{"_id":"@arnica-io/dependency-scan","_rev":"20-bf04baa4c258d9523fe567187b138158","name":"@arnica-io/dependency-scan","dist-tags":{"latest":"1.0.33"},"versions":{"1.0.30":{"name":"@arnica-io/dependency-scan","version":"1.0.30","keywords":[],"author":"","license":"ISC","_id":"@arnica-io/dependency-scan@1.0.30","maintainers":[{"name":"arnica-io","email":"engineering@arnica.io"}],"homepage":"https://github.com/arnica-io/dependency-scan#readme","bugs":{"url":"https://github.com/arnica-io/dependency-scan/issues"},"bin":{"arnica-scan":"dist/cli.js"},"dist":{"shasum":"938e1107b1d351d402568d2fab42785bd2cc613f","tarball":"https://registry.npmjs.org/@arnica-io/dependency-scan/-/dependency-scan-1.0.30.tgz","fileCount":43,"integrity":"sha512-BdHmkoUXxvKs9FQf9CkvhVXmpxVc8saocYw9J5DrZsawMC5aItEuFDTlpptRuNldk7Dgj/VrWSqKJU4e5zKNfA==","signatures":[{"sig":"MEQCIGF7XWKe+p87dXPy1hnnNTOpd4bhsFNXEGX3ikqktK/SAiAOM8CEiLIo8zjo/Z4Z5lqdW5oXhofCn5Ay4queA0rMqg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@arnica-io%2fdependency-scan@1.0.30","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":73268},"main":"dist/cli.js","type":"commonjs","_from":"file:arnica-io-dependency-scan-1.0.30.tgz","types":"./dist/cli.d.ts","scripts":{"scan":"node dist/cli.js","test":"pnpm run typecheck","build":"tsc","typecheck":"tsc --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:0f48e19d-fb04-4e97-953d-428a7bc2471a"}},"_resolved":"/tmp/47876bf8d57e4e5a360445fefed4ce7b/arnica-io-dependency-scan-1.0.30.tgz","_integrity":"sha512-BdHmkoUXxvKs9FQf9CkvhVXmpxVc8saocYw9J5DrZsawMC5aItEuFDTlpptRuNldk7Dgj/VrWSqKJU4e5zKNfA==","repository":{"url":"git+https://github.com/arnica-io/dependency-scan.git","type":"git"},"_npmVersion":"11.9.0","description":"Arnica dependency security scan for GitHub Actions and Azure DevOps pipelines","directories":{"doc":"docs","test":"tests"},"_nodeVersion":"24.14.0","dependencies":{"@actions/core":"^2.0.3","@actions/exec":"^1.1.1","@cyclonedx/cdxgen":"11.3.2"},"publishConfig":{"registry":"https://registry.npmjs.org","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.9.3","@types/node":"^24.10.1"},"_npmOperationalInternal":{"tmp":"tmp/dependency-scan_1.0.30_1774996840413_0.28095890131947643","host":"s3://npm-registry-packages-npm-production"}},"1.0.31":{"name":"@arnica-io/dependency-scan","version":"1.0.31","keywords":[],"author":"","license":"ISC","_id":"@arnica-io/dependency-scan@1.0.31","maintainers":[{"name":"arnica-io","email":"engineering@arnica.io"}],"homepage":"https://github.com/arnica-io/dependency-scan#readme","bugs":{"url":"https://github.com/arnica-io/dependency-scan/issues"},"bin":{"arnica-scan":"dist/cli.js"},"dist":{"shasum":"60ab208473de9895002b99b4ae5a30604662bba6","tarball":"https://registry.npmjs.org/@arnica-io/dependency-scan/-/dependency-scan-1.0.31.tgz","fileCount":59,"integrity":"sha512-lZex20gw6Y4kUdp/G8AJcZ1iuu6FiBZDqh3r9FoNY31GWhJS90j5dkRdDoXkcNRg1rNEL6cSe0Cpie7ix7pocA==","signatures":[{"sig":"MEUCIQDsqNnomyhqQ1lM/2dYxDHJXh/K9R92BPrya4ySAiIKYgIgTeSfczT9/452lc2AZeCeB1ovff6UhVCwicbrjKw3zUU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@arnica-io%2fdependency-scan@1.0.31","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":116506},"main":"dist/cli.js","type":"commonjs","_from":"file:arnica-io-dependency-scan-1.0.31.tgz","types":"./dist/cli.d.ts","scripts":{"scan":"node dist/cli.js","test":"pnpm run typecheck && node --test tests/*.test.cjs","build":"tsc","typecheck":"tsc --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:0f48e19d-fb04-4e97-953d-428a7bc2471a"}},"_resolved":"/tmp/04613267a03ad5f85399c69b65eaaaad/arnica-io-dependency-scan-1.0.31.tgz","_integrity":"sha512-lZex20gw6Y4kUdp/G8AJcZ1iuu6FiBZDqh3r9FoNY31GWhJS90j5dkRdDoXkcNRg1rNEL6cSe0Cpie7ix7pocA==","repository":{"url":"git+https://github.com/arnica-io/dependency-scan.git","type":"git"},"_npmVersion":"11.12.1","description":"Arnica dependency security scan for GitHub Actions, Azure DevOps, Bitbucket Pipelines, and GitLab CI","directories":{"doc":"docs","test":"tests"},"_nodeVersion":"24.15.0","dependencies":{"@actions/core":"^2.0.3","@actions/exec":"^1.1.1","@cyclonedx/cdxgen":"11.3.2"},"publishConfig":{"registry":"https://registry.npmjs.org","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.9.3","@types/node":"^24.10.1"},"_npmOperationalInternal":{"tmp":"tmp/dependency-scan_1.0.31_1779136690601_0.16754649345108108","host":"s3://npm-registry-packages-npm-production"}},"1.0.32":{"name":"@arnica-io/dependency-scan","version":"1.0.32","keywords":[],"author":"","license":"ISC","_id":"@arnica-io/dependency-scan@1.0.32","maintainers":[{"name":"arnica-io","email":"engineering@arnica.io"}],"homepage":"https://github.com/arnica-io/dependency-scan#readme","bugs":{"url":"https://github.com/arnica-io/dependency-scan/issues"},"bin":{"arnica-scan":"dist/cli.js"},"dist":{"shasum":"fcd0e682f8f916035972ad27d3f1d97d5241908e","tarball":"https://registry.npmjs.org/@arnica-io/dependency-scan/-/dependency-scan-1.0.32.tgz","fileCount":59,"integrity":"sha512-XrZxnxTLkbs2nJEw7yO0R5Hdf1MG7/C4FO8JsMcGR80g2V20YnHCQNwFKyy7a8x0z7pd5X5W8g8ZKvJJXb7oeQ==","signatures":[{"sig":"MEQCIDEcfMtFwVv+7Ik7REJ0dEupVyWfG7pwW8trQQda6jRsAiB/PvA7wV91ZPTVuhuxw0WMV0Fe6s7Im4FWePF0d9W8Sw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@arnica-io%2fdependency-scan@1.0.32","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":116506},"main":"dist/cli.js","type":"commonjs","_from":"file:arnica-io-dependency-scan-1.0.32.tgz","types":"./dist/cli.d.ts","scripts":{"scan":"node dist/cli.js","test":"pnpm run typecheck && node --test tests/*.test.cjs","build":"tsc","typecheck":"tsc --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:0f48e19d-fb04-4e97-953d-428a7bc2471a"}},"_resolved":"/tmp/414a5689933345567a25ff187708816f/arnica-io-dependency-scan-1.0.32.tgz","_integrity":"sha512-XrZxnxTLkbs2nJEw7yO0R5Hdf1MG7/C4FO8JsMcGR80g2V20YnHCQNwFKyy7a8x0z7pd5X5W8g8ZKvJJXb7oeQ==","repository":{"url":"git+https://github.com/arnica-io/dependency-scan.git","type":"git"},"_npmVersion":"11.17.0","description":"Arnica dependency security scan for GitHub Actions, Azure DevOps, Bitbucket Pipelines, and GitLab CI","directories":{"doc":"docs","test":"tests"},"_nodeVersion":"24.19.0","dependencies":{"@actions/core":"^2.0.3","@actions/exec":"^1.1.1","@cyclonedx/cdxgen":"11.3.2"},"publishConfig":{"registry":"https://registry.npmjs.org","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.9.3","@types/node":"^24.10.1"},"_npmOperationalInternal":{"tmp":"tmp/dependency-scan_1.0.32_1786990015151_0.15721488026872743","host":"s3://npm-registry-packages-npm-production"}},"1.0.33":{"name":"@arnica-io/dependency-scan","version":"1.0.33","description":"Arnica dependency security scan for GitHub Actions, Azure DevOps, Bitbucket Pipelines, and GitLab CI","main":"dist/cli.js","bin":{"arnica-scan":"dist/cli.js"},"publishConfig":{"registry":"https://registry.npmjs.org","provenance":true},"repository":{"type":"git","url":"git+https://github.com/arnica-io/dependency-scan.git"},"dependencies":{"@actions/core":"^2.0.3","@actions/exec":"^1.1.1","@cyclonedx/cdxgen":"11.3.2"},"devDependencies":{"@types/node":"^24.10.1","typescript":"^5.9.3"},"directories":{"doc":"docs","test":"tests"},"keywords":[],"author":"","license":"ISC","type":"commonjs","types":"./dist/cli.d.ts","bugs":{"url":"https://github.com/arnica-io/dependency-scan/issues"},"homepage":"https://github.com/arnica-io/dependency-scan#readme","scripts":{"build":"tsc","typecheck":"tsc --noEmit","scan":"node dist/cli.js","test":"pnpm run typecheck && node --test tests/*.test.cjs"},"_id":"@arnica-io/dependency-scan@1.0.33","_integrity":"sha512-3g5GqigjBxXF8wi8sY/vHl3325XnGO9cvVqxoxIeB1FSk0ZHr1j/MzDBEEjxp20pC4jxV5zKeXuxoYfz4LT7Og==","_resolved":"/tmp/bce115720ab939dbf5f14c875bebc1f7/arnica-io-dependency-scan-1.0.33.tgz","_from":"file:arnica-io-dependency-scan-1.0.33.tgz","_nodeVersion":"24.19.0","_npmVersion":"11.17.0","dist":{"integrity":"sha512-3g5GqigjBxXF8wi8sY/vHl3325XnGO9cvVqxoxIeB1FSk0ZHr1j/MzDBEEjxp20pC4jxV5zKeXuxoYfz4LT7Og==","shasum":"3025284103c7f6220279d5b63eec7ce94b2f516d","tarball":"https://registry.npmjs.org/@arnica-io/dependency-scan/-/dependency-scan-1.0.33.tgz","fileCount":59,"unpackedSize":116659,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@arnica-io%2fdependency-scan@1.0.33","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIALDvbUeRu/JZkOr21Cjurnavsu71c648iM4eKEee22lAiBRd4/pz5rieMzzBvC7ElwX1H2akPbSHwqw0aB6AuwmDg=="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:0f48e19d-fb04-4e97-953d-428a7bc2471a"}},"maintainers":[{"name":"arnica-io","email":"engineering@arnica.io"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/dependency-scan_1.0.33_1786993012229_0.18204230644668362"},"_hasShrinkwrap":false}},"time":{"created":"2026-03-30T20:10:41.880Z","modified":"2026-08-17T18:56:52.702Z","0.0.1-dev.1":"2026-03-30T20:10:42.189Z","0.0.0-dev.1.488f588":"2026-03-31T17:59:36.844Z","1.0.26":"2026-03-31T18:03:23.306Z","1.0.27":"2026-03-31T18:08:41.792Z","1.0.28":"2026-03-31T18:14:40.949Z","1.0.29":"2026-03-31T19:25:41.142Z","1.1.0":"2026-03-31T19:39:34.272Z","1.1.2":"2026-03-31T19:45:24.884Z","1.0.30":"2026-03-31T22:40:40.558Z","1.0.31":"2026-05-18T20:38:10.736Z","1.0.32":"2026-08-17T18:06:55.293Z","1.0.33":"2026-08-17T18:56:52.375Z"},"bugs":{"url":"https://github.com/arnica-io/dependency-scan/issues"},"license":"ISC","homepage":"https://github.com/arnica-io/dependency-scan#readme","keywords":[],"repository":{"type":"git","url":"git+https://github.com/arnica-io/dependency-scan.git"},"description":"Arnica dependency security scan for GitHub Actions, Azure DevOps, Bitbucket Pipelines, and GitLab CI","maintainers":[{"name":"arnica-io","email":"engineering@arnica.io"}],"readme":"<p align=\"center\">\n  <a href=\"https://app.arnica.io\">\n    <img src=\"docs/images/arnica-logo.png\" alt=\"Arnica\" height=\"120\" />\n  </a>\n</p>\n\n## Arnica Dependency Scan – GitHub Action\n\nThe same scanner is available as a **GitHub Action** (composite) and as an **npm CLI** for Azure DevOps, Bitbucket Pipelines, and GitLab CI (`npx @arnica-io/dependency-scan`).\n\nExtend Arnica’s security scanning into complex build environments that pull dependencies from multiple sources or compile packages from source.\nWhen real-time checks aren’t enough, post-build scanning validates SBOMs directly from your CI/CD pipelines via API, returning pass/fail results to enforce security gates before merges or deployments. Ensure consistent policy enforcement and centralized visibility in Arnica’s dashboard, even for environments with intricate dependency resolution.\n\n### Pipeline Examples\n\nReference pipeline files with comments and secret/path notes:\n\n- GitHub Action: `examples/github-action.yml`\n- Azure DevOps: `examples/azure-devops.yml`\n- Bitbucket Pipelines: `examples/bitbucket-pipelines.yml`\n- GitLab CI: `examples/gitlab-ci.yml`\n\n### Quickstart\n\nAdd a workflow that runs on PR events and merges to SLA branches for complete security coverage.\n\n```yaml\nname: Arnica Dependency Security Scan\non:\n  pull_request:\n    types: [opened, synchronize]\n  push:\n    branches: [main, develop, staging, production] # Add your SLA branches\n  workflow_dispatch:\n\njobs:\n  security-scan:\n    runs-on: ubuntu-latest\n    permissions:\n      contents: read\n    steps:\n      - name: Checkout repository\n        uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd #v6.0.2\n        with:\n          persist-credentials: false\n\n      - name: Dependency Security Scan with Arnica\n        id: arnica\n        uses: arnica-io/dependency-scan@ab5da123065b211ff1d3b941748edb819153ea08 # v1.0.33\n        env:\n          ARNICA_API_TOKEN: ${{ secrets.ARNICA_API_TOKEN }}\n        with:\n          repository-url: ${{ github.server_url }}/${{ github.repository }}\n          branch: ${{ github.head_ref || github.ref_name }} # Uses the PR source branch for pull requests, or the current branch for pushes\n          scan-path: .\n\n      - name: Print scan results\n        run: |\n          echo \"Scan ID: ${{ steps.arnica.outputs['scan-id'] }}\"\n          echo \"Status: ${{ steps.arnica.outputs.status }}\"\n```\n\n### Pinning to a Commit SHA\n\nWhile Arnica's action tags are immutable, as a general best practice we recommend pinning all GitHub Actions to a full commit SHA rather than a tag. SHA pinning ensures your workflows are deterministic and aligned with [GitHub's security hardening guidelines](https://docs.github.com/en/actions/security-for-github-actions/security-guides/security-hardening-for-github-actions#using-third-party-actions).\n\n```yaml\n# Best practice – pinned to commit SHA\nuses: arnica-io/dependency-scan@ab5da123065b211ff1d3b941748edb819153ea08 # v1.0.33\n```\n\nThe SHA for each release is listed on the [Releases](../../releases) page. This README is automatically updated with the latest SHA on every release.\n\n### Package Integrity\n\nAll npm packages are published with [SLSA provenance](https://docs.npmjs.com/generating-provenance-statements), providing cryptographic proof that each build originated from this repository. npm versions are immutable — once published, they cannot be modified or overwritten.\n\n### Recommended Workflow Triggers\n\nFor complete security coverage and accurate issue lifecycle tracking:\n\n- **Pull Requests**: `opened`, `synchronize` - Catches issues before merge\n- **Main/Release Branches**: `push` to `main`, `develop`, `staging`, `production`\n- **Build Pipelines**: Add to any workflow where code is built or deployed\n- **Manual Runs**: `workflow_dispatch` for on-demand scans\n\n### Where to View Reports\n\nSecurity scan results appear in multiple locations:\n\n1. **GitHub Step Summary**: Detailed findings report in the workflow run\n2. **Arnica Dashboard**: Full vulnerability management at `https://app.arnica.io`\n3. **Workflow Logs**: Console output with scan details\n4. **PR Comments** (if configured): Summary posted to pull requests\n\n### Inputs\n\n| Name                   | Required | Default                     | Description                                                                |\n| ---------------------- | :------: | --------------------------- | -------------------------------------------------------------------------- |\n| `repository-url`       |   Yes    |                             | Repository URL associated with the scan                                    |\n| `branch`               |   Yes    | `main`                      | Branch to associate with the scan                                          |\n| `scan-path`            |   No     |  `.`                        | Directory path to scan and generate SBOM for (e.g., `.` or `services/api`) |\n| `api-base-url`         |    No    | `https://api.app.arnica.io` | Arnica API base URL                                                        |\n| `api-token`            |    No    |                             | Arnica API token; prefer secret env `ARNICA_API_TOKEN`                     |\n| `scan-timeout-seconds` |    No    | `900`                       | Timeout (seconds) to wait for scan completion                              |\n| `on-findings`          |    No    | `fail`                      | Behavior when findings are detected: fail, alert, or pass                  |\n| `debug`                |    No    | `false`                     | Enable verbose API response debug logs                                     |\n\n### Outputs\n\n- **scan-id**: Arnica scan identifier.\n- **status**: Final status, one of `Success`, `Failure`, `Error`, `Skipped`, or `Timeout`.\n\n### CLI Environment Variables (All Platforms)\n\nUse these env vars when running the scanner via `npx @arnica-io/dependency-scan` (Azure DevOps, Bitbucket Pipelines, and similar CI).\n\n| Name                          | Required | Default                     | Description                              |\n| ----------------------------- | :------: | --------------------------- | ---------------------------------------- |\n| `ARNICA_API_TOKEN`            |   Yes    |                             | Arnica API token                         |\n| `ARNICA_API_BASE_URL`         |    No    | `https://api.app.arnica.io` | Arnica API base URL                      |\n| `ARNICA_REPOSITORY_URL`       |    No    | auto-detected               | Repository URL override                  |\n| `ARNICA_BRANCH`               |    No    | auto-detected               | Branch override                          |\n| `ARNICA_SCAN_PATH`            |    No    | `.`                         | Directory path to scan                   |\n| `ARNICA_SCAN_TIMEOUT_SECONDS` |    No    | `900`                       | Scan wait timeout in seconds             |\n| `ARNICA_ON_FINDINGS`          |    No    | `fail`                      | `fail`, `alert`, or `pass`               |\n| `ARNICA_DEBUG`                |    No    | `false`                     | Verbose API debug logs when set to `true`|\n\nGeneric `DEBUG` is intentionally ignored so unrelated tools that set `DEBUG=true` do not enable Arnica verbose logging.\n\nAuto-detection sources when `ARNICA_REPOSITORY_URL` / `ARNICA_BRANCH` are not provided:\n\n- **GitHub**: `GITHUB_SERVER_URL`, `GITHUB_REPOSITORY`, `GITHUB_HEAD_REF` / `GITHUB_REF_NAME`\n- **Azure DevOps**: `BUILD_REPOSITORY_URI`, `BUILD_SOURCEBRANCHNAME`\n- **Bitbucket Cloud/Server**: `BITBUCKET_GIT_HTTP_ORIGIN`, `BITBUCKET_GIT_SSH_ORIGIN`, `BITBUCKET_REPO_FULL_NAME`, `BITBUCKET_WORKSPACE`, `BITBUCKET_REPO_OWNER`, `BITBUCKET_REPO_SLUG`, `BITBUCKET_BRANCH`, `BITBUCKET_PR_SOURCE_BRANCH`, `BITBUCKET_SOURCE_BRANCH`, `BITBUCKET_BRANCH_NAME`\n- **Bitbucket Server (HTTPS clone URL synthesis):** `BITBUCKET_SERVER_URL` or `BITBUCKET_BASE_URL` with `BITBUCKET_REPO_FULL_NAME`; optional `BITBUCKET_SERVER_SCM_PREFIX` (default `scm`) when the Git HTTP path is not `/scm/...`\n- **GitLab CI**: `CI_REPOSITORY_URL` (credentials are stripped automatically), `CI_PROJECT_URL`, `CI_COMMIT_BRANCH`, `CI_MERGE_REQUEST_SOURCE_BRANCH_NAME`, `CI_COMMIT_REF_NAME` (skipped when `CI_COMMIT_TAG` is set to avoid reporting tags as branches), `CI_DEFAULT_BRANCH` (used as fallback in tag pipelines)\n\n### Permissions\n\nThis action does not require repository write permissions. For least privilege, set:\n\n```yaml\npermissions:\n  contents: read\n```\n\n### Examples\n\nScan a subdirectory and alert (do not fail) on policy violations:\n\n```yaml\n- name: Generate SBOM and scan with Arnica\n  id: arnica\n  uses: arnica-io/dependency-scan@ab5da123065b211ff1d3b941748edb819153ea08 # v1.0.33\n  env:\n    ARNICA_API_TOKEN: ${{ secrets.ARNICA_API_TOKEN }}\n  with:\n    repository-url: https://github.com/owner/repo\n    branch: ${{ github.ref_name }}\n    scan-path: services/payments\n    on-findings: alert\n```\n\n### Prerequisites\n\n- Sign in to Arnica with a privileged `admin` account. Sign in at `https://app.arnica.io`.\n\n### API key and permissions\n\nCreate an Arnica API key with only the SBOM scopes:\n\n1. Navigate to Admin → API.\n2. Create a new API key.\n3. Select scopes: `sbom-api:read` and `sbom-api:write` only.\n4. Store the token as a repository secret named `ARNICA_API_TOKEN`.\n\n---\n\n## Azure DevOps Pipelines\n\nUse the **published npm package** from the registry (`npx`). You only need `checkout: self` and a Node task—no extra GitHub service connection for the default flow.\n\n### Prerequisites\n\n1. **ARNICA_API_TOKEN**: Store in a **Variable Group** (e.g. `arnica-secrets` under **Pipelines → Library**) as a secret.\n2. **Node.js 24+** on the agent (`NodeTool@0`).\n\n### Example pipeline\n\n```yaml\ntrigger:\n  branches:\n    include:\n      - main\n\npool:\n  vmImage: ubuntu-latest\n\nvariables:\n  - group: arnica-secrets\n\nsteps:\n  - checkout: self\n\n  - task: NodeTool@0\n    inputs:\n      versionSpec: \"24.x\"\n    displayName: Use Node 24\n\n  - script: |\n      set -euo pipefail\n      cd \"$(Build.SourcesDirectory)\"\n      npx --yes \"@arnica-io/dependency-scan@1.0.33\"\n    displayName: Arnica dependency scan\n    env:\n      ARNICA_API_TOKEN: $(ARNICA_API_TOKEN)\n```\n\nPin the version in the `npx` argument (`@x.y.z`). This README is updated with current pins on each release.\n\n### Self-hosted agent note (`npm.pkg.github.com` / 401)\n\nIf your Azure DevOps self-hosted agent has a global/user `.npmrc` that maps `@arnica-io` to GitHub Packages, `npx` may fail with `401 Unauthorized` against `npm.pkg.github.com`.\n\nForce npmjs for this step:\n\n```yaml\n  - script: |\n      set -euo pipefail\n      cd \"$(Build.SourcesDirectory)\"\n      npm config set registry \"https://registry.npmjs.org/\"\n      npm config delete @arnica-io:registry || true\n      npx --registry \"https://registry.npmjs.org/\" --yes \"@arnica-io/dependency-scan@1.0.33\"\n    displayName: Arnica dependency scan\n```\n\n### Advanced: build from a git checkout (lockfile-pinned)\n\nIf you want transitives fixed to this repo’s `pnpm-lock.yaml`, add a **GitHub service connection**, check out `arnica-io/dependency-scan` at a release tag, then `corepack prepare pnpm@9.15.4 --activate`, `pnpm install --frozen-lockfile`, `pnpm run build`, and run `node dist/cli.js` with `PATH` including that checkout’s `node_modules/.bin`. Use the same CLI env vars (`ARNICA_API_TOKEN`, `ARNICA_REPOSITORY_URL`, `ARNICA_BRANCH`, `ARNICA_SCAN_PATH`, `ARNICA_ON_FINDINGS`, etc.) from `$(Build.SourcesDirectory)` for the project you are scanning (`checkout: self`).\n\nEnvironment variables are documented once in **CLI Environment Variables (All Platforms)** above.\n\n### Example: scan a subdirectory, alert only\n\nAdd to the same `env` block as the main example:\n\n```yaml\n      ARNICA_SCAN_PATH: \"services/payments\"\n      ARNICA_ON_FINDINGS: alert\n```\n\n### Where to View Reports (Azure DevOps)\n\n1. **Pipeline Extensions Tab**: Scan summary is uploaded as a task summary attachment\n2. **Arnica Dashboard**: Full vulnerability management at `https://app.arnica.io`\n3. **Pipeline Logs**: Console output with scan details\n\n---\n\n## Bitbucket Pipelines\n\nUse the **published npm package** with `npx`, same as Azure DevOps.\n\n- **Bitbucket Cloud**: auto-detects from `BITBUCKET_GIT_HTTP_ORIGIN` and `BITBUCKET_BRANCH`.\n- **Bitbucket Server/Data Center runners**: also supports `BITBUCKET_GIT_SSH_ORIGIN` and derives a repository URL from `BITBUCKET_SERVER_URL` + `BITBUCKET_REPO_FULL_NAME` when needed.\n\nYou can always override detection with `ARNICA_REPOSITORY_URL` and `ARNICA_BRANCH`.\n\n**Bitbucket Server URL shape:** Auto-derived URLs use `{BITBUCKET_SERVER_URL}/{BITBUCKET_SERVER_SCM_PREFIX}/{BITBUCKET_REPO_FULL_NAME}.git` with prefix defaulting to `scm` (common for Atlassian Bitbucket Server). Some installations use a different path segment (for example `git`); set `BITBUCKET_SERVER_SCM_PREFIX` to match yours. Project-key layouts, HTTP(S) proxies, or non-standard Git HTTP paths may still require setting `ARNICA_REPOSITORY_URL` explicitly.\n\n### Prerequisites\n\n1. **ARNICA_API_TOKEN**: Store as a **secured** repository variable (Repository settings → Pipelines → Repository variables).\n2. **Node.js 24+** on the step image (for example `node:24`).\n\n### Example pipeline\n\n```yaml\nimage: node:24\n\npipelines:\n  default:\n    - step:\n        name: Arnica dependency scan\n        script:\n          - cd \"$BITBUCKET_CLONE_DIR\"\n          - npx --yes \"@arnica-io/dependency-scan@1.0.33\"\n        artifacts:\n          - arnica-scan-summary.md\n          - .arnica-scan-outputs.env\n```\n\nPin the version in the `npx` argument (`@x.y.z`). This README is updated with current pins on each release.\n\n### Advanced: test scanner from source before npm publish\n\nIf you want to validate unreleased changes, clone the scanner source in the pipeline, build it, and run it from source.\n\n```yaml\nimage: node:24\n\npipelines:\n  default:\n    - step:\n        name: Arnica dependency scan (from source)\n        script:\n          - set -euo pipefail\n          - test -n \"${ARNICA_API_TOKEN:-}\" || (echo \"ARNICA_API_TOKEN is required\" && exit 1)\n          - test -n \"${ARNICA_SCAN_REPO_URL:-}\" || (echo \"ARNICA_SCAN_REPO_URL is required\" && exit 1)\n          - git clone --depth 1 --branch \"${ARNICA_SCAN_REF:-main}\" \"${ARNICA_SCAN_REPO_URL}\" /tmp/dependency-scan-src\n          - cd /tmp/dependency-scan-src\n          - corepack enable\n          - corepack prepare pnpm@9.15.4 --activate\n          - pnpm install --frozen-lockfile\n          - pnpm run build\n          - pnpm run scan\n        artifacts:\n          - arnica-scan-summary.md\n          - .arnica-scan-outputs.env\n```\n\nRequired variables for this mode:\n\n- `ARNICA_API_TOKEN` (secured)\n- `ARNICA_SCAN_REPO_URL` (git URL to your private/public dependency-scan fork)\n- `ARNICA_SCAN_REF` (optional branch/tag/commit; defaults to `main`)\n\n### Outputs and summary\n\nBitbucket Pipelines does not expose GitHub-style step outputs or Azure `##vso` variables. This integration:\n\n- Logs lines `ARNICA_OUTPUT <name>=<value>` for visibility in the build log.\n- Appends `name=value` lines to **`.arnica-scan-outputs.env`** under the clone directory (optional `source` in a later step, or keep via artifacts).\n- Writes **`arnica-scan-summary.md`** in the clone directory; list both files under `artifacts` if you want to download them.\n\nEnvironment variables are documented once in **CLI Environment Variables (All Platforms)** above.\n\nRepository URL detection fallback order:\n\n1. `BITBUCKET_GIT_HTTP_ORIGIN`\n2. `BITBUCKET_GIT_SSH_ORIGIN`\n3. `BITBUCKET_SERVER_URL` (or `BITBUCKET_BASE_URL`) + `BITBUCKET_REPO_FULL_NAME`\n4. `https://bitbucket.org/<BITBUCKET_REPO_FULL_NAME>`\n\nBranch detection fallback order:\n\n1. `BITBUCKET_BRANCH`\n2. `BITBUCKET_PR_SOURCE_BRANCH`\n3. `BITBUCKET_SOURCE_BRANCH`\n4. `BITBUCKET_BRANCH_NAME`\n\n### Example: scan a subdirectory, alert only\n\nAdd to the same `script` or export env before `npx`:\n\n```yaml\n        script:\n          - export ARNICA_SCAN_PATH=\"services/payments\"\n          - export ARNICA_ON_FINDINGS=\"alert\"\n          - cd \"$BITBUCKET_CLONE_DIR\"\n          - npx --yes \"@arnica-io/dependency-scan@1.0.33\"\n```\n\n### Where to View Reports (Bitbucket)\n\n1. **Build logs**: `ARNICA_OUTPUT` lines and scan progress\n2. **Artifacts**: `arnica-scan-summary.md` if declared under `artifacts`\n3. **Arnica Dashboard**: Full vulnerability management at `https://app.arnica.io`\n\n### Troubleshooting (Bitbucket)\n\n- **Repository URL is missing**\n  - Set `ARNICA_REPOSITORY_URL` explicitly in the step environment.\n  - Verify your runner exports one of: `BITBUCKET_GIT_HTTP_ORIGIN`, `BITBUCKET_GIT_SSH_ORIGIN`, or (`BITBUCKET_SERVER_URL` + `BITBUCKET_REPO_FULL_NAME`).\n- **Unexpected branch value in PR pipelines**\n  - PR pipelines may expose multiple branch variables depending on runner type.\n  - Set `ARNICA_BRANCH` explicitly if you need strict source-branch mapping.\n- **No summary/output artifacts visible**\n  - Make sure `arnica-scan-summary.md` and `.arnica-scan-outputs.env` are listed under `artifacts`.\n\n---\n\n## GitLab CI\n\nUse the **published npm package** with `npx`, same as Azure DevOps and Bitbucket.\n\n- Auto-detects repository URL from `CI_REPOSITORY_URL` or `CI_PROJECT_URL` (embedded CI job tokens are stripped automatically).\n- Auto-detects branch from `CI_COMMIT_BRANCH`, `CI_MERGE_REQUEST_SOURCE_BRANCH_NAME`, or `CI_COMMIT_REF_NAME` (tag pipelines are handled — `CI_COMMIT_REF_NAME` is skipped when `CI_COMMIT_TAG` is set).\n\nYou can always override detection with `ARNICA_REPOSITORY_URL` and `ARNICA_BRANCH`.\n\n### Prerequisites\n\n1. **ARNICA_API_TOKEN**: Store as a **masked** CI/CD variable (Settings → CI/CD → Variables).\n2. **Node.js 24+** on the job image (for example `node:24`).\n\n### Example pipeline\n\n```yaml\nstages:\n  - scan\n\ndependency-scan:\n  stage: scan\n  image: node:24\n  script:\n    - cd \"${CI_PROJECT_DIR}\"\n    - npx --yes \"@arnica-io/dependency-scan@1.0.33\"\n  artifacts:\n    paths:\n      - arnica-scan-summary.md\n      - .arnica-scan-outputs.env\n    reports:\n      dotenv: .arnica-scan-outputs.env\n    when: always\n    expire_in: 7 days\n```\n\nPin the version in the `npx` argument (`@x.y.z`). This README is updated with current pins on each release.\n\n### Advanced: test scanner from source before npm publish\n\nIf you want to validate unreleased changes, clone the scanner source in the pipeline, build it, and run it from source.\n\n```yaml\nstages:\n  - scan\n\ndependency-scan:\n  stage: scan\n  image: node:24\n  script:\n    - set -euo pipefail\n    - test -n \"${ARNICA_API_TOKEN:-}\" || (echo \"ARNICA_API_TOKEN is required\" && exit 1)\n    - git clone --depth 1 --branch \"${ARNICA_SCAN_REF:-main}\" \"${ARNICA_SCAN_REPO_URL}\" /tmp/dependency-scan-src\n    - cd /tmp/dependency-scan-src\n    - corepack enable\n    - corepack prepare pnpm@9.15.4 --activate\n    - pnpm install --frozen-lockfile\n    - pnpm run build\n    - cd \"${CI_PROJECT_DIR}\"\n    - export PATH=\"/tmp/dependency-scan-src/node_modules/.bin:${PATH}\"\n    - node /tmp/dependency-scan-src/dist/cli.js\n  artifacts:\n    paths:\n      - arnica-scan-summary.md\n      - .arnica-scan-outputs.env\n    reports:\n      dotenv: .arnica-scan-outputs.env\n    when: always\n    expire_in: 7 days\n```\n\nRequired variables for this mode:\n\n- `ARNICA_API_TOKEN` (masked)\n- `ARNICA_SCAN_REPO_URL` (git URL to your private/public dependency-scan fork)\n- `ARNICA_SCAN_REF` (optional branch/tag/commit; defaults to `main`)\n\n### Outputs and summary\n\nGitLab CI does not expose GitHub-style step outputs or Azure `##vso` variables. This integration:\n\n- Logs lines `ARNICA_OUTPUT <name>=<value>` for visibility in the job log.\n- Appends `name=value` lines to **`.arnica-scan-outputs.env`** under the project directory. Declare it as a `dotenv` report artifact so downstream jobs can consume the variables.\n- Writes **`arnica-scan-summary.md`** in the project directory; list it under `artifacts: paths` to download from the pipeline UI.\n\nEnvironment variables are documented once in **CLI Environment Variables (All Platforms)** above.\n\nRepository URL detection fallback order:\n\n1. `CI_REPOSITORY_URL` (embedded credentials stripped)\n2. `CI_PROJECT_URL`\n\nBranch detection fallback order:\n\n1. `CI_COMMIT_BRANCH`\n2. `CI_MERGE_REQUEST_SOURCE_BRANCH_NAME`\n3. `CI_COMMIT_REF_NAME` (skipped when `CI_COMMIT_TAG` is set)\n4. `CI_DEFAULT_BRANCH` (the project's default branch; used automatically in tag pipelines)\n\n### Example: scan a subdirectory, alert only\n\nAdd a `variables` block to the job:\n\n```yaml\n  variables:\n    ARNICA_SCAN_PATH: \"services/payments\"\n    ARNICA_ON_FINDINGS: \"alert\"\n```\n\n### Where to View Reports (GitLab)\n\n1. **Job logs**: `ARNICA_OUTPUT` lines and scan progress\n2. **Artifacts**: `arnica-scan-summary.md` downloadable from the pipeline UI\n3. **Downstream variables**: `.arnica-scan-outputs.env` as a `dotenv` report artifact\n4. **Arnica Dashboard**: Full vulnerability management at `https://app.arnica.io`\n\n### Troubleshooting (GitLab)\n\n- **Repository URL is missing**\n  - Set `ARNICA_REPOSITORY_URL` explicitly in the job variables.\n  - Verify your runner exports `CI_REPOSITORY_URL` or `CI_PROJECT_URL`.\n- **Branch shows tag name instead of branch**\n  - In tag pipelines, `CI_COMMIT_BRANCH` is unset and `CI_COMMIT_REF_NAME` contains the tag. The scanner detects `CI_COMMIT_TAG` and skips `CI_COMMIT_REF_NAME`, falling back to `CI_DEFAULT_BRANCH` (if set by the runner) then `main`. Set `ARNICA_BRANCH` explicitly if you need a specific value.\n- **No summary/output artifacts visible**\n  - Make sure `arnica-scan-summary.md` and `.arnica-scan-outputs.env` are listed under `artifacts: paths`, and `.arnica-scan-outputs.env` is declared under `artifacts: reports: dotenv`.\n- **Workspace path warning (`CI_PROJECT_DIR` is unavailable)**\n  - Ensure the job runs inside a proper GitLab CI runner. Custom Docker executors must export `CI_PROJECT_DIR`.\n\n---\n\n### Contributing\n\nSee `CONTRIBUTING.md` for development, testing, and release guidance. Please open an Issue first for substantial changes.\n\n### Code of Conduct\n\nThis project adheres to a Code of Conduct. By participating, you agree to uphold it. See `CODE_OF_CONDUCT.md`.\n\n### License\n\nMIT — see `LICENSE.md`.\n\n### Support\n\nQuestions or issues? Open a GitHub Issue. You can also propose enhancements via a feature request Issue or PR.\n","readmeFilename":"README.md"}