Skip to content

Snyk brings in a boat-load of dependencies #33

Closed
@JaredReisinger

Description

A bit puzzled here. Why would this package need so many dependencies?

[4/4] Building fresh packages...
success Saved lockfile.
success Saved 187 new dependencies.
info Direct dependencies
└─ @jaredreisinger/react-crossword@2.2.3
info All dependencies
├─ @arcanis/slice-ansi@1.0.2
├─ @emotion/is-prop-valid@0.8.8
├─ @jaredreisinger/react-crossword@2.2.3
├─ @nodelib/fs.scandir@2.1.3
├─ @nodelib/fs.stat@2.0.3
├─ @nodelib/fs.walk@1.2.4
├─ @octetstream/promisify@2.0.2
├─ @sindresorhus/is@3.1.0
├─ @snyk/cli-interface@2.8.1
├─ @snyk/cocoapods-lockfile-parser@3.4.0
├─ @snyk/composer-lockfile-parser@1.4.0
├─ @snyk/dep-graph@1.19.3
├─ @snyk/docker-registry-v2-client@1.13.5
├─ @snyk/gemfile@1.2.0
├─ @snyk/inquirer@6.2.2-patch
├─ @snyk/java-call-graph-builder@1.13.1
├─ @snyk/rpm-parser@2.0.0
├─ @snyk/ruby-semver@2.2.0
├─ @snyk/snyk-cocoapods-plugin@2.3.0
├─ @snyk/snyk-docker-pull@3.2.0
├─ @szmarczak/http-timer@4.0.5
├─ @types/cacheable-request@6.0.1
├─ @types/debug@4.1.5
├─ @types/emscripten@1.39.4
├─ @types/glob@7.1.3
├─ @types/hosted-git-info@2.7.0
├─ @types/http-cache-semantics@4.0.0
├─ @types/js-yaml@3.12.5
├─ @types/keyv@3.1.1
├─ @types/minimatch@3.0.3
├─ @types/responselike@1.0.0
├─ @types/semver@5.5.0
├─ @types/xml2js@0.4.5
├─ @yarnpkg/core@2.1.1
├─ @yarnpkg/json-proxy@2.1.0
├─ @yarnpkg/lockfile@1.1.0
├─ @yarnpkg/pnp@2.1.0
├─ @yarnpkg/shell@2.1.0
├─ ansi-align@3.0.0
├─ ansicolors@0.3.2
├─ any-promise@1.3.0
├─ archy@1.0.0
├─ ast-types@0.13.3
├─ async@1.5.2
├─ babel-plugin-styled-components@1.11.1
├─ bl@4.0.2
├─ boxen@4.2.0
├─ cacheable-lookup@5.0.3
├─ cacheable-request@7.0.1
├─ camelize@1.0.0
├─ child-process@1.0.2
├─ cli-boxes@2.2.0
├─ cli-spinner@0.2.10
├─ crypto-random-string@2.0.0
├─ css-color-keywords@1.0.0
├─ css-to-react-native@3.0.0
├─ data-uri-to-buffer@1.2.0
├─ decompress-response@6.0.0
├─ defer-to-connect@2.0.0
├─ degenerator@1.0.4
├─ docker-modem@2.1.3
├─ dockerfile-ast@0.0.19
├─ dot-prop@5.2.0
├─ dotnet-deps-parser@4.10.0
├─ duplexer3@0.1.4
├─ email-validator@2.0.4
├─ es6-promise@4.2.8
├─ escape-goat@2.1.1
├─ fast-glob@3.2.4
├─ fastq@1.8.0
├─ file-uri-to-path@1.0.0
├─ fs-constants@1.0.0
├─ ftp@0.3.10
├─ get-uri@2.0.4
├─ global-dirs@2.0.1
├─ got@11.5.2
├─ grapheme-splitter@1.0.4
├─ gunzip-maybe@1.4.2
├─ has-yarn@2.1.0
├─ http2-wrapper@1.0.0-beta.5.2
├─ immediate@3.0.6
├─ immer@7.0.7
├─ import-lazy@2.1.0
