[6.0.0]
Breaking changes
- Requires Node.js 20.19+ or 22.12+ (previously 18+).
--proxy(and thehttp_proxyenvironment variable) now only supportshttp://andhttps://proxy URLs. SOCKS (socks://,socks5://, ...) and PAC (pac+http://, ...) proxies are no longer supported and fail with anUnsupported proxy protocolerror.
Improvements
- Replaced the
proxy-agentdependency (and its 27 transitive packages) with a small built-in proxy client. Proxy credentials in the URL (http://user:pass@host:port) are still supported. - Removed the
ansi-colorsdependency.
Bugfixes
--includeOsvlookups ignored--proxy,--insecureand--cacert. They now use the same settings as the repository download.--includeOsvlooked up advisories under the repository's display name instead of the npm package name, so most components that declare annpmnamesilently got no OSV results (#626).--includeOsvfindings could be missing from the report, because the report was closed before the OSV lookups finished (#623).- Invalid CLI input (an unknown
--severity, an unreadable--cacertor ignore file) now stops before scanning with an error message instead of a stack trace (#623). - Malformed repository files and malformed OSV responses are reported with their source, instead of crashing the scan (#623).
- Errors while scanning files or
bower.jsonare now reported, and the scan exits with code 1 (#623). bower.jsonfiles were not detected on Windows paths (#623).- Distinct CVEs that share an issue were merged into one finding, while repeated advisories for the same vulnerability were not deduplicated (#623).
- The upper bound of a license version range was treated as inclusive (#623).
- CycloneDX output could change the scan results used by other reporters, and duplicate components are now merged together with their vulnerabilities and evidence (#625).