Package manager
|
Version(s)
|
Language(s)
|
File name(s)
|
Bundler
|
>2.5
|
Ruby
|
gems.locked
|
Cargo
|
All
|
Rust
|
Cargo.toml, Cargo.lock
|
Composer
|
>1.0.0
|
PHP
|
composer.json, composer.lock
|
Conan
|
>2.0
|
C, C++
|
conanfile.txt, conan.lock, conanfile.py
|
CycloneDX (SBOM)
|
All
|
Multi-language
|
cyclonedx.json
|
Docker images
|
All
|
Docker
|
N/A
|
GitHub Actions
|
All
|
YAML
|
workflows.yaml
|
Go Package Manager
|
All
|
Go |
go.mod
|
Gradle
|
>5.1
|
Java
|
.gradle, build.gradle.kts
|
Gradle Wrapper
|
All
|
Java
|
gradle-wrapper.properties
|
Hex
|
All
|
Erlang
|
mix.exs, mix.lock
|
Libraries delivered via CDN
|
All
|
HTML
|
.html |
Maven
|
>3.0.0
|
Java
|
pom.xml
|
npm
|
1 to 3
|
JavaScript/TypeScript
|
package.json, package-lock.json
|
NuGet
|
All
|
C#
|
csproj, myapp.exe.config, packages.config, packages.lock.json
|
pip
|
>20.0
|
Python
|
requirements.txt
|
Pipenv
|
>1.0.0
|
Python
|
Pipfile, Pipfile.lock
|
pnpm
|
1
|
JavaScript/TypeScript
|
package.json, pnpm-lock.yaml
|
Poetry
|
>1.0.0
|
Python
|
poetry.lock, pyproject.toml
|
Pub
|
All
|
Dart
|
pubspec.yaml
|
RubyGems
|
>3.5
|
Ruby
|
Gemfile, Gemfile.lock
|
sbt
|
All
|
Java
|
build.sbt
|
SPDX (SBOM) |
All
|
Multi-language
|
spdx.json
|
Swift Package Manager
|
All
|
Swift
|
Packages.resolved
|
Yarn
|
1
|
JavaScript/TypeScript
|
package.json, yarn.lock
|