guarddog icon indicating copy to clipboard operation
guarddog copied to clipboard

Feature Request: Option to Ignore Dev Dependencies for NPM

Open davekerber opened this issue 10 months ago • 1 comments

With NPM packages, I'd like the option to check all dependencies or exclude devDependencies when scanning a package.

davekerber avatar Feb 11 '25 01:02 davekerber

Hello @davekerber , thanks for reaching out. Your request makes total sense. IMO your proposal should be the default behaviour and optionally we can provide an environment variable to enable dev dep scanning.

sobregosodd avatar Feb 11 '25 08:02 sobregosodd