11cb0ef41Sopenharmony_ci<!DOCTYPE html><html><head>
21cb0ef41Sopenharmony_ci<meta charset="utf-8">
31cb0ef41Sopenharmony_ci<title>npm-sbom</title>
41cb0ef41Sopenharmony_ci<style>
51cb0ef41Sopenharmony_cibody {
61cb0ef41Sopenharmony_ci    background-color: #ffffff;
71cb0ef41Sopenharmony_ci    color: #24292e;
81cb0ef41Sopenharmony_ci
91cb0ef41Sopenharmony_ci    margin: 0;
101cb0ef41Sopenharmony_ci
111cb0ef41Sopenharmony_ci    line-height: 1.5;
121cb0ef41Sopenharmony_ci
131cb0ef41Sopenharmony_ci    font-family: -apple-system, BlinkMacSystemFont, "Segoe UI", Helvetica, Arial, sans-serif, "Apple Color Emoji", "Segoe UI Emoji";
141cb0ef41Sopenharmony_ci}
151cb0ef41Sopenharmony_ci#rainbar {
161cb0ef41Sopenharmony_ci    height: 10px;
171cb0ef41Sopenharmony_ci    background-image: linear-gradient(139deg, #fb8817, #ff4b01, #c12127, #e02aff);
181cb0ef41Sopenharmony_ci}
191cb0ef41Sopenharmony_ci
201cb0ef41Sopenharmony_cia {
211cb0ef41Sopenharmony_ci    text-decoration: none;
221cb0ef41Sopenharmony_ci    color: #0366d6;
231cb0ef41Sopenharmony_ci}
241cb0ef41Sopenharmony_cia:hover {
251cb0ef41Sopenharmony_ci    text-decoration: underline;
261cb0ef41Sopenharmony_ci}
271cb0ef41Sopenharmony_ci
281cb0ef41Sopenharmony_cipre {
291cb0ef41Sopenharmony_ci    margin: 1em 0px;
301cb0ef41Sopenharmony_ci    padding: 1em;
311cb0ef41Sopenharmony_ci    border: solid 1px #e1e4e8;
321cb0ef41Sopenharmony_ci    border-radius: 6px;
331cb0ef41Sopenharmony_ci
341cb0ef41Sopenharmony_ci    display: block;
351cb0ef41Sopenharmony_ci    overflow: auto;
361cb0ef41Sopenharmony_ci
371cb0ef41Sopenharmony_ci    white-space: pre;
381cb0ef41Sopenharmony_ci
391cb0ef41Sopenharmony_ci    background-color: #f6f8fa;
401cb0ef41Sopenharmony_ci    color: #393a34;
411cb0ef41Sopenharmony_ci}
421cb0ef41Sopenharmony_cicode {
431cb0ef41Sopenharmony_ci    font-family: SFMono-Regular, Consolas, "Liberation Mono", Menlo, Courier, monospace;
441cb0ef41Sopenharmony_ci    font-size: 85%;
451cb0ef41Sopenharmony_ci    padding: 0.2em 0.4em;
461cb0ef41Sopenharmony_ci    background-color: #f6f8fa;
471cb0ef41Sopenharmony_ci    color: #393a34;
481cb0ef41Sopenharmony_ci}
491cb0ef41Sopenharmony_cipre > code {
501cb0ef41Sopenharmony_ci    padding: 0;
511cb0ef41Sopenharmony_ci    background-color: inherit;
521cb0ef41Sopenharmony_ci    color: inherit;
531cb0ef41Sopenharmony_ci}
541cb0ef41Sopenharmony_cih1, h2, h3 {
551cb0ef41Sopenharmony_ci    font-weight: 600;
561cb0ef41Sopenharmony_ci}
571cb0ef41Sopenharmony_ci
581cb0ef41Sopenharmony_ci#logobar {
591cb0ef41Sopenharmony_ci    background-color: #333333;
601cb0ef41Sopenharmony_ci    margin: 0 auto;
611cb0ef41Sopenharmony_ci    padding: 1em 4em;
621cb0ef41Sopenharmony_ci}
631cb0ef41Sopenharmony_ci#logobar .logo {
641cb0ef41Sopenharmony_ci    float: left;
651cb0ef41Sopenharmony_ci}
661cb0ef41Sopenharmony_ci#logobar .title {
671cb0ef41Sopenharmony_ci    font-weight: 600;
681cb0ef41Sopenharmony_ci    color: #dddddd;
691cb0ef41Sopenharmony_ci    float: left;
701cb0ef41Sopenharmony_ci    margin: 5px 0 0 1em;
711cb0ef41Sopenharmony_ci}
721cb0ef41Sopenharmony_ci#logobar:after {
731cb0ef41Sopenharmony_ci    content: "";
741cb0ef41Sopenharmony_ci    display: block;
751cb0ef41Sopenharmony_ci    clear: both;
761cb0ef41Sopenharmony_ci}
771cb0ef41Sopenharmony_ci
781cb0ef41Sopenharmony_ci#content {
791cb0ef41Sopenharmony_ci    margin: 0 auto;
801cb0ef41Sopenharmony_ci    padding: 0 4em;
811cb0ef41Sopenharmony_ci}
821cb0ef41Sopenharmony_ci
831cb0ef41Sopenharmony_ci#table_of_contents > h2 {
841cb0ef41Sopenharmony_ci    font-size: 1.17em;
851cb0ef41Sopenharmony_ci}
861cb0ef41Sopenharmony_ci#table_of_contents ul:first-child {
871cb0ef41Sopenharmony_ci    border: solid 1px #e1e4e8;
881cb0ef41Sopenharmony_ci    border-radius: 6px;
891cb0ef41Sopenharmony_ci    padding: 1em;
901cb0ef41Sopenharmony_ci    background-color: #f6f8fa;
911cb0ef41Sopenharmony_ci    color: #393a34;
921cb0ef41Sopenharmony_ci}
931cb0ef41Sopenharmony_ci#table_of_contents ul {
941cb0ef41Sopenharmony_ci    list-style-type: none;
951cb0ef41Sopenharmony_ci    padding-left: 1.5em;
961cb0ef41Sopenharmony_ci}
971cb0ef41Sopenharmony_ci#table_of_contents li {
981cb0ef41Sopenharmony_ci    font-size: 0.9em;
991cb0ef41Sopenharmony_ci}
1001cb0ef41Sopenharmony_ci#table_of_contents li a {
1011cb0ef41Sopenharmony_ci    color: #000000;
1021cb0ef41Sopenharmony_ci}
1031cb0ef41Sopenharmony_ci
1041cb0ef41Sopenharmony_ciheader.title {
1051cb0ef41Sopenharmony_ci    border-bottom: solid 1px #e1e4e8;
1061cb0ef41Sopenharmony_ci}
1071cb0ef41Sopenharmony_ciheader.title > h1 {
1081cb0ef41Sopenharmony_ci    margin-bottom: 0.25em;
1091cb0ef41Sopenharmony_ci}
1101cb0ef41Sopenharmony_ciheader.title > .description {
1111cb0ef41Sopenharmony_ci    display: block;
1121cb0ef41Sopenharmony_ci    margin-bottom: 0.5em;
1131cb0ef41Sopenharmony_ci    line-height: 1;
1141cb0ef41Sopenharmony_ci}
1151cb0ef41Sopenharmony_ci
1161cb0ef41Sopenharmony_cifooter#edit {
1171cb0ef41Sopenharmony_ci    border-top: solid 1px #e1e4e8;
1181cb0ef41Sopenharmony_ci    margin: 3em 0 4em 0;
1191cb0ef41Sopenharmony_ci    padding-top: 2em;
1201cb0ef41Sopenharmony_ci}
1211cb0ef41Sopenharmony_ci</style>
1221cb0ef41Sopenharmony_ci</head>
1231cb0ef41Sopenharmony_ci<body>
1241cb0ef41Sopenharmony_ci<div id="banner">
1251cb0ef41Sopenharmony_ci<div id="rainbar"></div>
1261cb0ef41Sopenharmony_ci<div id="logobar">
1271cb0ef41Sopenharmony_ci<svg class="logo" role="img" height="32" width="32" viewBox="0 0 700 700">
1281cb0ef41Sopenharmony_ci<polygon fill="#cb0000" points="0,700 700,700 700,0 0,0"></polygon>
1291cb0ef41Sopenharmony_ci<polygon fill="#ffffff" points="150,550 350,550 350,250 450,250 450,550 550,550 550,150 150,150"></polygon>
1301cb0ef41Sopenharmony_ci</svg>
1311cb0ef41Sopenharmony_ci<div class="title">
1321cb0ef41Sopenharmony_cinpm command-line interface
1331cb0ef41Sopenharmony_ci</div>
1341cb0ef41Sopenharmony_ci</div>
1351cb0ef41Sopenharmony_ci</div>
1361cb0ef41Sopenharmony_ci
1371cb0ef41Sopenharmony_ci<section id="content">
1381cb0ef41Sopenharmony_ci<header class="title">
1391cb0ef41Sopenharmony_ci<h1 id="npm-sbom">npm-sbom</h1>
1401cb0ef41Sopenharmony_ci<span class="description">Generate a Software Bill of Materials (SBOM)</span>
1411cb0ef41Sopenharmony_ci</header>
1421cb0ef41Sopenharmony_ci
1431cb0ef41Sopenharmony_ci<section id="table_of_contents">
1441cb0ef41Sopenharmony_ci<h2 id="table-of-contents">Table of contents</h2>
1451cb0ef41Sopenharmony_ci<div id="_table_of_contents"><ul><li><a href="#see-also">See Also</a></li></ul></div>
1461cb0ef41Sopenharmony_ci</section>
1471cb0ef41Sopenharmony_ci
1481cb0ef41Sopenharmony_ci<div id="_content"><h3 id="synopsis">Synopsis</h3>
1491cb0ef41Sopenharmony_ci<pre><code class="language-bash">npm sbom
1501cb0ef41Sopenharmony_ci</code></pre>
1511cb0ef41Sopenharmony_ci<h3 id="description">Description</h3>
1521cb0ef41Sopenharmony_ci<p>The <code>npm sbom</code> command generates a Software Bill of Materials (SBOM) listing the
1531cb0ef41Sopenharmony_cidependencies for the current project. SBOMs can be generated in either
1541cb0ef41Sopenharmony_ci<a href="https://spdx.dev/">SPDX</a> or <a href="https://cyclonedx.org/">CycloneDX</a> format.</p>
1551cb0ef41Sopenharmony_ci<h3 id="example-cyclonedx-sbom">Example CycloneDX SBOM</h3>
1561cb0ef41Sopenharmony_ci<pre><code class="language-json">{
1571cb0ef41Sopenharmony_ci  "$schema": "http://cyclonedx.org/schema/bom-1.5.schema.json",
1581cb0ef41Sopenharmony_ci  "bomFormat": "CycloneDX",
1591cb0ef41Sopenharmony_ci  "specVersion": "1.5",
1601cb0ef41Sopenharmony_ci  "serialNumber": "urn:uuid:09f55116-97e1-49cf-b3b8-44d0207e7730",
1611cb0ef41Sopenharmony_ci  "version": 1,
1621cb0ef41Sopenharmony_ci  "metadata": {
1631cb0ef41Sopenharmony_ci    "timestamp": "2023-09-01T00:00:00.001Z",
1641cb0ef41Sopenharmony_ci    "lifecycles": [
1651cb0ef41Sopenharmony_ci      {
1661cb0ef41Sopenharmony_ci        "phase": "build"
1671cb0ef41Sopenharmony_ci      }
1681cb0ef41Sopenharmony_ci    ],
1691cb0ef41Sopenharmony_ci    "tools": [
1701cb0ef41Sopenharmony_ci      {
1711cb0ef41Sopenharmony_ci        "vendor": "npm",
1721cb0ef41Sopenharmony_ci        "name": "cli",
1731cb0ef41Sopenharmony_ci        "version": "10.1.0"
1741cb0ef41Sopenharmony_ci      }
1751cb0ef41Sopenharmony_ci    ],
1761cb0ef41Sopenharmony_ci    "component": {
1771cb0ef41Sopenharmony_ci      "bom-ref": "simple@1.0.0",
1781cb0ef41Sopenharmony_ci      "type": "library",
1791cb0ef41Sopenharmony_ci      "name": "simple",
1801cb0ef41Sopenharmony_ci      "version": "1.0.0",
1811cb0ef41Sopenharmony_ci      "scope": "required",
1821cb0ef41Sopenharmony_ci      "author": "John Doe",
1831cb0ef41Sopenharmony_ci      "description": "simple react app",
1841cb0ef41Sopenharmony_ci      "purl": "pkg:npm/simple@1.0.0",
1851cb0ef41Sopenharmony_ci      "properties": [
1861cb0ef41Sopenharmony_ci        {
1871cb0ef41Sopenharmony_ci          "name": "cdx:npm:package:path",
1881cb0ef41Sopenharmony_ci          "value": ""
1891cb0ef41Sopenharmony_ci        }
1901cb0ef41Sopenharmony_ci      ],
1911cb0ef41Sopenharmony_ci      "externalReferences": [],
1921cb0ef41Sopenharmony_ci      "licenses": [
1931cb0ef41Sopenharmony_ci        {
1941cb0ef41Sopenharmony_ci          "license": {
1951cb0ef41Sopenharmony_ci            "id": "MIT"
1961cb0ef41Sopenharmony_ci          }
1971cb0ef41Sopenharmony_ci        }
1981cb0ef41Sopenharmony_ci      ]
1991cb0ef41Sopenharmony_ci    }
2001cb0ef41Sopenharmony_ci  },
2011cb0ef41Sopenharmony_ci  "components": [
2021cb0ef41Sopenharmony_ci    {
2031cb0ef41Sopenharmony_ci      "bom-ref": "lodash@4.17.21",
2041cb0ef41Sopenharmony_ci      "type": "library",
2051cb0ef41Sopenharmony_ci      "name": "lodash",
2061cb0ef41Sopenharmony_ci      "version": "4.17.21",
2071cb0ef41Sopenharmony_ci      "scope": "required",
2081cb0ef41Sopenharmony_ci      "author": "John-David Dalton",
2091cb0ef41Sopenharmony_ci      "description": "Lodash modular utilities.",
2101cb0ef41Sopenharmony_ci      "purl": "pkg:npm/lodash@4.17.21",
2111cb0ef41Sopenharmony_ci      "properties": [
2121cb0ef41Sopenharmony_ci        {
2131cb0ef41Sopenharmony_ci          "name": "cdx:npm:package:path",
2141cb0ef41Sopenharmony_ci          "value": "node_modules/lodash"
2151cb0ef41Sopenharmony_ci        }
2161cb0ef41Sopenharmony_ci      ],
2171cb0ef41Sopenharmony_ci      "externalReferences": [
2181cb0ef41Sopenharmony_ci        {
2191cb0ef41Sopenharmony_ci          "type": "distribution",
2201cb0ef41Sopenharmony_ci          "url": "https://registry.npmjs.org/lodash/-/lodash-4.17.21.tgz"
2211cb0ef41Sopenharmony_ci        },
2221cb0ef41Sopenharmony_ci        {
2231cb0ef41Sopenharmony_ci          "type": "vcs",
2241cb0ef41Sopenharmony_ci          "url": "git+https://github.com/lodash/lodash.git"
2251cb0ef41Sopenharmony_ci        },
2261cb0ef41Sopenharmony_ci        {
2271cb0ef41Sopenharmony_ci          "type": "website",
2281cb0ef41Sopenharmony_ci          "url": "https://lodash.com/"
2291cb0ef41Sopenharmony_ci        },
2301cb0ef41Sopenharmony_ci        {
2311cb0ef41Sopenharmony_ci          "type": "issue-tracker",
2321cb0ef41Sopenharmony_ci          "url": "https://github.com/lodash/lodash/issues"
2331cb0ef41Sopenharmony_ci        }
2341cb0ef41Sopenharmony_ci      ],
2351cb0ef41Sopenharmony_ci      "hashes": [
2361cb0ef41Sopenharmony_ci        {
2371cb0ef41Sopenharmony_ci          "alg": "SHA-512",
2381cb0ef41Sopenharmony_ci          "content": "bf690311ee7b95e713ba568322e3533f2dd1cb880b189e99d4edef13592b81764daec43e2c54c61d5c558dc5cfb35ecb85b65519e74026ff17675b6f8f916f4a"
2391cb0ef41Sopenharmony_ci        }
2401cb0ef41Sopenharmony_ci      ],
2411cb0ef41Sopenharmony_ci      "licenses": [
2421cb0ef41Sopenharmony_ci        {
2431cb0ef41Sopenharmony_ci          "license": {
2441cb0ef41Sopenharmony_ci            "id": "MIT"
2451cb0ef41Sopenharmony_ci          }
2461cb0ef41Sopenharmony_ci        }
2471cb0ef41Sopenharmony_ci      ]
2481cb0ef41Sopenharmony_ci    }
2491cb0ef41Sopenharmony_ci  ],
2501cb0ef41Sopenharmony_ci  "dependencies": [
2511cb0ef41Sopenharmony_ci    {
2521cb0ef41Sopenharmony_ci      "ref": "simple@1.0.0",
2531cb0ef41Sopenharmony_ci      "dependsOn": [
2541cb0ef41Sopenharmony_ci        "lodash@4.17.21"
