go-dep-parser
go-dep-parser copied to clipboard
Why is the scan for jar packages not including dependencies, such as those declared in pom.xml
it may like this

https://nvd.nist.gov/vuln/detail/CVE-2017-18349

Why are dependencies not included like in other product implementations? like package-lock.json or Pipfile.lock