added arborist.js file & support for npm auth token for arborist lib to scan private deps

This commit is contained in:
Sahilb315
2025-04-10 01:10:56 +05:30
parent ed8f9b6d53
commit 2d2f0fdee9
6 changed files with 101 additions and 13 deletions
+6 -2
View File
@@ -49,7 +49,7 @@ func NewNpmCommand() *cobra.Command {
return fmt.Errorf("npm not found: %w", err)
}
return utils.ExecCmd(npmPath, args)
return utils.ExecCmd(npmPath, args, []string{})
},
}
return cmd
@@ -71,7 +71,11 @@ func wrapNpm() error {
Interpreter: "node",
ScriptType: "js",
Args: []string{},
Env: map[string]string{
"NPM_AUTH_TOKEN": utils.NpmAuthToken(),
},
})
if err != nil {
return fmt.Errorf("failed to extract package info: %w", err)
}
@@ -154,7 +158,7 @@ func wrapNpm() error {
// Install the package and return
cmdArgs := []string{action, packageName}
if err = utils.ExecCmd(npmPath, cmdArgs); err != nil {
if err = utils.ExecCmd(npmPath, cmdArgs, []string{}); err != nil {
return fmt.Errorf("failed to execute npm command: %w", err)
}
+10 -4
View File
@@ -69306,11 +69306,11 @@ var require_lib43 = __commonJS({
// arborist.js
var Arborist = require_lib43();
var fs = require("fs");
async function getDependencyTree(packageName) {
async function getDependencyTree(packageName, authToken2) {
const arb = new Arborist({
registry: "https://registry.npmjs.org",
token: "",
authToken: ""
token: authToken2,
authToken: authToken2
});
try {
const idealTree = await arb.buildIdealTree({
@@ -69337,6 +69337,7 @@ function writeToFile(packages, filename) {
}
var packageArg = process.argv[2];
var outputFile = process.argv[3];
var authToken = process.env.NPM_AUTH_TOKEN;
if (!packageArg) {
console.error("Please provide a package name as an argument");
process.exit(1);
@@ -69345,7 +69346,12 @@ if (!outputFile) {
console.error("Please provide an output filename as the second argument");
process.exit(1);
}
getDependencyTree(packageArg).then((packages) => {
if (!authToken) {
console.warn(
"NPM token not found. Some private or scoped dependencies may not be included in the scan."
);
}
getDependencyTree(packageArg, authToken).then((packages) => {
writeToFile(packages, outputFile);
}).catch((err) => {
console.error("Error:", err);