HValdez344285 (Community Member) asked a question.

Why does the Software Composition Analysis fail to identify npm library as updated?

Hi Veracode community,

 

I'm having an issue with some libraries of my NodeJS project. There was a vulnerability in a dependency and update from version x to y was suggested. After applying the update and modifying the npm-shrinkwrap.json to version y, the analysis does not catch the update and still marks it as if it uses the previous version.

 

The specific library I have trouble with is 'tar', and it is not a direct dependency but a transitive one.


  • Hello @HValdez344285 (Community Member)​ ,

     

    For this type of issue, I would advise opening a Support ticket in order for someone to take a look at what is going on with the library. Here's how you can log a case:

     

    1. Navigate to the upper right corner of any page in the Community, click on your user avatar.
    2. Select Contact Support from the drop-down menu.

     

    When you open the ticket, I would include a link to the scan and also more information on the .json file that was updated.

     

    Jason

    Veracode Support Engineer

    Expand Post

Topics (2)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.