-
Notifications
You must be signed in to change notification settings - Fork 32
Open
Description
Example:
socket package shallow npm @axe-core/react
_____ _ _ /---------------
| __|___ ___| |_ ___| |_ | CLI: v1.1.46
|__ | . | _| '_| -_| _| | token: ****** (config), org: **** (config)
|_____|___|___|_,_|___|_|.dev | Command: `socket package shallow`, cwd: ~/work/xxxxxxx
ℹ Requesting shallow score data for 1 package urls (purl): pkg:npm/@axe-core/react
✔ Received Socket API response (after requesting looking up package).
Shallow Package Score
Please note: The listed scores are ONLY for the package itself. It does NOT
reflect the scores of any dependencies, transitive or otherwise.
Package: pkg:npm/[email protected]
- Supply Chain Risk: 99
- Maintenance: 95
- Quality: 100
- Vulnerabilities: 100
- License: 70
- Alerts (0/0/2): [low] copyleftLicense and [low] nonpermissiveLicense
Informative print includes correct purl but output does not. The root cause:
| const purl = `pkg:${artifact.ecosystem}/${artifact.name}${artifact.version ? `@${artifact.version}` : ''}` |
socket package score command seems to be working fine because it is using data directly and on markdown generation data.purl is used as package name.
Metadata
Metadata
Assignees
Labels
No labels