Source code

Since each programming language has its declaration files for the libraries being used, the SBOM engine only analyzes the files with these specific filenames to avoid false positives or performance downgrades.

Programming languageFile to check
RubyGemfile.lock
Python

Pipfile.lock

poetry.lock

requirements*.txt

PHPcomposer.lock
NodeJS

package-lock.json

yarn.lock

pnpm-lock.yaml

Java

pom.xml

gradle.lockfile

*.jar

Gogo.mod
RustCargo.lock
Dartpubspec.lock
.NET

packages.lock.json

packages.config

.deps.json

Elixirmix.lock
SwiftPodfile.lock
C/C++ package managerconan.lock
Type to search, ESC to discard
Type to search, ESC to discard
Type to search, ESC to discard
On This Page
Source code