is reachable from CI without dropping to a rawcve-litecall. It acceptscyclonedx,spdxandspdx2.3, case-insensitively and with surrounding whitespace trimmed, and takes precedence overcdxwhen both are set;cdxstays a permanent alias rather than a deprecated one.--outputis now forwarded whensbomis set, so the file lands in the requested directory instead of the workspace root.sbom-inventory-onlywarns when it is set with no SBOM output at all, and warns again when the resolved format is CycloneDX, where it has no effect.
Fixed
-
PD002 no longer reports Node built-in modules as undeclared dependencies, and no longer prints an install command for them. A tree can carry
eventsandstring_decodertransitively, as browser shims arriving through common stream and archive packages, so the names genuinely are present without a declaration. But Node resolves a bareeventsimport to the core module whatever sits innode_modules, so the code never loads the npm copy and installing it changes nothing. -
OA005 reads a
pkg@rangeoverride key as a version selector rather than a literal name. npm accepts"minimatch@3"and treats the part after the@as a range, so a resolved3.1.2satisfies it. The rule now asks whether any resolved version satisfies the selector, sominimatch@3is silent whileminimatch@99still reports and says what is actually wrong. Versions come from the lockfile, so the check works on a scan with nonode_modules. OA005 also withholds its flattening suggestion from a selector-keyed override, since a selector scopes a pin to one copy and flattening would widen it to every copy. -
report.jsoncarrieslockfileSourceagain. The HTML report renders the lockfile filename from the report data, but the embedded payload lost the field when the--jsonand report shapes were unified, so the page showed more than the artefact beside it. -
The
.gitignorerule for local-only maintainer notes matched by exact name, so a backup beside one was not ignored. The patterns now cover backups and.localvariants.
Validation
- npm test
- npm run build