From f4d84fbcc48334ebe5e86eb9ea41eff59588930b Mon Sep 17 00:00:00 2001 From: "@chowmean [Gaurav Yadav]" Date: Tue, 7 Feb 2017 18:15:29 +0530 Subject: [PATCH] adding sniff for dependency security in nom --- fabpolish/contrib.py | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/fabpolish/contrib.py b/fabpolish/contrib.py index 2c428a2..d53da48 100644 --- a/fabpolish/contrib.py +++ b/fabpolish/contrib.py @@ -157,3 +157,10 @@ def check_preg_replace(): "! find src -name '*.php' -print0 | " "xargs -0 grep -n 'preg_replace('" ) + + +@sniff(severity='major', timing='fast') +def composer_security_check_npm(): + """Requires nsp in package""" + info('Running security check for npm dependencies...') + return local("nsp check")