/
snap
/
node
/
11691
/
lib
/
node_modules
/
npm
/
lib
/
commands
/
/snap/node/11691/lib/node_modules/npm/lib/commands
mkdir
upload
Name
Size
Mode
Actions
access.js
6189
0644
edit
dl
rm
adduser.js
1321
0644
edit
dl
rm
audit.js
3221
0644
edit
dl
rm
bugs.js
847
0644
edit
dl
rm
cache.js
7292
0644
edit
dl
rm
ci.js
4325
0644
edit
dl
rm
completion.js
9116
0644
edit
dl
rm
config.js
11444
0644
edit
dl
rm
dedupe.js
1443
0644
edit
dl
rm
deprecate.js
2182
0644
edit
dl
rm
diff.js
8191
0644
edit
dl
rm
dist-tag.js
5654
0644
edit
dl
rm
docs.js
449
0644
edit
dl
rm
doctor.js
10347
0644
edit
dl
rm
edit.js
1804
0644
edit
dl
rm
exec.js
3500
0644
edit
dl
rm
explain.js
3661
0644
edit
dl
rm
explore.js
2211
0644
edit
dl
rm
find-dupes.js
634
0644
edit
dl
rm
fund.js
6610
0644
edit
dl
rm
get.js
577
0644
edit
dl
rm
help-search.js
5650
0644
edit
dl
rm
help.js
3752
0644
edit
dl
rm
hook.js
3453
0644
edit
dl
rm
init.js
7018
0644
edit
dl
rm
install-ci-test.js
373
0644
edit
dl
rm
install-test.js
370
0644
edit
dl
rm
install.js
5277
0644
edit
dl
rm
link.js
5381
0644
edit
dl
rm
ll.js
234
0644
edit
dl
rm
login.js
1318
0644
edit
dl
rm
logout.js
1453
0644
edit
dl
rm
ls.js
18629
0644
edit
dl
rm
org.js
4121
0644
edit
dl
rm
outdated.js
7880
0644
edit
dl
rm
owner.js
5988
0644
edit
dl
rm
pack.js
2665
0644
edit
dl
rm
ping.js
873
0644
edit
dl
rm
pkg.js
3641
0644
edit
dl
rm
prefix.js
335
0644
edit
dl
rm
profile.js
10819
0644
edit
dl
rm
prune.js
799
0644
edit
dl
rm
publish.js
7552
0644
edit
dl
rm
query.js
3595
0644
edit
dl
rm
rebuild.js
2241
0644
edit
dl
rm
repo.js
1278
0644
edit
dl
rm
restart.js
310
0644
edit
dl
rm
root.js
295
0644
edit
dl
rm
run-script.js
6221
0644
edit
dl
rm
sbom.js
4616
0644
edit
dl
rm
search.js
1877
0644
edit
dl
rm
set.js
671
0644
edit
dl
rm
shrinkwrap.js
2712
0644
edit
dl
rm
star.js
1911
0644
edit
dl
rm
stars.js
1052
0644
edit
dl
rm
start.js
300
0644
edit
dl
rm
stop.js
295
0644
edit
dl
rm
team.js
4461
0644
edit
dl
rm
test.js
295
0644
edit
dl
rm
token.js
6160
0644
edit
dl
rm
uninstall.js
1561
0644
edit
dl
rm
unpublish.js
5394
0644
edit
dl
rm
unstar.js
183
0644
edit
dl
rm
update.js
1765
0644
edit
dl
rm
version.js
3628
0644
edit
dl
rm
view.js
13106
0644
edit
dl
rm
whoami.js
527
0644
edit
dl
rm
Edit:
/snap/node/11691/lib/node_modules/npm/lib/commands/sbom.js
(4616B)
const localeCompare = require('@isaacs/string-locale-compare')('en') const BaseCommand = require('../base-cmd.js') const { log, output } = require('proc-log') const { cyclonedxOutput } = require('../utils/sbom-cyclonedx.js') const { spdxOutput } = require('../utils/sbom-spdx.js') const SBOM_FORMATS = ['cyclonedx', 'spdx'] class SBOM extends BaseCommand { #response = {} // response is the sbom response static description = 'Generate a Software Bill of Materials (SBOM)' static name = 'sbom' static workspaces = true static params = [ 'omit', 'package-lock-only', 'sbom-format', 'sbom-type', 'workspace', 'workspaces', ] async exec () { const sbomFormat = this.npm.config.get('sbom-format') const packageLockOnly = this.npm.config.get('package-lock-only') if (!sbomFormat) { /* eslint-disable-next-line max-len */ throw this.usageError(`Must specify --sbom-format flag with one of: ${SBOM_FORMATS.join(', ')}.