11cb0ef41Sopenharmony_ci<!DOCTYPE html><html><head> 21cb0ef41Sopenharmony_ci<meta charset="utf-8"> 31cb0ef41Sopenharmony_ci<title>npm-sbom</title> 41cb0ef41Sopenharmony_ci<style> 51cb0ef41Sopenharmony_cibody { 61cb0ef41Sopenharmony_ci background-color: #ffffff; 71cb0ef41Sopenharmony_ci color: #24292e; 81cb0ef41Sopenharmony_ci 91cb0ef41Sopenharmony_ci margin: 0; 101cb0ef41Sopenharmony_ci 111cb0ef41Sopenharmony_ci line-height: 1.5; 121cb0ef41Sopenharmony_ci 131cb0ef41Sopenharmony_ci font-family: -apple-system, BlinkMacSystemFont, "Segoe UI", Helvetica, Arial, sans-serif, "Apple Color Emoji", "Segoe UI Emoji"; 141cb0ef41Sopenharmony_ci} 151cb0ef41Sopenharmony_ci#rainbar { 161cb0ef41Sopenharmony_ci height: 10px; 171cb0ef41Sopenharmony_ci background-image: linear-gradient(139deg, #fb8817, #ff4b01, #c12127, #e02aff); 181cb0ef41Sopenharmony_ci} 191cb0ef41Sopenharmony_ci 201cb0ef41Sopenharmony_cia { 211cb0ef41Sopenharmony_ci text-decoration: none; 221cb0ef41Sopenharmony_ci color: #0366d6; 231cb0ef41Sopenharmony_ci} 241cb0ef41Sopenharmony_cia:hover { 251cb0ef41Sopenharmony_ci text-decoration: underline; 261cb0ef41Sopenharmony_ci} 271cb0ef41Sopenharmony_ci 281cb0ef41Sopenharmony_cipre { 291cb0ef41Sopenharmony_ci margin: 1em 0px; 301cb0ef41Sopenharmony_ci padding: 1em; 311cb0ef41Sopenharmony_ci border: solid 1px #e1e4e8; 321cb0ef41Sopenharmony_ci border-radius: 6px; 331cb0ef41Sopenharmony_ci 341cb0ef41Sopenharmony_ci display: block; 351cb0ef41Sopenharmony_ci overflow: auto; 361cb0ef41Sopenharmony_ci 371cb0ef41Sopenharmony_ci white-space: pre; 381cb0ef41Sopenharmony_ci 391cb0ef41Sopenharmony_ci background-color: #f6f8fa; 401cb0ef41Sopenharmony_ci color: #393a34; 411cb0ef41Sopenharmony_ci} 421cb0ef41Sopenharmony_cicode { 431cb0ef41Sopenharmony_ci font-family: SFMono-Regular, Consolas, "Liberation Mono", Menlo, Courier, monospace; 441cb0ef41Sopenharmony_ci font-size: 85%; 451cb0ef41Sopenharmony_ci padding: 0.2em 0.4em; 461cb0ef41Sopenharmony_ci background-color: #f6f8fa; 471cb0ef41Sopenharmony_ci color: #393a34; 481cb0ef41Sopenharmony_ci} 491cb0ef41Sopenharmony_cipre > code { 501cb0ef41Sopenharmony_ci padding: 0; 511cb0ef41Sopenharmony_ci background-color: inherit; 521cb0ef41Sopenharmony_ci color: inherit; 531cb0ef41Sopenharmony_ci} 541cb0ef41Sopenharmony_cih1, h2, h3 { 551cb0ef41Sopenharmony_ci font-weight: 600; 561cb0ef41Sopenharmony_ci} 571cb0ef41Sopenharmony_ci 581cb0ef41Sopenharmony_ci#logobar { 591cb0ef41Sopenharmony_ci background-color: #333333; 601cb0ef41Sopenharmony_ci margin: 0 auto; 611cb0ef41Sopenharmony_ci padding: 1em 4em; 621cb0ef41Sopenharmony_ci} 631cb0ef41Sopenharmony_ci#logobar .logo { 641cb0ef41Sopenharmony_ci float: left; 651cb0ef41Sopenharmony_ci} 661cb0ef41Sopenharmony_ci#logobar .title { 671cb0ef41Sopenharmony_ci font-weight: 600; 681cb0ef41Sopenharmony_ci color: #dddddd; 691cb0ef41Sopenharmony_ci float: left; 701cb0ef41Sopenharmony_ci margin: 5px 0 0 1em; 711cb0ef41Sopenharmony_ci} 721cb0ef41Sopenharmony_ci#logobar:after { 731cb0ef41Sopenharmony_ci content: ""; 741cb0ef41Sopenharmony_ci display: block; 751cb0ef41Sopenharmony_ci clear: both; 761cb0ef41Sopenharmony_ci} 771cb0ef41Sopenharmony_ci 781cb0ef41Sopenharmony_ci#content { 791cb0ef41Sopenharmony_ci margin: 0 auto; 801cb0ef41Sopenharmony_ci padding: 0 4em; 811cb0ef41Sopenharmony_ci} 821cb0ef41Sopenharmony_ci 831cb0ef41Sopenharmony_ci#table_of_contents > h2 { 841cb0ef41Sopenharmony_ci font-size: 1.17em; 851cb0ef41Sopenharmony_ci} 861cb0ef41Sopenharmony_ci#table_of_contents ul:first-child { 871cb0ef41Sopenharmony_ci border: solid 1px #e1e4e8; 881cb0ef41Sopenharmony_ci border-radius: 6px; 891cb0ef41Sopenharmony_ci padding: 1em; 901cb0ef41Sopenharmony_ci background-color: #f6f8fa; 911cb0ef41Sopenharmony_ci color: #393a34; 921cb0ef41Sopenharmony_ci} 931cb0ef41Sopenharmony_ci#table_of_contents ul { 941cb0ef41Sopenharmony_ci list-style-type: none; 951cb0ef41Sopenharmony_ci padding-left: 1.5em; 961cb0ef41Sopenharmony_ci} 971cb0ef41Sopenharmony_ci#table_of_contents li { 981cb0ef41Sopenharmony_ci font-size: 0.9em; 991cb0ef41Sopenharmony_ci} 1001cb0ef41Sopenharmony_ci#table_of_contents li a { 1011cb0ef41Sopenharmony_ci color: #000000; 1021cb0ef41Sopenharmony_ci} 1031cb0ef41Sopenharmony_ci 1041cb0ef41Sopenharmony_ciheader.title { 1051cb0ef41Sopenharmony_ci border-bottom: solid 1px #e1e4e8; 1061cb0ef41Sopenharmony_ci} 1071cb0ef41Sopenharmony_ciheader.title > h1 { 1081cb0ef41Sopenharmony_ci margin-bottom: 0.25em; 1091cb0ef41Sopenharmony_ci} 1101cb0ef41Sopenharmony_ciheader.title > .description { 1111cb0ef41Sopenharmony_ci display: block; 1121cb0ef41Sopenharmony_ci margin-bottom: 0.5em; 1131cb0ef41Sopenharmony_ci line-height: 1; 1141cb0ef41Sopenharmony_ci} 1151cb0ef41Sopenharmony_ci 1161cb0ef41Sopenharmony_cifooter#edit { 1171cb0ef41Sopenharmony_ci border-top: solid 1px #e1e4e8; 1181cb0ef41Sopenharmony_ci margin: 3em 0 4em 0; 1191cb0ef41Sopenharmony_ci padding-top: 2em; 1201cb0ef41Sopenharmony_ci} 1211cb0ef41Sopenharmony_ci</style> 1221cb0ef41Sopenharmony_ci</head> 1231cb0ef41Sopenharmony_ci<body> 1241cb0ef41Sopenharmony_ci<div id="banner"> 1251cb0ef41Sopenharmony_ci<div id="rainbar"></div> 1261cb0ef41Sopenharmony_ci<div id="logobar"> 1271cb0ef41Sopenharmony_ci<svg class="logo" role="img" height="32" width="32" viewBox="0 0 700 700"> 1281cb0ef41Sopenharmony_ci<polygon fill="#cb0000" points="0,700 700,700 700,0 0,0"></polygon> 1291cb0ef41Sopenharmony_ci<polygon fill="#ffffff" points="150,550 350,550 350,250 450,250 450,550 550,550 550,150 150,150"></polygon> 1301cb0ef41Sopenharmony_ci</svg> 1311cb0ef41Sopenharmony_ci<div class="title"> 1321cb0ef41Sopenharmony_cinpm command-line interface 1331cb0ef41Sopenharmony_ci</div> 1341cb0ef41Sopenharmony_ci</div> 1351cb0ef41Sopenharmony_ci</div> 1361cb0ef41Sopenharmony_ci 1371cb0ef41Sopenharmony_ci<section id="content"> 1381cb0ef41Sopenharmony_ci<header class="title"> 1391cb0ef41Sopenharmony_ci<h1 id="npm-sbom">npm-sbom</h1> 1401cb0ef41Sopenharmony_ci<span class="description">Generate a Software Bill of Materials (SBOM)</span> 1411cb0ef41Sopenharmony_ci</header> 1421cb0ef41Sopenharmony_ci 1431cb0ef41Sopenharmony_ci<section id="table_of_contents"> 1441cb0ef41Sopenharmony_ci<h2 id="table-of-contents">Table of contents</h2> 1451cb0ef41Sopenharmony_ci<div id="_table_of_contents"><ul><li><a href="#see-also">See Also</a></li></ul></div> 1461cb0ef41Sopenharmony_ci</section> 1471cb0ef41Sopenharmony_ci 1481cb0ef41Sopenharmony_ci<div id="_content"><h3 id="synopsis">Synopsis</h3> 1491cb0ef41Sopenharmony_ci<pre><code class="language-bash">npm sbom 1501cb0ef41Sopenharmony_ci</code></pre> 1511cb0ef41Sopenharmony_ci<h3 id="description">Description</h3> 1521cb0ef41Sopenharmony_ci<p>The <code>npm sbom</code> command generates a Software Bill of Materials (SBOM) listing the 1531cb0ef41Sopenharmony_cidependencies for the current project. SBOMs can be generated in either 1541cb0ef41Sopenharmony_ci<a href="https://spdx.dev/">SPDX</a> or <a href="https://cyclonedx.org/">CycloneDX</a> format.</p> 1551cb0ef41Sopenharmony_ci<h3 id="example-cyclonedx-sbom">Example CycloneDX SBOM</h3> 1561cb0ef41Sopenharmony_ci<pre><code class="language-json">{ 1571cb0ef41Sopenharmony_ci "$schema": "http://cyclonedx.org/schema/bom-1.5.schema.json", 1581cb0ef41Sopenharmony_ci "bomFormat": "CycloneDX", 1591cb0ef41Sopenharmony_ci "specVersion": "1.5", 1601cb0ef41Sopenharmony_ci "serialNumber": "urn:uuid:09f55116-97e1-49cf-b3b8-44d0207e7730", 1611cb0ef41Sopenharmony_ci "version": 1, 1621cb0ef41Sopenharmony_ci "metadata": { 1631cb0ef41Sopenharmony_ci "timestamp": "2023-09-01T00:00:00.001Z", 1641cb0ef41Sopenharmony_ci "lifecycles": [ 1651cb0ef41Sopenharmony_ci { 1661cb0ef41Sopenharmony_ci "phase": "build" 1671cb0ef41Sopenharmony_ci } 1681cb0ef41Sopenharmony_ci ], 1691cb0ef41Sopenharmony_ci "tools": [ 1701cb0ef41Sopenharmony_ci { 1711cb0ef41Sopenharmony_ci "vendor": "npm", 1721cb0ef41Sopenharmony_ci "name": "cli", 1731cb0ef41Sopenharmony_ci "version": "10.1.0" 1741cb0ef41Sopenharmony_ci } 1751cb0ef41Sopenharmony_ci ], 1761cb0ef41Sopenharmony_ci "component": { 1771cb0ef41Sopenharmony_ci "bom-ref": "simple@1.0.0", 1781cb0ef41Sopenharmony_ci "type": "library", 1791cb0ef41Sopenharmony_ci "name": "simple", 1801cb0ef41Sopenharmony_ci "version": "1.0.0", 1811cb0ef41Sopenharmony_ci "scope": "required", 1821cb0ef41Sopenharmony_ci "author": "John Doe", 1831cb0ef41Sopenharmony_ci "description": "simple react app", 1841cb0ef41Sopenharmony_ci "purl": "pkg:npm/simple@1.0.0", 1851cb0ef41Sopenharmony_ci "properties": [ 1861cb0ef41Sopenharmony_ci { 1871cb0ef41Sopenharmony_ci "name": "cdx:npm:package:path", 1881cb0ef41Sopenharmony_ci "value": "" 1891cb0ef41Sopenharmony_ci } 1901cb0ef41Sopenharmony_ci ], 1911cb0ef41Sopenharmony_ci "externalReferences": [], 1921cb0ef41Sopenharmony_ci "licenses": [ 1931cb0ef41Sopenharmony_ci { 1941cb0ef41Sopenharmony_ci "license": { 1951cb0ef41Sopenharmony_ci "id": "MIT" 1961cb0ef41Sopenharmony_ci } 1971cb0ef41Sopenharmony_ci } 1981cb0ef41Sopenharmony_ci ] 1991cb0ef41Sopenharmony_ci } 2001cb0ef41Sopenharmony_ci }, 2011cb0ef41Sopenharmony_ci "components": [ 2021cb0ef41Sopenharmony_ci { 2031cb0ef41Sopenharmony_ci "bom-ref": "lodash@4.17.21", 2041cb0ef41Sopenharmony_ci "type": "library", 2051cb0ef41Sopenharmony_ci "name": "lodash", 2061cb0ef41Sopenharmony_ci "version": "4.17.21", 2071cb0ef41Sopenharmony_ci "scope": "required", 2081cb0ef41Sopenharmony_ci "author": "John-David Dalton", 2091cb0ef41Sopenharmony_ci "description": "Lodash modular utilities.", 2101cb0ef41Sopenharmony_ci "purl": "pkg:npm/lodash@4.17.21", 2111cb0ef41Sopenharmony_ci "properties": [ 2121cb0ef41Sopenharmony_ci { 2131cb0ef41Sopenharmony_ci "name": "cdx:npm:package:path", 2141cb0ef41Sopenharmony_ci "value": "node_modules/lodash" 2151cb0ef41Sopenharmony_ci } 2161cb0ef41Sopenharmony_ci ], 2171cb0ef41Sopenharmony_ci "externalReferences": [ 2181cb0ef41Sopenharmony_ci { 2191cb0ef41Sopenharmony_ci "type": "distribution", 2201cb0ef41Sopenharmony_ci "url": "https://registry.npmjs.org/lodash/-/lodash-4.17.21.tgz" 2211cb0ef41Sopenharmony_ci }, 2221cb0ef41Sopenharmony_ci { 2231cb0ef41Sopenharmony_ci "type": "vcs", 2241cb0ef41Sopenharmony_ci "url": "git+https://github.com/lodash/lodash.git" 2251cb0ef41Sopenharmony_ci }, 2261cb0ef41Sopenharmony_ci { 2271cb0ef41Sopenharmony_ci "type": "website", 2281cb0ef41Sopenharmony_ci "url": "https://lodash.com/" 2291cb0ef41Sopenharmony_ci }, 2301cb0ef41Sopenharmony_ci { 2311cb0ef41Sopenharmony_ci "type": "issue-tracker", 2321cb0ef41Sopenharmony_ci "url": "https://github.com/lodash/lodash/issues" 2331cb0ef41Sopenharmony_ci } 2341cb0ef41Sopenharmony_ci ], 2351cb0ef41Sopenharmony_ci "hashes": [ 2361cb0ef41Sopenharmony_ci { 2371cb0ef41Sopenharmony_ci "alg": "SHA-512", 2381cb0ef41Sopenharmony_ci "content": "bf690311ee7b95e713ba568322e3533f2dd1cb880b189e99d4edef13592b81764daec43e2c54c61d5c558dc5cfb35ecb85b65519e74026ff17675b6f8f916f4a" 2391cb0ef41Sopenharmony_ci } 2401cb0ef41Sopenharmony_ci ], 2411cb0ef41Sopenharmony_ci "licenses": [ 2421cb0ef41Sopenharmony_ci { 2431cb0ef41Sopenharmony_ci "license": { 2441cb0ef41Sopenharmony_ci "id": "MIT" 2451cb0ef41Sopenharmony_ci } 2461cb0ef41Sopenharmony_ci } 2471cb0ef41Sopenharmony_ci ] 2481cb0ef41Sopenharmony_ci } 2491cb0ef41Sopenharmony_ci ], 2501cb0ef41Sopenharmony_ci "dependencies": [ 2511cb0ef41Sopenharmony_ci { 2521cb0ef41Sopenharmony_ci "ref": "simple@1.0.0", 2531cb0ef41Sopenharmony_ci "dependsOn": [ 2541cb0ef41Sopenharmony_ci "lodash@4.17.21" 2551cb0ef41Sopenharmony_ci ] 2561cb0ef41Sopenharmony_ci }, 2571cb0ef41Sopenharmony_ci { 2581cb0ef41Sopenharmony_ci "ref": "lodash@4.17.21", 2591cb0ef41Sopenharmony_ci "dependsOn": [] 2601cb0ef41Sopenharmony_ci } 2611cb0ef41Sopenharmony_ci ] 2621cb0ef41Sopenharmony_ci} 2631cb0ef41Sopenharmony_ci</code></pre> 2641cb0ef41Sopenharmony_ci<h3 id="example-spdx-sbom">Example SPDX SBOM</h3> 2651cb0ef41Sopenharmony_ci<pre><code class="language-json">{ 2661cb0ef41Sopenharmony_ci "spdxVersion": "SPDX-2.3", 2671cb0ef41Sopenharmony_ci "dataLicense": "CC0-1.0", 2681cb0ef41Sopenharmony_ci "SPDXID": "SPDXRef-DOCUMENT", 2691cb0ef41Sopenharmony_ci "name": "simple@1.0.0", 2701cb0ef41Sopenharmony_ci "documentNamespace": "http://spdx.org/spdxdocs/simple-1.0.0-bf81090e-8bbc-459d-bec9-abeb794e096a", 2711cb0ef41Sopenharmony_ci "creationInfo": { 2721cb0ef41Sopenharmony_ci "created": "2023-09-01T00:00:00.001Z", 2731cb0ef41Sopenharmony_ci "creators": [ 2741cb0ef41Sopenharmony_ci "Tool: npm/cli-10.1.0" 2751cb0ef41Sopenharmony_ci ] 2761cb0ef41Sopenharmony_ci }, 2771cb0ef41Sopenharmony_ci "documentDescribes": [ 2781cb0ef41Sopenharmony_ci "SPDXRef-Package-simple-1.0.0" 2791cb0ef41Sopenharmony_ci ], 2801cb0ef41Sopenharmony_ci "packages": [ 2811cb0ef41Sopenharmony_ci { 2821cb0ef41Sopenharmony_ci "name": "simple", 2831cb0ef41Sopenharmony_ci "SPDXID": "SPDXRef-Package-simple-1.0.0", 2841cb0ef41Sopenharmony_ci "versionInfo": "1.0.0", 2851cb0ef41Sopenharmony_ci "packageFileName": "", 2861cb0ef41Sopenharmony_ci "description": "simple react app", 2871cb0ef41Sopenharmony_ci "primaryPackagePurpose": "LIBRARY", 2881cb0ef41Sopenharmony_ci "downloadLocation": "NOASSERTION", 2891cb0ef41Sopenharmony_ci "filesAnalyzed": false, 2901cb0ef41Sopenharmony_ci "homepage": "NOASSERTION", 2911cb0ef41Sopenharmony_ci "licenseDeclared": "MIT", 2921cb0ef41Sopenharmony_ci "externalRefs": [ 2931cb0ef41Sopenharmony_ci { 2941cb0ef41Sopenharmony_ci "referenceCategory": "PACKAGE-MANAGER", 2951cb0ef41Sopenharmony_ci "referenceType": "purl", 2961cb0ef41Sopenharmony_ci "referenceLocator": "pkg:npm/simple@1.0.0" 2971cb0ef41Sopenharmony_ci } 2981cb0ef41Sopenharmony_ci ] 2991cb0ef41Sopenharmony_ci }, 3001cb0ef41Sopenharmony_ci { 3011cb0ef41Sopenharmony_ci "name": "lodash", 3021cb0ef41Sopenharmony_ci "SPDXID": "SPDXRef-Package-lodash-4.17.21", 3031cb0ef41Sopenharmony_ci "versionInfo": "4.17.21", 3041cb0ef41Sopenharmony_ci "packageFileName": "node_modules/lodash", 3051cb0ef41Sopenharmony_ci "description": "Lodash modular utilities.", 3061cb0ef41Sopenharmony_ci "downloadLocation": "https://registry.npmjs.org/lodash/-/lodash-4.17.21.tgz", 3071cb0ef41Sopenharmony_ci "filesAnalyzed": false, 3081cb0ef41Sopenharmony_ci "homepage": "https://lodash.com/", 3091cb0ef41Sopenharmony_ci "licenseDeclared": "MIT", 3101cb0ef41Sopenharmony_ci "externalRefs": [ 3111cb0ef41Sopenharmony_ci { 3121cb0ef41Sopenharmony_ci "referenceCategory": "PACKAGE-MANAGER", 3131cb0ef41Sopenharmony_ci "referenceType": "purl", 3141cb0ef41Sopenharmony_ci "referenceLocator": "pkg:npm/lodash@4.17.21" 3151cb0ef41Sopenharmony_ci } 3161cb0ef41Sopenharmony_ci ], 3171cb0ef41Sopenharmony_ci "checksums": [ 3181cb0ef41Sopenharmony_ci { 3191cb0ef41Sopenharmony_ci "algorithm": "SHA512", 3201cb0ef41Sopenharmony_ci "checksumValue": "bf690311ee7b95e713ba568322e3533f2dd1cb880b189e99d4edef13592b81764daec43e2c54c61d5c558dc5cfb35ecb85b65519e74026ff17675b6f8f916f4a" 3211cb0ef41Sopenharmony_ci } 3221cb0ef41Sopenharmony_ci ] 3231cb0ef41Sopenharmony_ci } 3241cb0ef41Sopenharmony_ci ], 3251cb0ef41Sopenharmony_ci "relationships": [ 3261cb0ef41Sopenharmony_ci { 3271cb0ef41Sopenharmony_ci "spdxElementId": "SPDXRef-DOCUMENT", 3281cb0ef41Sopenharmony_ci "relatedSpdxElement": "SPDXRef-Package-simple-1.0.0", 3291cb0ef41Sopenharmony_ci "relationshipType": "DESCRIBES" 3301cb0ef41Sopenharmony_ci }, 3311cb0ef41Sopenharmony_ci { 3321cb0ef41Sopenharmony_ci "spdxElementId": "SPDXRef-Package-simple-1.0.0", 3331cb0ef41Sopenharmony_ci "relatedSpdxElement": "SPDXRef-Package-lodash-4.17.21", 3341cb0ef41Sopenharmony_ci "relationshipType": "DEPENDS_ON" 3351cb0ef41Sopenharmony_ci } 3361cb0ef41Sopenharmony_ci ] 3371cb0ef41Sopenharmony_ci} 3381cb0ef41Sopenharmony_ci</code></pre> 3391cb0ef41Sopenharmony_ci<h3 id="package-lock-only-mode">Package lock only mode</h3> 3401cb0ef41Sopenharmony_ci<p>If package-lock-only is enabled, only the information in the package 3411cb0ef41Sopenharmony_cilock (or shrinkwrap) is loaded. This means that information from the 3421cb0ef41Sopenharmony_cipackage.json files of your dependencies will not be included in the 3431cb0ef41Sopenharmony_ciresult set (e.g. description, homepage, engines).</p> 3441cb0ef41Sopenharmony_ci<h3 id="configuration">Configuration</h3> 3451cb0ef41Sopenharmony_ci<h4 id="omit"><code>omit</code></h4> 3461cb0ef41Sopenharmony_ci<ul> 3471cb0ef41Sopenharmony_ci<li>Default: 'dev' if the <code>NODE_ENV</code> environment variable is set to 3481cb0ef41Sopenharmony_ci'production', otherwise empty.</li> 3491cb0ef41Sopenharmony_ci<li>Type: "dev", "optional", or "peer" (can be set multiple times)</li> 3501cb0ef41Sopenharmony_ci</ul> 3511cb0ef41Sopenharmony_ci<p>Dependency types to omit from the installation tree on disk.</p> 3521cb0ef41Sopenharmony_ci<p>Note that these dependencies <em>are</em> still resolved and added to the 3531cb0ef41Sopenharmony_ci<code>package-lock.json</code> or <code>npm-shrinkwrap.json</code> file. They are just not 3541cb0ef41Sopenharmony_ciphysically installed on disk.</p> 3551cb0ef41Sopenharmony_ci<p>If a package type appears in both the <code>--include</code> and <code>--omit</code> lists, then 3561cb0ef41Sopenharmony_ciit will be included.</p> 3571cb0ef41Sopenharmony_ci<p>If the resulting omit list includes <code>'dev'</code>, then the <code>NODE_ENV</code> environment 3581cb0ef41Sopenharmony_civariable will be set to <code>'production'</code> for all lifecycle scripts.</p> 3591cb0ef41Sopenharmony_ci<h4 id="package-lock-only"><code>package-lock-only</code></h4> 3601cb0ef41Sopenharmony_ci<ul> 3611cb0ef41Sopenharmony_ci<li>Default: false</li> 3621cb0ef41Sopenharmony_ci<li>Type: Boolean</li> 3631cb0ef41Sopenharmony_ci</ul> 3641cb0ef41Sopenharmony_ci<p>If set to true, the current operation will only use the <code>package-lock.json</code>, 3651cb0ef41Sopenharmony_ciignoring <code>node_modules</code>.</p> 3661cb0ef41Sopenharmony_ci<p>For <code>update</code> this means only the <code>package-lock.json</code> will be updated, 3671cb0ef41Sopenharmony_ciinstead of checking <code>node_modules</code> and downloading dependencies.</p> 3681cb0ef41Sopenharmony_ci<p>For <code>list</code> this means the output will be based on the tree described by the 3691cb0ef41Sopenharmony_ci<code>package-lock.json</code>, rather than the contents of <code>node_modules</code>.</p> 3701cb0ef41Sopenharmony_ci<h4 id="sbom-format"><code>sbom-format</code></h4> 3711cb0ef41Sopenharmony_ci<ul> 3721cb0ef41Sopenharmony_ci<li>Default: null</li> 3731cb0ef41Sopenharmony_ci<li>Type: "cyclonedx" or "spdx"</li> 3741cb0ef41Sopenharmony_ci</ul> 3751cb0ef41Sopenharmony_ci<p>SBOM format to use when generating SBOMs.</p> 3761cb0ef41Sopenharmony_ci<h4 id="sbom-type"><code>sbom-type</code></h4> 3771cb0ef41Sopenharmony_ci<ul> 3781cb0ef41Sopenharmony_ci<li>Default: "library"</li> 3791cb0ef41Sopenharmony_ci<li>Type: "library", "application", or "framework"</li> 3801cb0ef41Sopenharmony_ci</ul> 3811cb0ef41Sopenharmony_ci<p>The type of package described by the generated SBOM. For SPDX, this is the 3821cb0ef41Sopenharmony_civalue for the <code>primaryPackagePurpose</code> field. For CycloneDX, this is the 3831cb0ef41Sopenharmony_civalue for the <code>type</code> field.</p> 3841cb0ef41Sopenharmony_ci<h4 id="workspace"><code>workspace</code></h4> 3851cb0ef41Sopenharmony_ci<ul> 3861cb0ef41Sopenharmony_ci<li>Default:</li> 3871cb0ef41Sopenharmony_ci<li>Type: String (can be set multiple times)</li> 3881cb0ef41Sopenharmony_ci</ul> 3891cb0ef41Sopenharmony_ci<p>Enable running a command in the context of the configured workspaces of the 3901cb0ef41Sopenharmony_cicurrent project while filtering by running only the workspaces defined by 3911cb0ef41Sopenharmony_cithis configuration option.</p> 3921cb0ef41Sopenharmony_ci<p>Valid values for the <code>workspace</code> config are either:</p> 3931cb0ef41Sopenharmony_ci<ul> 3941cb0ef41Sopenharmony_ci<li>Workspace names</li> 3951cb0ef41Sopenharmony_ci<li>Path to a workspace directory</li> 3961cb0ef41Sopenharmony_ci<li>Path to a parent workspace directory (will result in selecting all 3971cb0ef41Sopenharmony_ciworkspaces within that folder)</li> 3981cb0ef41Sopenharmony_ci</ul> 3991cb0ef41Sopenharmony_ci<p>When set for the <code>npm init</code> command, this may be set to the folder of a 4001cb0ef41Sopenharmony_ciworkspace which does not yet exist, to create the folder and set it up as a 4011cb0ef41Sopenharmony_cibrand new workspace within the project.</p> 4021cb0ef41Sopenharmony_ci<p>This value is not exported to the environment for child processes.</p> 4031cb0ef41Sopenharmony_ci<h4 id="workspaces"><code>workspaces</code></h4> 4041cb0ef41Sopenharmony_ci<ul> 4051cb0ef41Sopenharmony_ci<li>Default: null</li> 4061cb0ef41Sopenharmony_ci<li>Type: null or Boolean</li> 4071cb0ef41Sopenharmony_ci</ul> 4081cb0ef41Sopenharmony_ci<p>Set to true to run the command in the context of <strong>all</strong> configured 4091cb0ef41Sopenharmony_ciworkspaces.</p> 4101cb0ef41Sopenharmony_ci<p>Explicitly setting this to false will cause commands like <code>install</code> to 4111cb0ef41Sopenharmony_ciignore workspaces altogether. When not set explicitly:</p> 4121cb0ef41Sopenharmony_ci<ul> 4131cb0ef41Sopenharmony_ci<li>Commands that operate on the <code>node_modules</code> tree (install, update, etc.) 4141cb0ef41Sopenharmony_ciwill link workspaces into the <code>node_modules</code> folder. - Commands that do 4151cb0ef41Sopenharmony_ciother things (test, exec, publish, etc.) will operate on the root project, 4161cb0ef41Sopenharmony_ci<em>unless</em> one or more workspaces are specified in the <code>workspace</code> config.</li> 4171cb0ef41Sopenharmony_ci</ul> 4181cb0ef41Sopenharmony_ci<p>This value is not exported to the environment for child processes.</p> 4191cb0ef41Sopenharmony_ci<h2 id="see-also">See Also</h2> 4201cb0ef41Sopenharmony_ci<ul> 4211cb0ef41Sopenharmony_ci<li><a href="../using-npm/package-spec.html">package spec</a></li> 4221cb0ef41Sopenharmony_ci<li><a href="../using-npm/dependency-selectors.html">dependency selectors</a></li> 4231cb0ef41Sopenharmony_ci<li><a href="../configuring-npm/package-json.html">package.json</a></li> 4241cb0ef41Sopenharmony_ci<li><a href="../using-npm/workspaces.html">workspaces</a></li> 4251cb0ef41Sopenharmony_ci</ul></div> 4261cb0ef41Sopenharmony_ci 4271cb0ef41Sopenharmony_ci<footer id="edit"> 4281cb0ef41Sopenharmony_ci<a href="https://github.com/npm/cli/edit/latest/docs/content/commands/npm-sbom.md"> 4291cb0ef41Sopenharmony_ci<svg role="img" viewBox="0 0 16 16" width="16" height="16" fill="currentcolor" style="vertical-align: text-bottom; margin-right: 0.3em;"> 4301cb0ef41Sopenharmony_ci<path fill-rule="evenodd" d="M11.013 1.427a1.75 1.75 0 012.474 0l1.086 1.086a1.75 1.75 0 010 2.474l-8.61 8.61c-.21.21-.47.364-.756.445l-3.251.93a.75.75 0 01-.927-.928l.929-3.25a1.75 1.75 0 01.445-.758l8.61-8.61zm1.414 1.06a.25.25 0 00-.354 0L10.811 3.75l1.439 1.44 1.263-1.263a.25.25 0 000-.354l-1.086-1.086zM11.189 6.25L9.75 4.81l-6.286 6.287a.25.25 0 00-.064.108l-.558 1.953 1.953-.558a.249.249 0 00.108-.064l6.286-6.286z"></path> 4311cb0ef41Sopenharmony_ci</svg> 4321cb0ef41Sopenharmony_ciEdit this page on GitHub 4331cb0ef41Sopenharmony_ci</a> 4341cb0ef41Sopenharmony_ci</footer> 4351cb0ef41Sopenharmony_ci</section> 4361cb0ef41Sopenharmony_ci 4371cb0ef41Sopenharmony_ci 4381cb0ef41Sopenharmony_ci 4391cb0ef41Sopenharmony_ci</body></html>