/
usr
/
local
/
lib
/
node_modules
/
npm
/
docs
/
content
/
commands
/
/usr/local/lib/node_modules/npm/docs/content/commands
mkdir
upload
Name
Size
Mode
Actions
npm-access.md
2888
0644
edit
dl
rm
npm-adduser.md
2033
0644
edit
dl
rm
npm-audit.md
16252
0644
edit
dl
rm
npm-bugs.md
2997
0644
edit
dl
rm
npm-cache.md
3450
0644
edit
dl
rm
npm-ci.md
9770
0644
edit
dl
rm
npm-completion.md
908
0644
edit
dl
rm
npm-config.md
4091
0644
edit
dl
rm
npm-dedupe.md
9543
0644
edit
dl
rm
npm-deprecate.md
2156
0644
edit
dl
rm
npm-diff.md
8985
0644
edit
dl
rm
npm-dist-tag.md
5170
0644
edit
dl
rm
npm-docs.md
2975
0644
edit
dl
rm
npm-doctor.md
5047
0644
edit
dl
rm
npm-edit.md
1091
0644
edit
dl
rm
npm-exec.md
11357
0644
edit
dl
rm
npm-explain.md
2794
0644
edit
dl
rm
npm-explore.md
1006
0644
edit
dl
rm
npm-find-dupes.md
6791
0644
edit
dl
rm
npm-fund.md
3674
0644
edit
dl
rm
npm-get.md
445
0644
edit
dl
rm
npm-help-search.md
755
0644
edit
dl
rm
npm-help.md
1003
0644
edit
dl
rm
npm-init.md
10213
0644
edit
dl
rm
npm-install-ci-test.md
8083
0644
edit
dl
rm
npm-install-test.md
11573
0644
edit
dl
rm
npm-install.md
29306
0644
edit
dl
rm
npm-link.md
12386
0644
edit
dl
rm
npm-ll.md
5686
0644
edit
dl
rm
npm-login.md
2354
0644
edit
dl
rm
npm-logout.md
1749
0644
edit
dl
rm
npm-ls.md
7148
0644
edit
dl
rm
npm-org.md
1974
0644
edit
dl
rm
npm-outdated.md
6978
0644
edit
dl
rm
npm-owner.md
3082
0644
edit
dl
rm
npm-pack.md
3832
0644
edit
dl
rm
npm-ping.md
769
0644
edit
dl
rm
npm-pkg.md
8056
0644
edit
dl
rm
npm-prefix.md
1206
0644
edit
dl
rm
npm-profile.md
3067
0644
edit
dl
rm
npm-prune.md
5737
0644
edit
dl
rm
npm-publish.md
8028
0644
edit
dl
rm
npm-query.md
6954
0644
edit
dl
rm
npm-rebuild.md
4994
0644
edit
dl
rm
npm-repo.md
2755
0644
edit
dl
rm
npm-restart.md
1444
0644
edit
dl
rm
npm-root.md
1096
0644
edit
dl
rm
npm-run.md
7538
0644
edit
dl
rm
npm-sbom.md
8338
0644
edit
dl
rm
npm-search.md
3560
0644
edit
dl
rm
npm-set.md
1433
0644
edit
dl
rm
npm-shrinkwrap.md
909
0644
edit
dl
rm
npm-star.md
1712
0644
edit
dl
rm
npm-stars.md
743
0644
edit
dl
rm
npm-start.md
1632
0644
edit
dl
rm
npm-stop.md
1320
0644
edit
dl
rm
npm-team.md
4084
0644
edit
dl
rm
npm-test.md
1213
0644
edit
dl
rm
npm-token.md
4905
0644
edit
dl
rm
npm-trust.md
10073
0644
edit
dl
rm
npm-undeprecate.md
1406
0644
edit
dl
rm
npm-uninstall.md
4447
0644
edit
dl
rm
npm-unpublish.md
4491
0644
edit
dl
rm
npm-unstar.md
1574
0644
edit
dl
rm
npm-update.md
12972
0644
edit
dl
rm
npm-version.md
8011
0644
edit
dl
rm
npm-view.md
7425
0644
edit
dl
rm
npm-whoami.md
800
0644
edit
dl
rm
npm.md
5638
0644
edit
dl
rm
npx.md
6287
0644
edit
dl
rm
Edit:
/usr/local/lib/node_modules/npm/docs/content/commands/npm-sbom.md
(8338B)
--- title: npm-sbom section: 1 description: Generate a Software Bill of Materials (SBOM) --- ### Synopsis ```bash npm sbom ``` ### Description The `npm sbom` command generates a Software Bill of Materials (SBOM) listing the dependencies for the current project. SBOMs can be generated in either [SPDX](https://spdx.dev/) or [CycloneDX](https://cyclonedx.org/) format. ### Example CycloneDX SBOM ```json { "$schema": "http://cyclonedx.org/schema/bom-1.5.schema.json", "bomFormat": "CycloneDX", "specVersion": "1.5", "serialNumber": "urn:uuid:09f55116-97e1-49cf-b3b8-44d0207e7730", "version": 1, "metadata": { "timestamp": "2023-09-01T00:00:00.001Z", "lifecycles": [ { "phase": "build" } ], "tools": [ { "vendor": "npm", "name": "cli", "version": "10.1.0" } ], "component": { "bom-ref": "simple@1.0.0", "type": "library", "name": "simple", "version": "1.0.0", "scope": "required", "author": "John Doe", "description": "simple react app", "purl": "pkg:npm/simple@1.0.0", "properties": [ { "name": "cdx:npm:package:path", "value": "" } ], "externalReferences": [], "licenses": [ { "license": { "id": "MIT" } } ] } }, "components": [ { "bom-ref": "lodash@4.17.21", "type": "library", "name": "lodash", "version": "4.17.21", "scope": "required", "author": "John-David Dalton", "description": "Lodash modular utilities.", "purl": "pkg:npm/lodash@4.17.21", "properties": [ { "name": "cdx:npm:package:path", "value": "node_modules/lodash" } ], "externalReferences": [ { "type": "distribution", "url": "https://registry.npmjs.org/lodash/-/lodash-4.17.21.tgz" }, { "type": "vcs", "url": "git+https://github.com/lodash/lodash.git" }, { "type": "website", "url": "https://lodash.com/" }, { "type": "issue-tracker", "url": "https://github.com/lodash/lodash/issues" } ], "hashes": [ { "alg": "SHA-512", "content": "bf690311ee7b95e713ba568322e3533f2dd1cb880b189e99d4edef13592b81764daec43e2c54c61d5c558dc5cfb35ecb85b65519e74026ff17675b6f8f916f4a" } ], "licenses": [ { "license": { "id": "MIT" } } ] } ], "dependencies": [ { "ref": "simple@1.0.0", "dependsOn": [ "lodash@4.17.21" ] }, { "ref": "lodash@4.17.21", "dependsOn": [] } ] } ``` ### Example SPDX SBOM ```json { "spdxVersion": "SPDX-2.3", "dataLicense": "CC0-1.0", "SPDXID": "SPDXRef-DOCUMENT", "name": "simple@1.0.0", "documentNamespace": "http://spdx.org/spdxdocs/simple-1.0.0-bf81090e-8bbc-459d-bec9-abeb794e096a", "creationInfo": { "created": "2023-09-01T00:00:00.001Z", "creators": [ "Tool: npm/cli-10.1.0" ] }, "documentDescribes": [ "SPDXRef-Package-simple-1.0.0" ], "packages": [ { "name": "simple", "SPDXID": "SPDXRef-Package-simple-1.0.0", "versionInfo": "1.0.0", "packageFileName": "", "description": "simple react app", "primaryPackagePurpose": "LIBRARY", "downloadLocation": "NOASSERTION", "filesAnalyzed": false, "homepage": "NOASSERTION", "licenseDeclared": "MIT", "externalRefs": [ { "referenceCategory": "PACKAGE-MANAGER", "referenceType": "purl", "referenceLocator": "pkg:npm/simple@1.0.0" } ] }, { "name": "lodash", "SPDXID": "SPDXRef-Package-lodash-4.17.21", "versionInfo": "4.17.21", "packageFileName": "node_modules/lodash", "description": "Lodash modular utilities.", "downloadLocation": "https://registry.npmjs.org/lodash/-/lodash-4.17.21.tgz", "filesAnalyzed": false, "homepage": "https://lodash.com/", "licenseDeclared": "MIT", "externalRefs": [ { "referenceCategory": "PACKAGE-MANAGER", "referenceType": "purl", "referenceLocator": "pkg:npm/lodash@4.17.21" } ], "checksums": [ { "algorithm": "SHA512", "checksumValue": "bf690311ee7b95e713ba568322e3533f2dd1cb880b189e99d4edef13592b81764daec43e2c54c61d5c558dc5cfb35ecb85b65519e74026ff17675b6f8f916f4a" } ] } ], "relationships": [ { "spdxElementId": "SPDXRef-DOCUMENT", "relatedSpdxElement": "SPDXRef-Package-simple-1.0.0", "relationshipType": "DESCRIBES" }, { "spdxElementId": "SPDXRef-Package-simple-1.0.0", "relatedSpdxElement": "SPDXRef-Package-lodash-4.17.21", "relationshipType": "DEPENDS_ON" } ] } ``` ### Package