Skip to content

exhortignore ignoring transitive on Java but not on Javascript #194

@ruromero

Description

@ruromero

What happened?

There is a difference between the Java and the Javascript libraries where in Java adding a dependency name to exhortignore will ignore all the transitive dependencies but on the Javascript library will only ignore the dependencies that match the name.

I consider that the expected behaviour is the Javascript one given that the user will want to exclude dependencies from the analysis but might be interested in the transitive vulnerabilities

Please provide runtime information.

This happens in the current v0.8.0 Java version

Relevant log output

How can this issue be reproduced?

No response

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    Projects

    Status

    Backlog

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions