Fixed
- If reproducible flag enabled, SBOM result's
bom-ref
for alias/duplicated components are reproducible (#1351 via #1352)
What's Changed
- fix: have unique bomRefs for duplicated package installs by @jkowalleck in #1352
- chore(deps): bump the eslint group across 1 directory with 4 updates by @dependabot[bot] in #1348
- chore(deps): bump the eslint group across 1 directory with 5 updates by @dependabot[bot] in #1353
Full Changelog: v4.0.2...v4.0.3