Skip to content

dependabot npm(deps): bump @cyclonedx/bom from 3.10.6 to 4.0.1

Depen d'Abot requested to merge dependabot-npm_and_yarn-cyclonedx-bom-4.0.1 into master

Bumps @cyclonedx/bom from 3.10.6 to 4.0.1.

Release notes

Sourced from @​cyclonedx/bom's releases.

4.0.1

  • Docs:
    • Describe the "Out of Scope" section (via #342)
    • Fixed some typos

#342: CycloneDX/cyclonedx-node-module#342

4.0.0

This package became a so-called meta-package, it does not ship any own functionality, but it is a collection of dependencies. (via #321)

This package's dependencies are tools with one purpose in common: generate CycloneDX Software Bill-of-Materials (SBOM) from node-based projects.

  • for npm-based projects: @​cyclonedx/cyclonedx-npm
  • for yarn-based projects: to be announced
  • for pnpm-based projects: to be announced

If you are looking for a JavaScript/TypeScript library for working with CycloneDX, its data models or serialization, then you might want to try @​cyclonedx/cyclonedx-library.

#321: CycloneDX/cyclonedx-node-module#321

4.0.0-rc.1

No release notes provided.

Changelog

Sourced from @​cyclonedx/bom's changelog.

4.0.1 - 2022-10-21

  • Docs:
    • Describe the "Out of Scope" section (via #342)
    • Fixed some typos

#342: CycloneDX/cyclonedx-node-module#342

4.0.0 - 2022-10-21

This became a so-called meta-package, it does not ship any own functionality, but it is a collection of dependencies. (via #321)

This package's dependencies are tools with one purpose in common: generate CycloneDX Software Bill-of-Materials (SBOM) from node-based projects.

  • for npm-based projects: @​cyclonedx/cyclonedx-npm
  • for yarn-based projects: to be announced
  • for pnpm-based projects: to be announced

If you are looking for a JavaScript/TypeScript library for working with CycloneDX, its data models or serialization, then you might want to try @​cyclonedx/cyclonedx-library.

#321: CycloneDX/cyclonedx-node-module#321

Commits

Merge request reports

Loading