{"_id":"@dshbuilds/gitlab-npm-audit-parser","_rev":"1-a9e135cfa804ce768bd27b2c5a470709","name":"@dshbuilds/gitlab-npm-audit-parser","dist-tags":{"latest":"1.0.3"},"versions":{"1.0.2":{"name":"@dshbuilds/gitlab-npm-audit-parser","version":"1.0.2","description":"NPM Audit parser for GitLab dependency scanning","bin":{"gitlab-npm-audit-parser":"dist/parse.js"},"main":"dist/parse.js","directories":{"test":"test"},"scripts":{"build":"npm run --silent build:prod --","build-watch":"webpack --mode=production --watch","build:prod":"webpack --mode=production --node-env=production","prepublishOnly":"npm test && eslint . --ext md,mdx","lint":"eslint . --ext js,md,mdx","format":"npm run --silent lint -- --fix","pretest":"npm run --silent build","test":"npm run --silent test:prod --","test-debug":"jest --runInBand","test:prod":"jest"},"repository":{"type":"git","url":"git+ssh://git@github.com/dansholds/gitlab-npm-audit-parser.git"},"keywords":["gitlab","npm","CI","dependency-scan","audit","vulnerabilities","report","json","dshbuilds","convert"],"author":{"name":"Maxime Gibeau"},"contributors":[{"name":"Eric Peterson","email":"eric@elpete.com","url":"https://github.com/elpete"},{"name":"dshbuilds","email":"dshbuilds@gmail.com","url":"https://github.com/dshbuilds"}],"engines":{"node":">=10.24","npm":">=7.0"},"jest":{"setupFilesAfterEnv":["<rootDir>/test/setupTests.js"],"transformIgnorePatterns":[],"watchPathIgnorePatterns":["<rootDir>/(?!(dist|test)/)"]},"license":"MIT","devDependencies":{"@babel/core":"^7.14.8","@babel/preset-env":"^7.14.8","@gitlab-org/security-report-schemas":"^14.0.3","babel-jest":"^27.0.6","commander":"^7.2.0","eslint":"^7.26.0","eslint-config-airbnb-base":"^14.2.1","eslint-config-prettier":"^8.3.0","eslint-plugin-import":"^2.23.2","eslint-plugin-jest":"^24.3.6","eslint-plugin-mdx":"^1.0.1","eslint-plugin-prettier":"^3.4.0","eslint-webpack-plugin":"^3.0.1","jest":"^27.0.6","jsonschema":"^1.4.0","npm-audit-v1":"npm:npm-audit-report@^1.3.3","npm-audit-v2":"npm:npm-audit-report@^2.1.4","prettier":"^2.3.0","remark-lint-alphabetize-lists":"^3.0.0","remark-lint-no-dead-urls":"^1.1.0","remark-preset-lint-consistent":"^4.0.0","remark-preset-lint-markdown-style-guide":"^4.0.0","remark-preset-lint-recommended":"^5.0.0","remark-preset-prettier":"^0.5.1","replace-in-file":"^6.2.0","webpack":"^5.74.0","webpack-cli":"^4.10.0","webpack-shebang-plugin":"^1.1.4"},"gitHead":"a6a35b1ea034f6efe24c407efbd10ad9302cb8f3","bugs":{"url":"https://github.com/dansholds/gitlab-npm-audit-parser/issues"},"homepage":"https://github.com/dansholds/gitlab-npm-audit-parser#readme","_id":"@dshbuilds/gitlab-npm-audit-parser@1.0.2","_nodeVersion":"18.9.0","_npmVersion":"8.19.1","dist":{"integrity":"sha512-TVcN6GMwuIfTCLSWcse8yvHw6B+XHJgeFHHXJLrHqscbnpxlZpN+QgPFDVz4ikrpizolCwpq+9IFL/YhUPpIdw==","shasum":"a8719225acb6d8168e5ca20734f5471e7317fdc8","tarball":"https://registry.npmjs.org/@dshbuilds/gitlab-npm-audit-parser/-/gitlab-npm-audit-parser-1.0.2.tgz","fileCount":3,"unpackedSize":137541,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQC1YKz0+iUR1K38qKMEsQ0JFy61+f3flFv9Py7LYeVUngIgc6qrKKwC3Io+Q9x9VqloDoESVyvw1L+OU6mr2jip7nM="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjNblJACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmp5Rg/+JFpNKAzCFNBsi5YuXd5yPEWlKBaIxjUNelWhqI9igX13hl6H\r\nV8k6qSqcHyF+WHHb1kEgWAcSGyUS4OcSjtjQ9u0LLI2thzM7/uzZHIW0tHd6\r\n+noOTAvdEz0fHBVpz4YXHSQX5vJ7T7Ctwr6S7Yr+TNBTIiv2AXaD/z/e7npf\r\nUceMJnPzXLkRFnFtZlrVonlKDCjyroNn0g6wo7snk4s0vI5W/gXFXFxdvTtA\r\nt1/Wvu9uB7/hnB/gm2orWPQU2iKhfgC9J+h4rpooPouAGsvW0EoyboTJczpi\r\nr1Rk6nv7K9YcSBayYHyMfYlCtn5+dRs3uvFmJvHqbDvV2d3y30xNjiX1KYdN\r\nt7FTeMWC4tsyj4+KnsrpxGYMDLl9iXz4ZdVcq6wa7vs5C08bsO6k/+nBzkiT\r\nSmPJlCWTtB4lKF8ioFSXmFObBxUXwiLgEYK7b1j8Y4Bd9tio4+XfZqqnIaSw\r\nbQUMINPtAyWZftu4PsrPzH+9XvaAzPj+/o+B5tqVhtokUpjUGFGiX2vECRCD\r\n3PWu0EAZwyw+fFNgoWj9r6Y/IwzRcv6/lZ1qym0z1scGyhCXPqlaRlfUTuqD\r\nL2aUGeDk0EnTtqPwH3+LZzCBJbpcV6ou0p080BGsO94s2rgV9Qyoq01YkKc5\r\nIGnFlsRRo3Ud68c+ovAOaw4L/MYW72HewD4=\r\n=qNZJ\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"dshbuilds","email":"dshbuilds@gmail.com"},"maintainers":[{"name":"dshbuilds","email":"dshbuilds@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gitlab-npm-audit-parser_1.0.2_1664465225540_0.7832257422060016"},"_hasShrinkwrap":false},"1.0.3":{"name":"@dshbuilds/gitlab-npm-audit-parser","version":"1.0.3","description":"NPM Audit parser for GitLab dependency scanning","bin":{"gitlab-npm-audit-parser":"dist/parse.js"},"main":"dist/parse.js","directories":{"test":"test"},"scripts":{"build":"npm run --silent build:prod --","build-watch":"webpack --mode=production --watch","build:prod":"webpack --mode=production --node-env=production","prepublishOnly":"npm test && eslint . --ext md,mdx","lint":"eslint . --ext js,md,mdx","format":"npm run --silent lint -- --fix","pretest":"npm run --silent build","test":"npm run --silent test:prod --","test-debug":"jest --runInBand","test:prod":"jest"},"repository":{"type":"git","url":"git+ssh://git@github.com/dansholds/gitlab-npm-audit-parser.git"},"keywords":["gitlab","npm","CI","dependency-scan","audit","vulnerabilities","report","json","dshbuilds","convert"],"author":{"name":"Maxime Gibeau"},"contributors":[{"name":"Eric Peterson","email":"eric@elpete.com","url":"https://github.com/elpete"},{"name":"dshbuilds","email":"dshbuilds@gmail.com","url":"https://github.com/dshbuilds"}],"engines":{"node":">=10.24","npm":">=7.0"},"jest":{"setupFilesAfterEnv":["<rootDir>/test/setupTests.js"],"transformIgnorePatterns":[],"watchPathIgnorePatterns":["<rootDir>/(?!(dist|test)/)"]},"license":"MIT","devDependencies":{"@babel/core":"^7.14.8","@babel/preset-env":"^7.14.8","@gitlab-org/security-report-schemas":"^14.0.3","babel-jest":"^27.0.6","commander":"^7.2.0","eslint":"^7.26.0","eslint-config-airbnb-base":"^14.2.1","eslint-config-prettier":"^8.3.0","eslint-plugin-import":"^2.23.2","eslint-plugin-jest":"^24.3.6","eslint-plugin-mdx":"^1.0.1","eslint-plugin-prettier":"^3.4.0","eslint-webpack-plugin":"^3.0.1","jest":"^27.0.6","jsonschema":"^1.4.0","npm-audit-v1":"npm:npm-audit-report@^1.3.3","npm-audit-v2":"npm:npm-audit-report@^2.1.4","prettier":"^2.3.0","remark-lint-alphabetize-lists":"^3.0.0","remark-lint-no-dead-urls":"^1.1.0","remark-preset-lint-consistent":"^4.0.0","remark-preset-lint-markdown-style-guide":"^4.0.0","remark-preset-lint-recommended":"^5.0.0","remark-preset-prettier":"^0.5.1","replace-in-file":"^6.2.0","webpack":"^5.74.0","webpack-cli":"^4.10.0","webpack-shebang-plugin":"^1.1.4"},"gitHead":"d0aa55cc4a8cfff7172f8f2ffcd5751cbc618901","bugs":{"url":"https://github.com/dansholds/gitlab-npm-audit-parser/issues"},"homepage":"https://github.com/dansholds/gitlab-npm-audit-parser#readme","_id":"@dshbuilds/gitlab-npm-audit-parser@1.0.3","_nodeVersion":"18.9.0","_npmVersion":"8.19.1