coinbase / coinbase/salus

scan erros if package-lock.json is present when active_scanners: all

Open
#599 1 comment 1 reaction 0 assignees View on GitHub
Dominant language
HTML
Stars
31
Forks
3
PR merge metrics
No merged PRs in 30d

Description

Hello salus team, thank you for this great resource!

An issue I noticed when testing on https://github.com/hMatoba/piexifjs

salus.yaml has 'active_scanners: all' only, the scan errors out (see screenshot below)

works when only NPMAudit is selected
active_scanners:
- NPMAudit

![image](https://user-images.githubusercontent.com/38509779/167179256-87e9f4c9-4861-4603-8da3-93143f08add3.png)

Contributor guide

Open the contributing guide

Research direction

Reproduce the failure using the piexifjs repository and the salus.yaml configuration with active_scanners: all, then compare it with the NPMAudit-only configuration. Inspect the scan output or screenshot to identify which scanner fails when package-lock.json is present. Done means the all-scanners configuration completes successfully for this repository.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript
Domain
security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
32/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.