lock only mode If package-lock-only is enabled, only the information in the package lock (or shrinkwrap) is loaded. This means that information from the package.json files of your dependencies will not be included in the result set (e.g. description, homepage, engines). ### Configuration #### `omit` * Default: 'dev' if the `NODE_ENV` environment variable is set to 'production'; otherwise, empty. * Type: "dev", "optional", or "peer" (can be set multiple times) Dependency types to omit from the installation tree on disk. Note that these dependencies _are_ still resolved and added to the `package-lock.json` or `npm-shrinkwrap.json` file. They are just not physically installed on disk. If a package type appears in both the `--include` and `--omit` lists, then it will be included. If the resulting omit list includes `'dev'`, then the `NODE_ENV` environment variable will be set to `'production'` for all lifecycle scripts. #### `package-lock-only` * Default: false * Type: Boolean If set to true, the current operation will only use the `package-lock.json`, ignoring `node_modules`. For `update` this means only the `package-lock.json` will be updated, instead of checking `node_modules` and downloading dependencies. For `list` this means the output will be based on the tree described by the `package-lock.json`, rather than the contents of `node_modules`. #### `sbom-format` * Default: null * Type: "cyclonedx" or "spdx" SBOM format to use when generating SBOMs. #### `sbom-type` * Default: "library" * Type: "library", "application", or "framework" The type of package described by the generated SBOM. For SPDX, this is the value for the `primaryPackagePurpose` field. For CycloneDX, this is the value for the `type` field. #### `workspace` * Default: * Type: String (can be set multiple times) Enable running a command in the context of the configured workspaces of the current project while filtering by running only the workspaces defined by this configuration option. Valid values for the `workspace` config are either: * Workspace names * Path to a workspace directory * Path to a parent workspace directory (will result in selecting all workspaces within that folder) When set for the `npm init` command, this may be set to the folder of a workspace which does not yet exist, to create the folder and set it up as a brand new workspace within the project. This value is not exported to the environment for child processes. #### `workspaces` * Default: null * Type: null or Boolean Set to true to run the command in the context of **all** configured workspaces. Explicitly setting this to false will cause commands like `install` to ignore workspaces altogether. When not set explicitly: - Commands that operate on the `node_modules` tree (install, update, etc.) will link workspaces into the `node_modules` folder. - Commands that do other things (test, exec, publish, etc.) will operate on the root project, _unless_ one or more workspaces are specified in the `workspace` config. This value is not exported to the environment for child processes. ## See Also * [package spec](/using-npm/package-spec) * [dependency selectors](/using-npm/dependency-selectors) * [package.json](/configuring-npm/package-json) * [workspaces](/using-npm/workspaces)
Save
cmd:
run