","dist":{"integrity":"sha512-P/NdblKi4zWCsX9A4vmlVv4ZuabjdsCurpgqwqtq+s7IaSA0N9HOeadxMKvsD8wr88i+ZWuUE1QsAsePH4XsQQ==","shasum":"38904a499588f34292d553a16a72ef74cc87c20d","tarball":"https://registry.npmjs.org/@dshbuilds/gitlab-npm-audit-parser/-/gitlab-npm-audit-parser-1.0.3.tgz","fileCount":3,"unpackedSize":137541,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIHztUjvOwNLy7pAz5WjDlTSNSy0uvREhXi5SLfpVV4xEAiBf9K+5AG7bY8CWa1gl2S4FO6WM9sVq5M5GkJfc6sB33g=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjNb2uACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrIkg//am2I/CQUHKBC0p7VAxCTu0t8CuC79Nxm3R2LReqTPoj/UE4r\r\neTH8nsnrl6gFy1QdDMo4T80qhHWB22usG+NCLWrCYSoWbX0IgduQYaLeAiaq\r\noIghFqPldwA7xnz8MsnGaumzFjnUsb3cMgpiDs9zMvwO2cvuxxvOPPZejmES\r\naV18zWRmhZ9yEngevkUNspROG1BjJzY6d1ZqZXE8RlOlqMDtriZsHrxH2ClB\r\n6rQVXBob1foVlChqiMcFfLcnwaxrFv4K9l89tcOV0GMZFOB5BfpF9YuCBgxl\r\npRoRnS5weMN3F+5JRrTIcTV7cg2YW4TZ1IbnB/h+dZCLw4jk/ejAQ/N+rTDT\r\nMunQdfVbDZ2IJ+mOP2Z77is4ACAHeqXrwK6pfkNp1jRXwHXsYodI6U9jejXY\r\nerlRaxdQONPCIVsEosAn0IxLTsC9l9YtGMeGZ8sa3kiymbWRuHuil2w76wWy\r\n/Uqp8lLwqdPZHcteiyUVuETaPXN0RS48BBHxkb+svLqbHKyLzl6do3HwybTD\r\nRZYvEMh6wz2O93SFlcZuJLhAUC2rHWMzPRF+sQmTgFuPlWvme/DMw7FB3orR\r\nrKWhaWXHz0B0m1Lys66V1IOac0kpQTgORl9FdSq7cEcSelWq2pI4S9j6kqf7\r\njKKoVp3vj/X1CzyZj/yYul7yayGoIrXYgvo=\r\n=sTYc\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"dshbuilds","email":"dshbuilds@gmail.com"},"maintainers":[{"name":"dshbuilds","email":"dshbuilds@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gitlab-npm-audit-parser_1.0.3_1664466350193_0.980287552768695"},"_hasShrinkwrap":false}},"time":{"created":"2022-09-29T15:27:05.479Z","1.0.2":"2022-09-29T15:27:05.766Z","modified":"2022-09-29T15:45:50.592Z","1.0.3":"2022-09-29T15:45:50.512Z"},"maintainers":[{"name":"dshbuilds","email":"dshbuilds@gmail.com"}],"description":"NPM Audit parser for GitLab dependency scanning","homepage":"https://github.com/dansholds/gitlab-npm-audit-parser#readme","keywords":["gitlab","npm","CI","dependency-scan","audit","vulnerabilities","report","json","dshbuilds","convert"],"repository":{"type":"git","url":"git+ssh://git@github.com/dansholds/gitlab-npm-audit-parser.git"},"contributors":[{"name":"Eric Peterson","email":"eric@elpete.com","url":"https://github.com/elpete"},{"name":"dshbuilds","email":"dshbuilds@gmail.com","url":"https://github.com/dshbuilds"}],"author":{"name":"Maxime Gibeau"},"bugs":{"url":"https://github.com/dansholds/gitlab-npm-audit-parser/issues"},"license":"MIT","readme":"# GitLab parser for NPM Audit\n\n<p align=\"center\">\n  <a href=\"https://www.npmjs.com/package/@dshbuilds/gitlab-npm-audit-parser\">\n    <img src=\"https://img.shields.io/npm/v/@dshbuilds/gitlab-npm-audit-parser\" />\n  </a>\n  <img src=\"https://img.shields.io/npm/l/@dshbuilds/gitlab-npm-audit-parser?color=yellow\">\n  <a href=\"https://github.com/dansholds/gitlab-npm-audit-parser/blob/main/CHANGELOG.md\">\n    <img src=\"https://img.shields.io/badge/&#9741-changelog-yellow\">\n  </a>\n  <a href=\"https://github.com/dansholds/gitlab-npm-audit-parser/actions/workflows/ci.yml\">\n    <img src=\"https://github.com/dansholds/gitlab-npm-audit-parser/actions/workflows/ci.yml/badge.svg\" >\n  </a>\n  <a href=\"https://github.com/dansholds/gitlab-npm-audit-parser/issues\">\n    <img src=\"https://img.shields.io/github/issues/dansholds/gitlab-npm-audit-parser\">\n  </a>\n  <img src=\"https://img.shields.io/badge/dependencies-0-success\">\n  <img src=\"https://img.shields.io/snyk/vulnerabilities/npm/@dshbuilds/gitlab-npm-audit-parser\">\n</p>\n<p align=\"center\">\n  <img src=\"https://img.shields.io/npm/dependency-version/@dshbuilds/gitlab-npm-audit-parser/dev/webpack\">\n  <img src=\"https://img.shields.io/node/v-lts/@dshbuilds/gitlab-npm-audit-parser?color=blue\">\n  <img src=\"https://img.shields.io/bundlephobia/min/@dshbuilds/gitlab-npm-audit-parser\" />\n  <img src=\"https://img.shields.io/github/last-commit/dansholds/gitlab-npm-audit-parser\">\n</p>\n\n    Usage: gitlab-npm-audit-parser [options]\n\n    Input: Stdin via pipe\n      npm audit --json | gitlab-npm-audit-parser ...\n      cat <file> | gitlab-npm-audit-parser ...\n\n    Options:\n\n      -V, --version     output the version number\n      -o, --out <path>  output filename, defaults to gl-dependency-scanning-report.json\n      -h, --help        output usage information\n\n## Package Objective\n\nPerform the data translation from an `npm audit --json` report output to the\nGitLab.com standardized JSON schema format specifically for ingest of dependency\nscanning reports of a project.\n\n## Why?\n\nGitLab requires a common schema to ingest scanning reports from multiple\ndifferent dependency auditing tools across different languages. In the\nJavaScript/TypeScript ecosystem, most of us use `npm audit` to verify project\ndependencies but the JSON report is not ingestable by GitLab.com. It requires\nthis package as middleware to translate an `npm audit --json` report into the\nstandard dependency audit schema before it can be uploaded and ingested as a\ndependency_scanning artifact. Ingested artifacts can then be used as data\nsources to generate interactive content embedded in a pipeline results view or\nMerge Request (MR) webpage.\n\n**Why this library?** Because it's fast! We used\n[Webpack](https://github.com/webpack/webpack) to generate a self-contained\nbundle which means we have **0 dependencies** to download for production! With\nNPX you can use this library direct from the cloud with minimal delay at 15.7KB\npackage size. We use Gitlab's published schema repository directly to help\nconstruct the output code. For Developers, we also employ linting & automated\ntesting on the codebase to improve the development experience.\n\n## Compatibility\n\n| INGEST                  | SUPPORTED? | OUTPUT                                                 |\n| ----------------------- | :--------: | ------------------------------------------------------ |\n| npm-audit-report@^1.0.0 |    yes     | JSON file (dependency-scanning-report-format\\@v14.0.3) |\n| npm-audit-report@^2.0.0 |    yes     | JSON file (dependency-scanning-report-format\\@v14.0.3) |\n\nGitLab.org publishes their security report format to their own Package\nRepository which is attached to their schema generation repository:\n[gitlab-org/security-report-schemas](https://gitlab.com/gitlab-org/security-products/security-report-schemas).\nThis project targets the currently released report-format for Dependency\nScanning.\n\n## How to use\n\nInstall this package into your devDependencies or use `npx` directly to download\nthe package at runtime. If you opt to download for use at run time, make sure to\ninclude the correct scope name for the package since there are multiple versions\nof this package on npmjs.com.\n\n_I recommend the runtime option since this package is only needed in a GitLab\nspecific pipeline and not necessary to be locally installed for developer use._\n\n```sh\n# 1. Downloads at runtime use\nnpm audit --json | npx @dshbuilds/gitlab-npm-audit-parser -o gl-dependency-scanning.json\n\n# 2. Install in devDependencies\nnpm install --save-dev @dshbuilds/gitlab-npm-audit-parser\n```\n\nAdd the following job to `.gitlab-ci.yml`. If you used #2 and it is in your\ndevDependencies you may remove the `@<scope>` prefix from the following.\n\n```yaml\ndependency scanning:\n  image: node:10-alpine\n  script:\n    - npm ci\n    - npm audit --json | npx @dshbuilds/gitlab-npm-audit-parser -o\n      gl-dependency-scanning.json\n  artifacts:\n    reports:\n      dependency_scanning: gl-dependency-scanning.json\n```\n\nNOTE: If you use a `npm run-script` to call `npm audit` due to set project\nparameters, this library will ignore any prefixed stdout data prior to the first\nopen bracket for the JSON output. This way `npm run --silent` is no longer\nrequired.\n\n## Vulnerability Report\n\n| Vulnerability |     PKG      | Category |     In Production Pkg?      | Notes                                                                 |\n| ------------- | :----------: | :------: | :-------------------------: | --------------------------------------------------------------------- |\n| RegExp DoS    | trim\\@<0.0.3 |   High   | No _(DevDependency/Linter)_ | waiting for remark-parse\\@^9.x.x release, owner will not patch v8.0.3 |\n\n## Contributors\n\n### Development Environment\n\n- Use `nvm` for node version management (see `.nvmrc` for version requirement)\n- Use latest npm version via `nvm install-latest-npm`\n\n### Guidelines\n\n- Code (including Markdown) must pass a linting checks\n- Developmental repository must be compatible with NodeJS v12 LTS & `npm@^7.0.0`\n- Distribution build must be compatible with v10\n- Must have successful build & pass all test cases in both Node.js v10 LTS, v12\n  LTS, & v14 LTS\n- Releases will have all non-breaking changes in dependencies up-to-date\n\n### Test\n\n```sh\n# Production build (CLI bundle) & Executes all test cases\nnpm run test:prod\n\n# Verifies build process once, then runs tests against local files\nnpm test\nnpm run test:dev   # enable test watch mode\n\n# Monitor build process & interactive lint\nnpm run build-watch\n```\n\n## Examples\n\n| #   | INGEST FILE             |     | OUTPUT FILE                         |\n| --- | ----------------------- | --- | ----------------------------------- |\n| 1.  | `./test/v1_report.json` | =>  | `./test/snapshots/GL-report.1.json` |\n| 2.  | `./test/v2_report.json` | =>  | `./test/snapshots/GL-report.2.json` |\n\n## Future Features\n\n- Add `-i|--in|--input <file>` option for handling file input\n\n- Add support for input redirector `<(cat file.txt)`.\n\n- Add testing, dependency, & closer integration with `npm-audit-report` library\n\n- Configure a bot to monitor changes/updates to schema & audit reporter\n  repository\n\n## Extras\n\n**COMING SOON!**\n[gitlab-depscan-merger](https://github.com/dshbuilds/gitlab-depscan-merger): a\nsolution to create 1 ingestable dependency_scanning report from multiple audit\nreports overcoming the GitLab pipeline limitation.\n\nCheck out my other projects at [@dshbuilds](https://github.com/dshbuilds) on\nGitHub.com\n","readmeFilename":"README.md"}