scan erros if package-lock.json is present when active_scanners: all
- Dominant language
- HTML
- Stars
- 31
- Forks
- 3
- PR merge metrics
- No merged PRs in 30d
Description
Hello salus team, thank you for this great resource!
An issue I noticed when testing on https://github.com/hMatoba/piexifjs
salus.yaml has 'active_scanners: all' only, the scan errors out (see screenshot below)
works when only NPMAudit is selected
active_scanners:
- NPMAudit

Contributor guide
Research direction
Reproduce the failure using the piexifjs repository and the salus.yaml configuration with active_scanners: all, then compare it with the NPMAudit-only configuration. Inspect the scan output or screenshot to identify which scanner fails when package-lock.json is present. Done means the all-scanners configuration completes successfully for this repository.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript
- Domain
- security
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 32/100