-
-
Notifications
You must be signed in to change notification settings - Fork 29
v1.0-dev #1
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
v1.0-dev #1
Changes from 14 commits
Commits
Show all changes
114 commits
Select commit
Hold shift + click to select a range
8e2fed3
v1.0 kickoff
jkowalleck a2c3996
v1.0 initial setup
jkowalleck 59be04c
reproducible demos basics
jkowalleck e191e56
Merge pull request #3 from CycloneDX/basic-integration-tests
jkowalleck 4a49e8d
docs: fix typos and instructions
jkowalleck a4195d9
implement cli options
jkowalleck 0583fe5
implement cli options
jkowalleck be7355f
implement cli options
jkowalleck 69f54dd
implement cli options
jkowalleck a206f37
cli encapsulation
jkowalleck 3b14d88
publish shrinkwrap
jkowalleck 0af9090
Merge pull request #7 from CycloneDX/publish-shrinkwrap
jkowalleck cedde35
initial implementation (#5)
jkowalleck 0348c00
docs (#54)
jkowalleck 0852a11
docs: bundled dependencies (#13)
jkowalleck d433852
fix typo
jkowalleck 9ebe2c1
fix typo
jkowalleck 052d66e
bumped @cyclonedx/cyclonedx-library 1.3.1 -> 1.3.2
jkowalleck 0720925
chore: clean up todos
jkowalleck 620fed2
prefix nested component's bomRef (#55)
jkowalleck 3fdb7ff
bump @cyclonedx/cyclonedx-library 1.3.2 -> 1.3.3
jkowalleck 4221912
announce beta stat
jkowalleck 412eeff
bump @cyclonedx/cyclonedx-library 1.3.3 -> 1.3.4
jkowalleck bd5440a
cleanup research & development file
jkowalleck cbee2dd
demo: workspaces and insights (#57)
jkowalleck 0c34ed4
custom property to indicate devDependencies (#58)
jkowalleck 003f066
shorter fallback bomrefs (#59)
jkowalleck d777743
Beta release prep (#60)
jkowalleck 18fc1c1
chore: tighten release process
jkowalleck c72320e
chore: allow release without preid
jkowalleck 58a55f2
1.0.0-beta.1
jkowalleck 3f5314f
chore: allow release without preid
jkowalleck 9aa1058
chore: allow release without preid
jkowalleck 01434fd
less debug (#69)
jkowalleck f8290b6
1.0.0-beta.2
jkowalleck ebb594d
docs: known dirs and trim node version
jkowalleck 435d6ca
use lock instead of shrinkwrap (#72)
jkowalleck cc1bcd4
prepare 1.0.0-beta.3
jkowalleck a848867
1.0.0-beta.3
jkowalleck 3ed8f01
fix: runner on windows should be working (#74)
jkowalleck cb7c22e
fix: make debug output clearer (#75)
jkowalleck df3ce55
improve-error-detection (#76)
jkowalleck e25d5b9
chore: prepare v1.0.0-beta.4
jkowalleck 8c8ea71
1.0.0-beta.4
jkowalleck 07edf6f
docs: descrbe lockfile situation
jkowalleck fb6955c
docs: npm property taxonomy
jkowalleck e579907
integration test for the cli (#56)
jkowalleck 6f75568
support node14 (#80)
jkowalleck d01fa95
docs: explain call for local install and usage better (#105)
jkowalleck a340d16
chore(deps-dev): bump typescript from 4.7.4 to 4.8.2 (#86)
dependabot[bot] e322dc0
chore(deps-dev): bump @types/node from 18.7.11 to 18.7.14 (#104)
dependabot[bot] 69d62bd
docs: improved the HISTORY
jkowalleck bbd821b
chore(deps-dev): bump jest-junit from 14.0.0 to 14.0.1 (#87)
dependabot[bot] df4630d
fix: find npm when run by npx (#91)
Codex- 1457be2
style: block-comment for `eslint-disable-next-line`
jkowalleck 08c82cc
chore(deps): bump @types/yargs from 17.0.11 to 17.0.12 (#98)
dependabot[bot] 9fe24cd
chore(deps): bump caniuse-lite from 1.0.30001382 to 1.0.30001388 (#94)
dependabot[bot] ace774b
chore(deps): bump @types/babel__traverse from 7.18.0 to 7.18.1 (#95)
dependabot[bot] 4c6ca88
chore(deps): bump @sinclair/typebox from 0.24.28 to 0.24.34 (#99)
dependabot[bot] b165f16
chore(deps): bump update-browserslist-db from 1.0.5 to 1.0.7 (#100)
dependabot[bot] 510074d
chore(deps): bump es-abstract from 1.20.1 to 1.20.2 (#103)
dependabot[bot] 2280472
chore(deps): bump eslint-plugin-react from 7.30.1 to 7.31.4 (#102)
dependabot[bot] b49270a