2551cb0ef41Sopenharmony_ci      ]
2561cb0ef41Sopenharmony_ci    },
2571cb0ef41Sopenharmony_ci    {
2581cb0ef41Sopenharmony_ci      "ref": "lodash@4.17.21",
2591cb0ef41Sopenharmony_ci      "dependsOn": []
2601cb0ef41Sopenharmony_ci    }
2611cb0ef41Sopenharmony_ci  ]
2621cb0ef41Sopenharmony_ci}
2631cb0ef41Sopenharmony_ci</code></pre>
2641cb0ef41Sopenharmony_ci<h3 id="example-spdx-sbom">Example SPDX SBOM</h3>
2651cb0ef41Sopenharmony_ci<pre><code class="language-json">{
2661cb0ef41Sopenharmony_ci  "spdxVersion": "SPDX-2.3",
2671cb0ef41Sopenharmony_ci  "dataLicense": "CC0-1.0",
2681cb0ef41Sopenharmony_ci  "SPDXID": "SPDXRef-DOCUMENT",
2691cb0ef41Sopenharmony_ci  "name": "simple@1.0.0",
2701cb0ef41Sopenharmony_ci  "documentNamespace": "http://spdx.org/spdxdocs/simple-1.0.0-bf81090e-8bbc-459d-bec9-abeb794e096a",
2711cb0ef41Sopenharmony_ci  "creationInfo": {
2721cb0ef41Sopenharmony_ci    "created": "2023-09-01T00:00:00.001Z",
2731cb0ef41Sopenharmony_ci    "creators": [
2741cb0ef41Sopenharmony_ci      "Tool: npm/cli-10.1.0"
2751cb0ef41Sopenharmony_ci    ]
2761cb0ef41Sopenharmony_ci  },
2771cb0ef41Sopenharmony_ci  "documentDescribes": [
2781cb0ef41Sopenharmony_ci    "SPDXRef-Package-simple-1.0.0"
2791cb0ef41Sopenharmony_ci  ],
2801cb0ef41Sopenharmony_ci  "packages": [
2811cb0ef41Sopenharmony_ci    {
2821cb0ef41Sopenharmony_ci      "name": "simple",
2831cb0ef41Sopenharmony_ci      "SPDXID": "SPDXRef-Package-simple-1.0.0",
2841cb0ef41Sopenharmony_ci      "versionInfo": "1.0.0",
2851cb0ef41Sopenharmony_ci      "packageFileName": "",
2861cb0ef41Sopenharmony_ci      "description": "simple react app",
2871cb0ef41Sopenharmony_ci      "primaryPackagePurpose": "LIBRARY",
2881cb0ef41Sopenharmony_ci      "downloadLocation": "NOASSERTION",
2891cb0ef41Sopenharmony_ci      "filesAnalyzed": false,
2901cb0ef41Sopenharmony_ci      "homepage": "NOASSERTION",
2911cb0ef41Sopenharmony_ci      "licenseDeclared": "MIT",
2921cb0ef41Sopenharmony_ci      "externalRefs": [
2931cb0ef41Sopenharmony_ci        {
2941cb0ef41Sopenharmony_ci          "referenceCategory": "PACKAGE-MANAGER",
2951cb0ef41Sopenharmony_ci          "referenceType": "purl",
2961cb0ef41Sopenharmony_ci          "referenceLocator": "pkg:npm/simple@1.0.0"
2971cb0ef41Sopenharmony_ci        }
2981cb0ef41Sopenharmony_ci      ]
2991cb0ef41Sopenharmony_ci    },
3001cb0ef41Sopenharmony_ci    {
3011cb0ef41Sopenharmony_ci      "name": "lodash",
3021cb0ef41Sopenharmony_ci      "SPDXID": "SPDXRef-Package-lodash-4.17.21",
3031cb0ef41Sopenharmony_ci      "versionInfo": "4.17.21",
3041cb0ef41Sopenharmony_ci      "packageFileName": "node_modules/lodash",
3051cb0ef41Sopenharmony_ci      "description": "Lodash modular utilities.",
3061cb0ef41Sopenharmony_ci      "downloadLocation": "https://registry.npmjs.org/lodash/-/lodash-4.17.21.tgz",
3071cb0ef41Sopenharmony_ci      "filesAnalyzed": false,
3081cb0ef41Sopenharmony_ci      "homepage": "https://lodash.com/",
3091cb0ef41Sopenharmony_ci      "licenseDeclared": "MIT",
3101cb0ef41Sopenharmony_ci      "externalRefs": [
3111cb0ef41Sopenharmony_ci        {
3121cb0ef41Sopenharmony_ci          "referenceCategory": "PACKAGE-MANAGER",
3131cb0ef41Sopenharmony_ci          "referenceType": "purl",
3141cb0ef41Sopenharmony_ci          "referenceLocator": "pkg:npm/lodash@4.17.21"
3151cb0ef41Sopenharmony_ci        }
3161cb0ef41Sopenharmony_ci      ],
3171cb0ef41Sopenharmony_ci      "checksums": [
3181cb0ef41Sopenharmony_ci        {
3191cb0ef41Sopenharmony_ci          "algorithm": "SHA512",
3201cb0ef41Sopenharmony_ci          "checksumValue": "bf690311ee7b95e713ba568322e3533f2dd1cb880b189e99d4edef13592b81764daec43e2c54c61d5c558dc5cfb35ecb85b65519e74026ff17675b6f8f916f4a"
3211cb0ef41Sopenharmony_ci        }
3221cb0ef41Sopenharmony_ci      ]
3231cb0ef41Sopenharmony_ci    }
3241cb0ef41Sopenharmony_ci  ],
3251cb0ef41Sopenharmony_ci  "relationships": [
3261cb0ef41Sopenharmony_ci    {
3271cb0ef41Sopenharmony_ci      "spdxElementId": "SPDXRef-DOCUMENT",
3281cb0ef41Sopenharmony_ci      "relatedSpdxElement": "SPDXRef-Package-simple-1.0.0",
3291cb0ef41Sopenharmony_ci      "relationshipType": "DESCRIBES"
3301cb0ef41Sopenharmony_ci    },
3311cb0ef41Sopenharmony_ci    {
3321cb0ef41Sopenharmony_ci      "spdxElementId": "SPDXRef-Package-simple-1.0.0",
3331cb0ef41Sopenharmony_ci      "relatedSpdxElement": "SPDXRef-Package-lodash-4.17.21",
3341cb0ef41Sopenharmony_ci      "relationshipType": "DEPENDS_ON"
3351cb0ef41Sopenharmony_ci    }
3361cb0ef41Sopenharmony_ci  ]
3371cb0ef41Sopenharmony_ci}
3381cb0ef41Sopenharmony_ci</code></pre>
3391cb0ef41Sopenharmony_ci<h3 id="package-lock-only-mode">Package lock only mode</h3>
3401cb0ef41Sopenharmony_ci<p>If package-lock-only is enabled, only the information in the package
3411cb0ef41Sopenharmony_cilock (or shrinkwrap) is loaded.  This means that information from the
3421cb0ef41Sopenharmony_cipackage.json files of your dependencies will not be included in the
3431cb0ef41Sopenharmony_ciresult set (e.g. description, homepage, engines).</p>
3441cb0ef41Sopenharmony_ci<h3 id="configuration">Configuration</h3>
3451cb0ef41Sopenharmony_ci<h4 id="omit"><code>omit</code></h4>
3461cb0ef41Sopenharmony_ci<ul>
3471cb0ef41Sopenharmony_ci<li>Default: 'dev' if the <code>NODE_ENV</code> environment variable is set to
3481cb0ef41Sopenharmony_ci'production', otherwise empty.</li>
3491cb0ef41Sopenharmony_ci<li>Type: "dev", "optional", or "peer" (can be set multiple times)</li>
3501cb0ef41Sopenharmony_ci</ul>
3511cb0ef41Sopenharmony_ci<p>Dependency types to omit from the installation tree on disk.</p>
3521cb0ef41Sopenharmony_ci<p>Note that these dependencies <em>are</em> still resolved and added to the
3531cb0ef41Sopenharmony_ci<code>package-lock.json</code> or <code>npm-shrinkwrap.json</code> file. They are just not
3541cb0ef41Sopenharmony_ciphysically installed on disk.</p>
3551cb0ef41Sopenharmony_ci<p>If a package type appears in both the <code>--include</code> and <code>--omit</code> lists, then
3561cb0ef41Sopenharmony_ciit will be included.</p>
3571cb0ef41Sopenharmony_ci<p>If the resulting omit list includes <code>'dev'</code>, then the <code>NODE_ENV</code> environment
3581cb0ef41Sopenharmony_civariable will be set to <code>'production'</code> for all lifecycle scripts.</p>
3591cb0ef41Sopenharmony_ci<h4 id="package-lock-only"><code>package-lock-only</code></h4>
3601cb0ef41Sopenharmony_ci<ul>
3611cb0ef41Sopenharmony_ci<li>Default: false</li>
3621cb0ef41Sopenharmony_ci<li>Type: Boolean</li>
3631cb0ef41Sopenharmony_ci</ul>
3641cb0ef41Sopenharmony_ci<p>If set to true, the current operation will only use the <code>package-lock.json</code>,
3651cb0ef41Sopenharmony_ciignoring <code>node_modules</code>.</p>
3661cb0ef41Sopenharmony_ci<p>For <code>update</code> this means only the <code>package-lock.json</code> will be updated,
3671cb0ef41Sopenharmony_ciinstead of checking <code>node_modules</code> and downloading dependencies.</p>
3681cb0ef41Sopenharmony_ci<p>For <code>list</code> this means the output will be based on the tree described by the
3691cb0ef41Sopenharmony_ci<code>package-lock.json</code>, rather than the contents of <code>node_modules</code>.</p>
3701cb0ef41Sopenharmony_ci<h4 id="sbom-format"><code>sbom-format</code></h4>
3711cb0ef41Sopenharmony_ci<ul>
3721cb0ef41Sopenharmony_ci<li>Default: null</li>
3731cb0ef41Sopenharmony_ci<li>Type: "cyclonedx" or "spdx"</li>
3741cb0ef41Sopenharmony_ci</ul>
3751cb0ef41Sopenharmony_ci<p>SBOM format to use when generating SBOMs.</p>
3761cb0ef41Sopenharmony_ci<h4 id="sbom-type"><code>sbom-type</code></h4>
3771cb0ef41Sopenharmony_ci<ul>
3781cb0ef41Sopenharmony_ci<li>Default: "library"</li>
3791cb0ef41Sopenharmony_ci<li>Type: "library", "application", or "framework"</li>
3801cb0ef41Sopenharmony_ci</ul>
3811cb0ef41Sopenharmony_ci<p>The type of package described by the generated SBOM. For SPDX, this is the
3821cb0ef41Sopenharmony_civalue for the <code>primaryPackagePurpose</code> field. For CycloneDX, this is the
3831cb0ef41Sopenharmony_civalue for the <code>type</code> field.</p>
3841cb0ef41Sopenharmony_ci<h4 id="workspace"><code>workspace</code></h4>
3851cb0ef41Sopenharmony_ci<ul>
3861cb0ef41Sopenharmony_ci<li>Default:</li>
3871cb0ef41Sopenharmony_ci<li>Type: String (can be set multiple times)</li>
3881cb0ef41Sopenharmony_ci</ul>
3891cb0ef41Sopenharmony_ci<p>Enable running a command in the context of the configured workspaces of the
3901cb0ef41Sopenharmony_cicurrent project while filtering by running only the workspaces defined by
3911cb0ef41Sopenharmony_cithis configuration option.</p>
3921cb0ef41Sopenharmony_ci<p>Valid values for the <code>workspace</code> config are either:</p>
3931cb0ef41Sopenharmony_ci<ul>
3941cb0ef41Sopenharmony_ci<li>Workspace names</li>
3951cb0ef41Sopenharmony_ci<li>Path to a workspace directory</li>
3961cb0ef41Sopenharmony_ci<li>Path to a parent workspace directory (will result in selecting all
3971cb0ef41Sopenharmony_ciworkspaces within that folder)</li>
3981cb0ef41Sopenharmony_ci</ul>
3991cb0ef41Sopenharmony_ci<p>When set for the <code>npm init</code> command, this may be set to the folder of a
4001cb0ef41Sopenharmony_ciworkspace which does not yet exist, to create the folder and set it up as a
4011cb0ef41Sopenharmony_cibrand new workspace within the project.</p>
4021cb0ef41Sopenharmony_ci<p>This value is not exported to the environment for child processes.</p>
4031cb0ef41Sopenharmony_ci<h4 id="workspaces"><code>workspaces</code></h4>
4041cb0ef41Sopenharmony_ci<ul>
4051cb0ef41Sopenharmony_ci<li>Default: null</li>
4061cb0ef41Sopenharmony_ci<li>Type: null or Boolean</li>
4071cb0ef41Sopenharmony_ci</ul>
4081cb0ef41Sopenharmony_ci<p>Set to true to run the command in the context of <strong>all</strong> configured
4091cb0ef41Sopenharmony_ciworkspaces.</p>
4101cb0ef41Sopenharmony_ci<p>Explicitly setting this to false will cause commands like <code>install</code> to
4111cb0ef41Sopenharmony_ciignore workspaces altogether. When not set explicitly:</p>
4121cb0ef41Sopenharmony_ci<ul>
4131cb0ef41Sopenharmony_ci<li>Commands that operate on the <code>node_modules</code> tree (install, update, etc.)
4141cb0ef41Sopenharmony_ciwill link workspaces into the <code>node_modules</code> folder. - Commands that do
4151cb0ef41Sopenharmony_ciother things (test, exec, publish, etc.) will operate on the root project,
4161cb0ef41Sopenharmony_ci<em>unless</em> one or more workspaces are specified in the <code>workspace</code> config.</li>
4171cb0ef41Sopenharmony_ci</ul>
4181cb0ef41Sopenharmony_ci<p>This value is not exported to the environment for child processes.</p>
4191cb0ef41Sopenharmony_ci<h2 id="see-also">See Also</h2>
4201cb0ef41Sopenharmony_ci<ul>
4211cb0ef41Sopenharmony_ci<li><a href="../using-npm/package-spec.html">package spec</a></li>
4221cb0ef41Sopenharmony_ci<li><a href="../using-npm/dependency-selectors.html">dependency selectors</a></li>
4231cb0ef41Sopenharmony_ci<li><a href="../configuring-npm/package-json.html">package.json</a></li>
4241cb0ef41Sopenharmony_ci<li><a href="../using-npm/workspaces.html">workspaces</a></li>
4251cb0ef41Sopenharmony_ci</ul></div>
4261cb0ef41Sopenharmony_ci
4271cb0ef41Sopenharmony_ci<footer id="edit">
4281cb0ef41Sopenharmony_ci<a href="https://github.com/npm/cli/edit/latest/docs/content/commands/npm-sbom.md">
4291cb0ef41Sopenharmony_ci<svg role="img" viewBox="0 0 16 16" width="16" height="16" fill="currentcolor" style="vertical-align: text-bottom; margin-right: 0.3em;">
4301cb0ef41Sopenharmony_ci<path fill-rule="evenodd" d="M11.013 1.427a1.75 1.75 0 012.474 0l1.086 1.086a1.75 1.75 0 010 2.474l-8.61 8.61c-.21.21-.47.364-.756.445l-3.251.93a.75.75 0 01-.927-.928l.929-3.25a1.75 1.75 0 01.445-.758l8.61-8.61zm1.414 1.06a.25.25 0 00-.354 0L10.811 3.75l1.439 1.44 1.263-1.263a.25.25 0 000-.354l-1.086-1.086zM11.189 6.25L9.75 4.81l-6.286 6.287a.25.25 0 00-.064.108l-.558 1.953 1.953-.558a.249.249 0 00.108-.064l6.286-6.286z"></path>
4311cb0ef41Sopenharmony_ci</svg>
4321cb0ef41Sopenharmony_ciEdit this page on GitHub
4331cb0ef41Sopenharmony_ci</a>
4341cb0ef41Sopenharmony_ci</footer>
4351cb0ef41Sopenharmony_ci</section>
4361cb0ef41Sopenharmony_ci
4371cb0ef41Sopenharmony_ci
4381cb0ef41Sopenharmony_ci
4391cb0ef41Sopenharmony_ci</body></html>