Skip to content

Commit 8131d43

Browse files
Merge pull request #298 from luotianqi777/fix_js
fix: check out invalid npm components
2 parents 79bd286 + 5b5c2c5 commit 8131d43

File tree

1 file changed

+5
-1
lines changed

1 file changed

+5
-1
lines changed

opensca/sca/javascript/npm.go

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -143,7 +143,11 @@ func ParsePackageJsonWithNode(pkgjson *PackageJson, nodeMap map[string]*PackageJ
143143
subjs = npmOrigin(name, version)
144144
}
145145
if subjs == nil {
146-
return nil
146+
// 部分投毒组件会从官方库下架 这种构造一个虚拟的PacakgeJson保证检出
147+
subjs = &PackageJson{
148+
Name: name,
149+
Version: version,
150+
}
147151
}
148152
var dep *model.DepGraph
149153
if dev {

0 commit comments

Comments
 (0)