chore(deps): bump electron-to-chromium from 1.4.227 to 1.4.241 (#101)
dependabot[bot] 2da5d20
chode(deps): bump dependencies (#106)
jkowalleck 0fd07e9
chore: prepare v1.0.0-beta.5
jkowalleck d130de8
1.0.0-beta.5
jkowalleck 64b7dc4
docs: made install instructions more clear and precise
jkowalleck 48b0d40
feat: add CLI switch `--ignore-npm-errors` to ignore/suppress NPM err…
jkowalleck 35fd0c8
chore: prepare v1.0.0-beta.6
jkowalleck 773e7b9
1.0.0-beta.6
jkowalleck 7a8d9d0
feat: shorter purls (#108)
jkowalleck 75dd824
chore: prepare v1.0.0-beta.7
jkowalleck d4a29f0
1.0.0-beta.7
jkowalleck 8e5927a
improve usage of `npm_execpath` (#110)
jkowalleck bd0ee3a
chore: remove unused dependency `packageurl-js`
jkowalleck 59e4d65
QA: eslint plugins (#111)
jkowalleck afeb123
chore(deps): bump @cyclonedx/cyclonedx-library from 1.4.0 to 1.4.1 (#…
dependabot[bot] 4cac14d
chore(deps-dev): bump @types/node from 18.7.15 to 18.7.16 (#118)
dependabot[bot] 2a47f5d
chore(deps): bump ci-info from 3.3.2 to 3.4.0 (#116)
dependabot[bot] 73f1544
chore(deps): bump @sinclair/typebox from 0.24.35 to 0.24.39 (#115)
dependabot[bot] 705a23b
chore(deps): bump caniuse-lite from 1.0.30001390 to 1.0.30001393 (#112)
dependabot[bot] 83b9e36
chore(deps): bump electron-to-chromium from 1.4.242 to 1.4.247 (#114)
dependabot[bot] 42da763
chore(deps-dev): bump typescript from 4.8.2 to 4.8.3 (#117)
dependabot[bot] 286e3ab
chore(deps-dev): bump fast-glob from 3.2.11 to 3.2.12 (#119)
dependabot[bot] d28be5b
docs: write HISTORY
jkowalleck 1b9a1c8
chore: prepare v1.0.0-beta.8
jkowalleck fc8f5c5
1.0.0-beta.8
jkowalleck f24e97e
Demo example results (#123)
jkowalleck c48eb66
chore(deps): bump @cyclonedx/cyclonedx-library from 1.4.1 to 1.4.2 (#…
dependabot[bot] 203f592
chore(deps): bump packageurl-js from 0.0.7 to 1.0.0 (#120)
dependabot[bot] 4067a6a
chore(deps): bump @cyclonedx/cyclonedx-library from 1.4.2 to 1.5.1 (#…
dependabot[bot] 97c3848
chore(deps): bump eslint-plugin-n from 15.2.5 to 15.3.0 (#157)
dependabot[bot] 3848e82
chore(deps-dev): bump @types/node from 18.7.16 to 18.7.19 (#155)
dependabot[bot] 9b63150
chore(deps): bump @typescript-eslint/parser from 5.36.2 to 5.38.0 (#151)
dependabot[bot] f07d26b
chore(deps): bump @typescript-eslint/eslint-plugin from 5.36.2 to 5.3…
dependabot[bot] 46a1355
chore(deps): bump @babel/helper-compilation-targets (#126)
dependabot[bot] a98e7fb
chore(deps): bump @babel/traverse from 7.19.0 to 7.19.1 (#127)
dependabot[bot] 30708ee
chore(deps-dev): bump eslint-config-standard-with-typescript (#129)
dependabot[bot] 7183b45
chore(deps): bump @babel/parser from 7.19.0 to 7.19.1 (#131)
dependabot[bot] 3787f8c
chore(deps): bump get-intrinsic from 1.1.2 to 1.1.3 (#132)
dependabot[bot] 250d549
chore(deps): bump @babel/helper-validator-identifier (#133)
dependabot[bot] 66943b2
chore(deps): bump @eslint/eslintrc from 1.3.1 to 1.3.2 (#134)
dependabot[bot] ecf978d
chore(deps): bump @babel/compat-data from 7.19.0 to 7.19.1 (#135)
dependabot[bot] 0bb3a5d
chore(deps): bump update-browserslist-db from 1.0.7 to 1.0.9 (#138)
dependabot[bot] c0380eb
chore(deps): bump @sinclair/typebox from 0.24.39 to 0.24.42 (#140)
dependabot[bot] 27e56a8
chore(deps): bump es-abstract from 1.20.2 to 1.20.3 (#156)
dependabot[bot] da31755
chore(deps): bump electron-to-chromium from 1.4.247 to 1.4.260 (#154)
dependabot[bot] 16492aa
chore(deps): bump @humanwhocodes/config-array from 0.10.4 to 0.10.5 (…
dependabot[bot] 28787ad
chore(deps): bump fb-watchman from 2.0.1 to 2.0.2 (#152)
dependabot[bot] 431a17f
chore(deps): bump caniuse-lite from 1.0.30001393 to 1.0.30001410 (#149)
dependabot[bot] 6207984
chore(deps): bump @types/yargs from 17.0.12 to 17.0.13 (#147)
dependabot[bot] b163380
chore(deps): bump @types/babel__traverse from 7.18.1 to 7.18.2 (#145)
