Skip to content

yarn lockfile scan doesnt catch dev dependencies #4548

@rezmoss

Description

@rezmoss

What would you like to be added:
yarn lockfile scan doesnt catch dev dependencies right now like npm/pmpm,
also adding an option to exclude dev deps

Why is this needed:

1-scan yarn lock
2-check package json if its there
3-find dev and prod deps
4-find all transitives
5-filter and ret result

Additional context:

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    Status

    Done

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions