You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Awesome tool! I just noticed that a lot of Python repos have manifests such as requirements-dev.txt and requirements-prod.txt instead of one requirements.txt. Unfortunatley, those manifests are skipped. Could you include them in the scan?
You were right. Manifest discovery matched the exact filename requirements.txt, so requirements-dev.txt, requirements-prod.txt and
anything else in that family was skipped silently, with no warning that files
had been passed over.
Fixed in #3. Discovery now covers the requirements*.txt family and also the requirements/*.txt directory layout, since some projects split that way
instead:
While fixing this I found that pyproject.toml and Pipfile were listed as
supported but were actually being run through the requirements.txt line
parser, which produced dependencies named after TOML keys and missed the real
packages entirely. Both have proper parsers now, so if you have projects using
those, they will give real results rather than quietly empty ones.
Awesome tool! I just noticed that a lot of Python repos have manifests such as requirements-dev.txt and requirements-prod.txt instead of one requirements.txt. Unfortunatley, those manifests are skipped. Could you include them in the scan?
BR, Xenia