`) } const opts = { ...this.npm.flatOptions, path: this.npm.prefix, forceActual: true, } const Arborist = require('@npmcli/arborist') const arb = new Arborist(opts) const tree = packageLockOnly ? await arb.loadVirtual(opts).catch(() => { /* eslint-disable-next-line max-len */ throw this.usageError('A package lock or shrinkwrap file is required in package-lock-only mode') }) : await arb.loadActual(opts) // Collect the list of selected workspaces in the project const wsNodes = this.workspaceNames?.length ? arb.workspaceNodes(tree, this.workspaceNames) : null // Build the selector and query the tree for the list of nodes const selector = this.#buildSelector({ wsNodes }) log.info('sbom', `Using dependency selector: ${selector}`) const items = await tree.querySelectorAll(selector) const errors = items.flatMap(node => detectErrors(node)) if (errors.length) { throw Object.assign(new Error([...new Set(errors)].join('\n')), { code: 'ESBOMPROBLEMS', }) } // Populate the response with the list of unique nodes (sorted by location) this.#buildResponse(items.sort((a, b) => localeCompare(a.location, b.location))) // TODO(BREAKING_CHANGE): all sbom output is in json mode but setting it before // any of the errors will cause those to be thrown in json mode. this.npm.config.set('json', true) output.buffer(this.#response) } async execWorkspaces (args) { await this.setWorkspaces() return this.exec(args) } // Build the selector from all of the specified filter options #buildSelector ({ wsNodes }) { let selector const omit = this.npm.flatOptions.omit const workspacesEnabled = this.npm.flatOptions.workspacesEnabled // If omit is specified, omit all nodes and their children which match the // specified selectors const omits = omit.reduce((acc, o) => `${acc}:not(.${o})`, '') if (!workspacesEnabled) { // If workspaces are disabled, omit all workspace nodes and their children selector = `:root > :not(.workspace)${omits},:root > :not(.workspace) *${omits},:extraneous` } else if (wsNodes && wsNodes.length > 0) { // If one or more workspaces are selected, select only those workspaces and their children selector = wsNodes.map(ws => `#${ws.name},#${ws.name} *${omits}`).join(',') } else { selector = `:root *${omits},:extraneous` } // Always include the root node return `:root,${selector}` } // builds a normalized inventory #buildResponse (items) { const sbomFormat = this.npm.config.get('sbom-format') const packageType = this.npm.config.get('sbom-type') const packageLockOnly = this.npm.config.get('package-lock-only') this.#response = sbomFormat === 'cyclonedx' ? cyclonedxOutput({ npm: this.npm, nodes: items, packageType, packageLockOnly }) : spdxOutput({ npm: this.npm, nodes: items, packageType }) } } const detectErrors = (node) => { const errors = [] // Look for missing dependencies (that are NOT optional), or invalid dependencies for (const edge of node.edgesOut.values()) { if (edge.missing && !(edge.type === 'optional' || edge.type === 'peerOptional')) { errors.push(`missing: ${edge.name}@${edge.spec}, required by ${edge.from.pkgid}`) } if (edge.invalid) { /* istanbul ignore next */ const spec = edge.spec || '*' const from = edge.from.pkgid errors.push(`invalid: ${edge.to.pkgid}, ${spec} required by ${from}`) } } return errors } module.exports = SBOM
Save
cmd:
run