Skip to content

Should identify compose packages and validate their checksums #48

@juslintek

Description

@juslintek

Hi,

while scanning encountered really annoying issue, when scanned laravel project or projects with phpunit, there is constant detection of evil functions. Wouldn't it be better to skip these packages, by detected whether composer.json, composer.lock or vendor/autoload.php exists and just scan vendor dir for package files and validate their checksums, instead of file by file scan.

Best regards :-)

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions