CycloneDX / CycloneDX/cyclonedx-node-yarn

feat: Support external manifests

Open
#246 3 comments 0 reactions 0 assignees View on GitHub
enhancement hacktoberfest help wanted
Dominant language
JavaScript
Stars
26
Forks
11
Avg merge
17m
Merged PRs (30d)
1

Description

## Is your feature request related to a problem? Please describe.

As part of the Cyber Resilience Act we are required to add SBOM to all of your projects. Me make extensive use of CI pipelines for analysis and deployments. For every repository we need to add and maintain `cyclonedx-node-yarn` as additional dev-dependency.

## Describe the solution you'd like

Similar to `cyclonedx-node-npm` we would like `cyclonedx-node-yarn` to support external manifests:
```bash
cyclonedx-yarn [options] [--] []
```

This would enable this project to be used as a Docker container, which can easily added to every CI pipeline and maintained centrally, instead of per-project.

Additionally, in mono-repositories the dependency would have to be added to every single sub-project currently.

## Describe alternatives you've considered

Wrapping up the current version into a Docker container, which does not help, as it only works on the current project.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.