{"_id":"@deluksic/cyclonedx-npm","name":"@deluksic/cyclonedx-npm","dist-tags":{"latest":"1.14.0"},"versions":{"1.14.0":{"name":"@deluksic/cyclonedx-npm","version":"1.14.0","description":"Create CycloneDX Software Bill of Materials (SBOM) from NPM projects.","license":"Apache-2.0","keywords":["CycloneDX","SBOM","BOM","inventory","bill-of-materials","software-bill-of-materials","component","dependency","package-url","PURL","spdx","node","npm"],"homepage":"https://github.com/CycloneDX/cyclonedx-node-npm#readme","repository":{"type":"git","url":"git+https://github.com/CycloneDX/cyclonedx-node-npm.git"},"bugs":{"url":"https://github.com/CycloneDX/cyclonedx-node-npm/issues"},"funding":[{"type":"github","url":"https://github.com/sponsors/jkowalleck"},{"type":"individual","url":"https://owasp.org/donate/?reponame=www-project-cyclonedx&title=OWASP+CycloneDX"}],"author":{"name":"Jan Kowalleck","email":"jan.kowalleck@gmail.com"},"contributors":[{"name":"Jan Kowalleck","email":"jan.kowalleck@gmail.com"},{"name":"Alex Miller","email":"codex.nz@gmail.com"}],"dependencies":{"@cyclonedx/cyclonedx-library":"^2.0.0","commander":"^10.0.0","normalize-package-data":"^3||^4||^5","xmlbuilder2":"^3.0.2"},"devDependencies":{"@types/node":"ts5.0","@types/normalize-package-data":"^2.4.1","eslint":"^8.23.0","eslint-config-standard-with-typescript":"^34.0.0","eslint-plugin-header":"^3.1.1","eslint-plugin-simple-import-sort":"^10.0.0","fast-glob":"^3.2.11","imurmurhash":"^0.1.4","jest":"^29.5.0","jest-junit":"^16.0.0","npm-run-all":"^4.1.5","typescript":"^5.0.4"},"type":"commonjs","engines":{"node":">=14","npm":"6 - 9"},"directories":{"doc":"docs","src":"src","lib":"dist","test":"tests","example":"demo"},"bin":{"cyclonedx-npm":"bin/cyclonedx-npm-cli.js"},"main":"./dist/index.js","exports":"./dist/index.js","scripts":{"prepublish":"npm run build","prepublishOnly":"npm run build","lint":"tsc --noEmit","prebuild":"node -r fs -e 'fs.rmSync(`dist`,{recursive:true,force:true})'","build":"tsc -b ./tsconfig.json","cs-fix":"eslint --fix .","setup-tests":"echo 'noting yet'","test":"run-p --aggregate-output -lc test:*","test:jest":"jest","test:standard":"eslint .","dogfooding:npx":"npx .","dogfooding:npm-exec":"npm exec .","dogfooding:direct":"node -- bin/cyclonedx-npm-cli.js"},"jest-junit":{"suiteName":"jest tests","outputDirectory":"reports/jest","outputName":"tests.junit.xml"},"gitHead":"52a828194cae3ec5836eae6150cdec8ea045b5a0","_id":"@deluksic/cyclonedx-npm@1.14.0","_nodeVersion":"18.16.0","_npmVersion":"9.5.1","dist":{"integrity":"sha512-nFPpQHvTCWCxUnPnw4YFAZ2YlOCEk893Pd2bfq0ZCblRDx/9AeFhRjK7JRvKZTx3kNgl9TVw5TBF4stVbVzZUA==","shasum":"020bfb9ee361c6a1e952d1d868f8cedd9c86c8b5","tarball":"https://registry.npmjs.org/@deluksic/cyclonedx-npm/-/cyclonedx-npm-1.14.0.tgz","fileCount":15,"unpackedSize":68182,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIBcuSAlI6QO7Top2UC+EnADUHiSLTpPmPMbjCU2J5Iv9AiA/fnZuzrFfbRJLxQ1a2vOwtmnD07fyse76wl7WeqXDtw=="}]},"_npmUser":{"name":"deluksic","email":"deluksic@gmail.com"},"maintainers":[{"name":"deluksic","email":"deluksic@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/cyclonedx-npm_1.14.0_1687940824201_0.7125195142198102"},"_hasShrinkwrap":false}},"time":{"created":"2023-06-28T08:27:04.114Z","1.14.0":"2023-06-28T08:27:04.477Z","modified":"2023-06-28T08:27:04.725Z"},"maintainers":[{"name":"deluksic","email":"deluksic@gmail.com"}],"description":"Create CycloneDX Software Bill of Materials (SBOM) from NPM projects.","homepage":"https://github.com/CycloneDX/cyclonedx-node-npm#readme","keywords":["CycloneDX","SBOM","BOM","inventory","bill-of-materials","software-bill-of-materials","component","dependency","package-url","PURL","spdx","node","npm"],"repository":{"type":"git","url":"git+https://github.com/CycloneDX/cyclonedx-node-npm.git"},"contributors":[{"name":"Jan Kowalleck","email":"jan.kowalleck@gmail.com"},{"name":"Alex Miller","email":"codex.nz@gmail.com"}],"author":{"name":"Jan Kowalleck","email":"jan.kowalleck@gmail.com"},"bugs":{"url":"https://github.com/CycloneDX/cyclonedx-node-npm/issues"},"license":"Apache-2.0","readme":"[![shield_npm-version]][link_npm]\n[![shield_gh-workflow-test]][link_gh-workflow-test]\n[![shield_license]][license_file]  \n[![shield_website]][link_website]\n[![shield_slack]][link_slack]\n[![shield_groups]][link_discussion]\n[![shield_twitter-follow]][link_twitter]\n\n----\n\n# cyclonedx-npm\n\nCreate [CycloneDX] Software Bill of Materials (SBOM) from _[npm]_ projects.\n\nBased on [OWASP Software Component Verification Standard for Software Bill of Materials](https://scvs.owasp.org/scvs/v2-software-bill-of-materials/)'s\ncriteria, this tool is capable of producing SBOM documents almost passing Level-2 (only signing needs to be done externally).\n\nThe resulting SBOM documents follow [official specifications and standards](https://github.com/CycloneDX/specification), \nand might have properties following [`cdx:npm` Namespace Taxonomy](https://github.com/CycloneDX/cyclonedx-property-taxonomy/blob/main/cdx/npm.md)\n.\n\n## Requirements\n\n* `node` >= `14`\n* `npm` in range `6 - 9`\n\n## Installation\n\nThere are multiple methods for installing this tool:\n\n* As a global tool ala `npm`:\n\n  ```shell\n  npm install --global @cyclonedx/cyclonedx-npm\n  ```\n\n* As a global tool ala `npx`:\n\n  ```shell\n  npx --package @cyclonedx/cyclonedx-npm --call exit\n  ```\n\n* As a development dependency of the current projects:\n\n  ```shell\n  npm install --save-dev @cyclonedx/cyclonedx-npm\n  ```\n\n## Usage\n\nDepending on the installation method, the following describes the proper usage:\n\n* If installed as a global tool ala `npm`:\n\n  ```shell\n  cyclonedx-npm --help\n  ```\n\n* If installed as a global tool ala `npx`:  \n  — or —  \n  If installed as a development dependency of the current projects:\n\n  ```shell\n  npx @cyclonedx/cyclonedx-npm --help\n  ```\n\nThe help page:\n\n```text\nUsage: cyclonedx-npm [options] [--] [<package-manifest>]\n\nCreate CycloneDX Software Bill of Materials (SBOM) from Node.js NPM projects.\n\nArguments:\n  <package-manifest>        Path to project's manifest file.\n                            (default: \"package.json\" file in current working directory)\n\nOptions:\n  --ignore-npm-errors       Whether to ignore errors of NPM.\n                            This might be used, if \"npm install\" was run with \"--force\" or \"--legacy-peer-deps\".\n                            (default: false)\n  --package-lock-only       Whether to only use the lock file, ignoring \"node_modules\".\n                            This means the output will be based only on the few details in and the tree described by the \"npm-shrinkwrap.json\" or \"package-lock.json\", rather than the contents of \"node_modules\" directory.\n                            (default: false)\n  --omit <type...>          Dependency types to omit from the installation tree.\n                            (can be set multiple times)\n                            (choices: \"dev\", \"optional\", \"peer\", default: \"dev\" if the NODE_ENV environment variable is set to \"production\", otherwise empty)\n  --flatten-components      Whether to flatten the components.\n                            This means the actual nesting of node packages is not represented in the SBOM result.\n                            (default: false)\n  --short-PURLs             Omit all qualifiers from PackageURLs.\n                            This causes information loss in trade of shorter PURLs, which might improve digesting these strings.\n                            (default: false)\n  --spec-version <version>  Which version of CycloneDX spec to use.\n                            (choices: \"1.2\", \"1.3\", \"1.4\", default: \"1.4\")\n  --output-reproducible     Whether to go the extra mile and make the output reproducible.\n                            This requires more resources, and might result in loss of time- and random-based-values.\n                            (env: BOM_REPRODUCIBLE)\n  --output-format <format>  Which output format to use.\n                            (choices: \"JSON\", \"XML\", default: \"JSON\")\n  --output-file <file>      Path to the output file.\n                            Set to \"-\" to write to STDOUT.\n                            (default: write to STDOUT)\n  --validate                Validate resulting BOM before outputting. Validation is skipped, if requirements not met.\n                            (default: true)\n  --no-validate             Disable validation of resulting BOM.\n  --mc-type <type>          Type of the main component.\n                            (choices: \"application\", \"firmware\", \"library\", default: \"application\")\n  -V, --version             output the version number\n  -h, --help                display help for command\n```\n\n## Demo\n\nFor a demo of _cyclonedx-npm_ see the [demo project][demo_readme].\n\n## How it works\n\nThis tool utilizes _[npm]_ to collect evidences of installed packages/modules.\nRead more in the [dedicated docs](https://github.com/CycloneDX/cyclonedx-node-npm/tree/main/docs/how.md).\n\nThe appropriate _npm_ executable is detected automatically, yet can be overridden with the environment variable `npm_execpath`.  \nAutodetect: If called from `npm`/`npx` context, then the current _npm_ executable is utilized, otherwise it is managed by SHELL and PATH.\n\nThis tool does not do artificial deduplication.\nTherefore, if a component is installed multiple times, it appears multiple times in the SBOM result.\nRead more on the topic in the [dedicated docs \"Component Deduplication\"](https://github.com/CycloneDX/cyclonedx-node-npm/tree/main/docs/component_deduplication.md).\n\n## Internals\n\nThis tool utilizes the [CycloneDX library][cyclonedx-library] to generate the actual data structures, and serialize and validate them.  \nValidation requires [transitive optional dependencies](https://github.com/CycloneDX/cyclonedx-javascript-library/blob/main/README.md#optional-dependencies).\n\nThis tool does **not** expose any additional _public_ API or classes - all code is intended to be internal and might change without any notice during version upgrades.\n\n## Contributing\n\nFeel free to open issues, bugreports or pull requests.  \nSee the [CONTRIBUTING][contributing_file] file for details.\n\n## License\n\nPermission to modify and redistribute is granted under the terms of the Apache 2.0 license.  \nSee the [LICENSE][license_file] file for the full license.\n\n[license_file]: https://github.com/CycloneDX/cyclonedx-node-npm/blob/main/LICENSE\n[contributing_file]: https://github.com/CycloneDX/cyclonedx-node-npm/blob/main/CONTRIBUTING.md\n[demo_readme]: https://github.com/CycloneDX/cyclonedx-node-npm/blob/main/demo/README.md\n\n[CycloneDX]: https://cyclonedx.org/\n[npm]: http://www.npmjs.com/\n[cyclonedx-library]: https://www.npmjs.com/package/@cyclonedx/cyclonedx-library\n\n[shield_gh-workflow-test]: https://img.shields.io/github/actions/workflow/status/CycloneDX/cyclonedx-node-npm/nodejs.yml?branch=main&logo=GitHub&logoColor=white \"tests\"\n[shield_npm-version]: https://img.shields.io/npm/v/@cyclonedx/cyclonedx-npm?logo=npm&logoColor=white \"npm\"\n[shield_license]: https://img.shields.io/github/license/CycloneDX/cyclonedx-node-npm?logo=open%20source%20initiative&logoColor=white \"license\"\n[shield_website]: https://img.shields.io/badge/https://-cyclonedx.org-blue.svg \"homepage\"\n[shield_slack]: https://img.shields.io/badge/slack-join-blue?logo=Slack&logoColor=white \"slack join\"\n[shield_groups]: https://img.shields.io/badge/discussion-groups.io-blue.svg \"groups discussion\"\n[shield_twitter-follow]: https://img.shields.io/badge/Twitter-follow-blue?logo=Twitter&logoColor=white \"twitter follow\"\n\n[link_website]: https://cyclonedx.org/\n[link_gh-workflow-test]: https://github.com/CycloneDX/cyclonedx-node-npm/actions/workflows/nodejs.yml?query=branch%3Amain\n[link_npm]: https://www.npmjs.com/package/@cyclonedx/cyclonedx-npm\n[link_slack]: https://cyclonedx.org/slack/invite\n[link_discussion]: https://groups.io/g/CycloneDX\n[link_twitter]: https://twitter.com/CycloneDX_Spec\n","readmeFilename":"README.md"}