Skip to content

Conversation

@ujjwalgarg1995
Copy link

This PR is too add support for PNPM package manager.


function getCommand(action) {
// Derived from pnpm-audit-report
// TODO: share the code
Copy link
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This looks familiar. Is this comment section true?

}
}

module.exports = {
Copy link
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Doesn't look like it's any different from npm. Is this just 'p' added to every 'npm' in the code, or I missed the changes?

Is that enough for it to work?

Copy link
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@naugtur PNPM commands are almost similar to NPM. It works. We are using my fork in production.

@naugtur
Copy link
Owner

naugtur commented Jan 12, 2021

Thanks! I should have included pnpm a long time ago.

IS it really that similar to npm? If so, I don't see the point in copy-pasting the code, I'd just add the missing 'p' conditionally to the commands form the original implementation.

@ujjwalgarg1995
Copy link
Author

@naugtur in last 5 months, I haven't seen any difference in NPM and PNPM commands.

@bFerry-xealth
Copy link

@naugtur This appears to be dead, what can I do to get this moving again?

npm audit --json --omit=dev

{
  "auditReportVersion": 2,
  "vulnerabilities": {},
  "metadata": {
    "vulnerabilities": {
      "info": 0,
      "low": 0,
      "moderate": 0,
      "high": 0,
      "critical": 0,
      "total": 0
    },
    "dependencies": {
      "prod": 415,
      "dev": 987,
      "optional": 123,
      "peer": 84,
      "peerOptional": 0,
      "total": 1455
    }
  }
}

pnpm audit --json --prod

{
  "actions": [],
  "advisories": {},
  "muted": [],
  "metadata": {
    "vulnerabilities": {
      "info": 0,
      "low": 0,
      "moderate": 0,
      "high": 0,
      "critical": 0
    },
    "dependencies": 372,
    "devDependencies": 0,
    "optionalDependencies": 0,
    "totalDependencies": 372
  }
}

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants