github OWASP/cve-lite-cli v1.39.0
v1.39.0 - SPDX from the Action, and two rules that were giving wrong advice

5 hours ago

Added

  • The GitHub Action takes an sbom input, so SPDX output is reachable from CI without dropping to a raw cve-lite call. It accepts cyclonedx, spdx and spdx2.3, case-insensitively and with surrounding whitespace trimmed, and takes precedence over cdx when both are set; cdx stays a permanent alias rather than a deprecated one. --output is now forwarded when sbom is set, so the file lands in the requested directory instead of the workspace root. sbom-inventory-only warns when it is set with no SBOM output at all, and warns again when the resolved format is CycloneDX, where it has no effect.

Fixed

  • PD002 no longer reports Node built-in modules as undeclared dependencies, and no longer prints an install command for them. A tree can carry events and string_decoder transitively, as browser shims arriving through common stream and archive packages, so the names genuinely are present without a declaration. But Node resolves a bare events import to the core module whatever sits in node_modules, so the code never loads the npm copy and installing it changes nothing.

  • OA005 reads a pkg@range override key as a version selector rather than a literal name. npm accepts "minimatch@3" and treats the part after the @ as a range, so a resolved 3.1.2 satisfies it. The rule now asks whether any resolved version satisfies the selector, so minimatch@3 is silent while minimatch@99 still reports and says what is actually wrong. Versions come from the lockfile, so the check works on a scan with no node_modules. OA005 also withholds its flattening suggestion from a selector-keyed override, since a selector scopes a pin to one copy and flattening would widen it to every copy.

  • report.json carries lockfileSource again. The HTML report renders the lockfile filename from the report data, but the embedded payload lost the field when the --json and report shapes were unified, so the page showed more than the artefact beside it.

  • The .gitignore rule for local-only maintainer notes matched by exact name, so a backup beside one was not ignored. The patterns now cover backups and .local variants.

Validation

  • npm test
  • npm run build

Contributors

Don't miss a new cve-lite-cli release

NewReleases is sending notifications on new releases.