For this specific case (and maybe for other node based applications), couldn’t the scanner be updated to look for a package-lock.json and if it exists, check the packages.engines value?
For this specific case (and maybe for other node based applications), couldn’t the scanner be updated to look for a package-lock.json and if it exists, check the packages.engines value?