├─ is-deflate@1.0.0
├─ is-gzip@1.0.0
├─ is-installed-globally@0.3.2
├─ is-npm@4.0.0
├─ is-yarn-global@0.3.0
├─ json-buffer@3.0.1
├─ json-file-plus@3.3.1
├─ jszip@3.3.0
├─ keyv@4.0.1
├─ latest-version@5.1.0
├─ lodash.assignin@4.2.0
├─ lodash.constant@3.0.0
├─ lodash.escaperegexp@4.1.2
├─ lodash.filter@4.6.0
├─ lodash.flatmap@4.5.0
├─ lodash.foreach@4.5.0
├─ lodash.get@4.4.2
├─ lodash.has@4.5.2
├─ lodash.isarray@4.0.0
├─ lodash.isfunction@3.0.9
├─ lodash.isundefined@3.0.1
├─ lodash.keys@4.2.0
├─ lodash.map@4.6.0
├─ lodash.merge@4.6.2
├─ lodash.reduce@4.6.0
├─ lodash.size@4.2.0
├─ lodash.topairs@4.3.0
├─ lodash.transform@4.6.0
├─ lodash.union@4.6.0
├─ lodash.values@4.3.0
├─ logic-solver@2.0.1
├─ macos-release@2.4.1
├─ netmask@1.0.6
├─ node.extend@2.0.2
├─ os-name@3.1.0
├─ p-cancelable@2.0.0
├─ pac-proxy-agent@3.0.1
├─ pac-resolver@3.0.0
├─ package-json@6.5.0
├─ parse-link-header@1.0.1
├─ peek-stream@1.1.3
├─ picomatch@2.2.2
├─ pluralize@7.0.0
├─ promise-deferred@2.0.3
├─ promise-fs@2.1.1
├─ promiseback@2.0.3
├─ proxy-agent@3.1.1
├─ pupa@2.0.1
├─ quick-lru@5.1.1
├─ registry-auth-token@4.2.0
├─ registry-url@5.1.0
├─ resolve-alpn@1.0.0
├─ reusify@1.0.4
├─ run-parallel@1.1.9
├─ secure-keys@1.0.0
├─ semver-diff@3.1.1
├─ smart-buffer@4.1.0
├─ snyk-docker-plugin@3.16.0
├─ snyk-go-parser@1.4.1
├─ snyk-go-plugin@1.16.0
├─ snyk-gradle-plugin@3.5.1
├─ snyk-module@3.1.0
├─ snyk-mvn-plugin@2.19.1
├─ snyk-nodejs-lockfile-parser@1.26.3
├─ snyk-nuget-plugin@1.18.1
├─ snyk-paket-parser@1.6.0
├─ snyk-php-plugin@1.9.0
├─ snyk-policy@1.14.1
├─ snyk-python-plugin@1.17.1
├─ snyk-resolve-deps@4.4.0
├─ snyk-resolve@1.1.0
├─ snyk-sbt-plugin@2.11.0
├─ snyk-try-require@1.3.1
├─ snyk@1.373.0
├─ socks@2.3.3
├─ split-ca@1.0.1
├─ ssh2-streams@0.4.10
├─ ssh2@0.8.9
├─ stream-buffers@3.0.2
├─ stream-to-array@2.3.0
├─ stream-to-promise@2.2.0
├─ streamsearch@0.1.2
├─ styled-components@5.1.1
├─ tar-stream@2.1.3
├─ temp-dir@1.0.0
├─ tempfile@2.0.0
├─ term-size@2.2.0
├─ thunkify@2.1.2
├─ to-readable-stream@1.0.0
├─ toml@3.0.0
├─ tree-kill@1.2.2
├─ tunnel@0.0.6
├─ typedarray-to-buffer@3.1.5
├─ underscore@1.10.2
├─ unique-string@2.0.0
├─ update-notifier@4.1.0
├─ url-parse-lax@3.0.0
├─ vscode-languageserver-types@3.15.1
├─ widest-line@3.1.0
├─ window-size@0.1.4
├─ windows-release@3.3.3
├─ xml2js@0.4.23
├─ xmlbuilder@11.0.1
└─ yaml@1.10.0

Originally posted by @zehawki in #31 (comment)

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions