Skip to content

fix(report): restore lockfileSource to report.json payload (#1263) - #1268

Open
Fire162 wants to merge 1 commit into
OWASP:mainfrom
Fire162:fix/report-json-lockfile-source
Open

Fire162 wants to merge 1 commit into
OWASP:mainfrom
Fire162:fix/report-json-lockfile-source

Conversation

@Fire162

@Fire162 Fire162 commented Oct 2, 2026

Copy link
Copy Markdown

What changed and why

Restores lockfileSource to report.json alongside scannedAt and cliVersion in handleSingleFolderScan (src/scan/single-scan.ts).

When #1176 unified report.json with the --json payload builder, lockfileSource was omitted because it is not part of the standard --json output. Adding lockfileSource: reportData.lockfileSource to jsonPayload restores the field so report.json remains a strict superset of the --json shape.

Also updates test assertions in tests/html-reporter.test.ts and tests/e2e/validation-and-outputs.test.ts to verify lockfileSource presence in report.json and absence from the standard --json payload.

Closes #1263

@Fire162
Fire162 requested a review from sonukapoor as a code owner October 2, 2026 12:27

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix(report): report.json lost lockfileSource when it was unified with --json

1 participant