dependabot[bot] 7346bb5
chore(deps): bump @types/prettier from 2.7.0 to 2.7.1 (#148)
dependabot[bot] 9229c4e
chore(deps-dev): bump eslint from 8.23.0 to 8.24.0 (#150)
dependabot[bot] File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,27 @@ | ||
| # EditorConfig is awesome: https://EditorConfig.org | ||
|
|
||
| root = true | ||
|
|
||
| [*] | ||
| end_of_line = lf | ||
| insert_final_newline = true | ||
|
|
||
| [*.md] | ||
| # trailing white spaces are used for linebreaks in paragraphs. | ||
| trim_trailing_whitespace = false | ||
|
|
||
| [*.{ts,js,cjs,mjs}] | ||
| charset = utf-8 | ||
| end_of_line = lf | ||
| indent_style = space | ||
| indent_size = 2 | ||
| trim_trailing_whitespace = true | ||
| insert_final_newline = true | ||
|
|
||
| [*.{json,cjson,cjsn}] | ||
| charset = utf-8 | ||
| end_of_line = lf | ||
| indent_style = space | ||
| indent_size = 2 | ||
| trim_trailing_whitespace = true | ||
| insert_final_newline = true |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,5 @@ | ||
| /dist/** | ||
| /dist.*/** | ||
| /node_modules/** | ||
|
|
||
| !/src/** |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,49 @@ | ||
| 'use strict' | ||
| /*! | ||
| This file is part of CycloneDX generator for NPM projects. | ||
|
|
||
| Licensed under the Apache License, Version 2.0 (the "License"); | ||
| you may not use this file except in compliance with the License. | ||
| You may obtain a copy of the License at | ||
|
|
||
| http://www.apache.org/licenses/LICENSE-2.0 | ||
|
|
||
| Unless required by applicable law or agreed to in writing, software | ||
| distributed under the License is distributed on an "AS IS" BASIS, | ||
| WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. | ||
| See the License for the specific language governing permissions and | ||
| limitations under the License. | ||
|
|
||
| SPDX-License-Identifier: Apache-2.0 | ||
| Copyright (c) OWASP Foundation. All Rights Reserved. | ||
| */ | ||
|
|
||
| /** | ||
| * @see {@link https://eslint.org/} | ||
| * @type {import('eslint').Linter.Config} | ||
| */ | ||
| module.exports = { | ||
| root: true, | ||
| // see https://github.com/standard/ts-standard | ||
| extends: 'standard-with-typescript', | ||
| parserOptions: { | ||
| project: './tsconfig.json' | ||
| }, | ||
| env: { | ||
| node: true, | ||
| browser: false | ||
| }, | ||
| overrides: [ | ||
| { | ||
| files: [ | ||
| '*.spec.*', | ||
| '*.test.*' | ||
| ], | ||
| env: { | ||
| node: true, | ||
| jest: true, | ||
| browser: false | ||
| } | ||
| } | ||
| ] | ||
| } |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,3 @@ | ||
|
|
||
| tsconfig.json linguist-language=JSON-with-Comments | ||
| tsconfig.*.json linguist-language=JSON-with-Comments |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,27 @@ | ||
| # https://help.github.com/github/administering-a-repository/configuration-options-for-dependency-updates | ||
|
|
||
| version: 2 | ||
| updates: | ||
| - package-ecosystem: 'npm' | ||
| directory: '/' | ||
| schedule: | ||
| interval: 'weekly' | ||
| day: 'saturday' | ||
| allow: | ||
| - dependency-type: 'all' | ||
| versioning-strategy: 'auto' | ||
| labels: [ 'dependencies' ] | ||
| commit-message: | ||
| prefix: 'chore' ## prefix maximum string length of 15 | ||
| include: 'scope' | ||
| open-pull-requests-limit: 999 | ||
| - package-ecosystem: 'github-actions' | ||
| directory: '/' | ||
| schedule: | ||
| interval: 'weekly' | ||
| day: 'saturday' | ||
| labels: [ 'dependencies' ] | ||
| commit-message: | ||
| prefix: 'chore' ## prefix maximum string length of 15 | ||
| include: 'scope' | ||
| open-pull-requests-limit: 999 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,115 @@ | ||
| # For details of what checks are run for PRs please refer below | ||
| # docs: https://docs.github.com/en/actions/reference/workflow-syntax-for-github-actions | ||
|
|
||
| name: Node CI | ||
|
|
||
| on: | ||
| push: | ||
| branches: ["master", "1.0-dev" ] | ||
| pull_request: | ||
| workflow_dispatch: | ||
|
|
||
|
|
||
| env: | ||
| REPORTS_DIR: CI_reports | ||
| NODE_ACTIVE_LTS: "16" # https://nodejs.org/en/about/releases/ | ||
|
|
||
| jobs: | ||
| build: | ||
| name: build | ||
| runs-on: "ubuntu-latest" | ||
| timeout-minutes: 10 | ||
| steps: | ||
| - name: Checkout | ||
| # see https://github.com/actions/checkout | ||
| uses: actions/checkout@v3 | ||
| - name: Setup Node.js ${{ env.NODE_ACTIVE_LTS }} | ||
| # see https://github.com/actions/setup-node | ||
| uses: actions/setup-node@v3 | ||
| with: | ||
| node-version: ${{ env.NODE_ACTIVE_LTS }} | ||
| cache: "npm" | ||
| cache-dependency-path: | | ||
| **/npm-shrinkwrap.json | ||
| **/package-lock.json | ||
| - name: setup project | ||
| run: npm ci --ignore-scripts | ||
| - name: build | ||
| run: npm run build | ||
| - name: artifact build result | ||
| # see https://github.com/actions/upload-artifact | ||
| uses: actions/upload-artifact@v3 | ||
| with: | ||
| name: dist | ||
| path: dist | ||
| if-no-files-found: error | ||
| standards: | ||
| name: Standards | ||
| timeout-minutes: 30 | ||
| runs-on: "ubuntu-latest" | ||
| steps: | ||
| - name: Checkout | ||
| # see https://github.com/actions/checkout | ||
| uses: actions/checkout@v3 | ||
| - name: Setup Node.js ${{ env.NODE_ACTIVE_LTS }} | ||
| # see https://github.com/actions/setup-node | ||
| uses: actions/setup-node@v3 | ||
| with: | ||
| node-version: ${{ env.NODE_ACTIVE_LTS }} | ||
| cache: "npm" | ||
| cache-dependency-path: | | ||
| **/npm-shrinkwrap.json | ||
| **/package-lock.json | ||
| - name: install project | ||
| run: npm ci | ||
| - name: run tests | ||
| run: npm run test:standard | ||
| test-jest: | ||
| needs: [ 'build' ] | ||
| name: test jest (${{ matrix.node-version }}, ${{ matrix.os }}) | ||
| runs-on: ${{ matrix.os }} | ||
| strategy: | ||
| fail-fast: false | ||
| matrix: | ||
| node-version: | ||
| # action based on https://github.com/actions/node-versions/releases | ||
| # see also: https://nodejs.org/en/about/releases/ | ||
| - "18" # current | ||
| - "16" # active LTS | ||
| - "16.0.0" # lowest supported | ||
| os: | ||
| - ubuntu-latest | ||
| - macos-latest | ||
| - windows-latest | ||
| timeout-minutes: 30 | ||
| steps: | ||
| - name: Checkout | ||
| # see https://github.com/actions/checkout | ||
| uses: actions/checkout@v3 | ||
| - name: Setup Node.js ${{ matrix.node-version }} | ||
| # see https://github.com/actions/setup-node | ||
| uses: actions/setup-node@v3 | ||
| with: | ||
| node-version: ${{ matrix.node-version }} | ||
| cache: "npm" | ||
| cache-dependency-path: | | ||
| **/npm-shrinkwrap.json | ||
| **/package-lock.json | ||
| - name: setup project | ||
| run: npm ci --ignore-scripts | ||
| - name: fetch build artifact | ||
| # see https://github.com/actions/download-artifact | ||
| uses: actions/download-artifact@v3 | ||
| with: | ||
| name: dist | ||
| path: dist | ||
| - name: test | ||
| run: npm run test:jest | ||
| - name: artifact test reports | ||
| if: ${{ failure() }} | ||
| # see https://github.com/actions/upload-artifact | ||
| uses: actions/upload-artifact@v3 | ||
| with: | ||
| name: reports-jest-node${{ matrix.node-version }}-${{ matrix.os }} | ||
| path: reports | ||
| if-no-files-found: error |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,6 @@ | ||
| # Lift config. See: | ||
| # https://help.sonatype.com/lift/configuring-lift | ||
|
|
||
| ignoreFiles = """ | ||
| demo/ | ||
| """ | ||
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.