-
Notifications
You must be signed in to change notification settings - Fork 43
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add --extra-args
to fix #298
#300
Conversation
Signed-off-by: Sargun Vohra <[email protected]>
Signed-off-by: Sargun Vohra <[email protected]>
I also had trouble updating Yarn Berry to 3.3.1 in #294. Unless necessary, let's keep 3.3.0 and push the investigation for why 3.3.1 isn't working. |
Can you add a test to cover the |
Signed-off-by: Sargun Vohra <[email protected]>
Signed-off-by: Sargun Vohra <[email protected]>
@@ -385,6 +386,23 @@ Or, with the CLI: | |||
npx audit-ci@^6 --report-type summary | |||
``` | |||
|
|||
### Pass additional args to Yarn to exclude a certain package from audit |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Love it!
Currently the test Yarn Berry version is v2.4, so I was thinking I'd file a separate PR to include Yarn v3 in addition to v2 in tests (maybe v4 rc builds too?) and run against them all. Unsure if that's worth it though, thoughts? |
👍🏻
It was on my radar to do this as well. IMO, it is worth it, since the point of this package is to cover all package managers. However, I understand if you have a lot on your plate right now to tackle it. In either case, consider filing an issue so that we can track that work 😄 |
Cool, filed #302. I might work on it at some point, but not in the very near future. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Everything looks great. Thank you for this! I will release it ASAP. Will tag back here once released.
Closes #298
chore(deps): bump json5 from 1.0.1 to 1.0.2 (IBM#299) Add --extra-args to fix IBM#298 (IBM#300) Signed-off-by: Quinn Turner <[email protected]>
Released in v6.6.0 |
As discussed in #298, this PR adds a
--extra-args
flag to pass additional arguments to the underlying audit command.Since these additional args are likely to include flags (
--foo
), I added an escaping mechanism, so any "extra arg" starting with a\
will have that first\
removed.Usage example: