-
-
Notifications
You must be signed in to change notification settings - Fork 584
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Support npm overrides #4122
Comments
I’d like to work on adding support for npm overrides. Does anyone have guidance or a preferred approach before I begin? |
In the issue, you mentioned:"We should design how to handle these [overrides], as they do not apply to a detected package, but to other packages in the dependency tree and only in specific conditions." I have a few questions regarding this: 1. Should we only capture the raw overrides data, or should we also apply it to the final dependency graph so that sub- dependency versions are replaced? |
Update: I’ve added support for npm overrides in package.json within ScanCode Toolkit. Specifically, the NpmPackageJsonHandler now detects an "overrides" field (if present) and stores it in the package’s extra_data. I also added a dedicated test (test_parse_npm_package_json_with_overrides) to confirm this behavior and updated the .expected file for the alias test to ensure all tests pass. |
Signed-off-by: Diviz Bansal <[email protected]>
These are similar to Go replace.
See https://docs.npmjs.com/cli/v11/configuring-npm/package-json#overrides
We should design how to handle these, as they do not apply to a detected package, but to other packages in the dependency tree and only in specific conditions.
The text was updated successfully, but these errors were encountered: