Option 1: Adding feature to npm/composer/gem/pip ad infinitum
Option 2: add per-language parser support to the alerting tool instead.
Option 2 doesn't necessitate a new (information-duplicating, still potentially error prone) standard, and can likely leverage available, tested libraries ;-)
Option 1: Adding feature to npm/composer/gem/pip ad infinitum
Option 2: add per-language parser support to the alerting tool instead.
Option 2 doesn't necessitate a new (information-duplicating, still potentially error prone) standard, and can likely leverage available, tested libraries ;-)