# Syft own format, how to distinguish dependency vs devDependency for npm?

**URL:** <https://anchorecommunity.discourse.group/t/syft-own-format-how-to-distinguish-dependency-vs-devdependency-for-npm/151>\
**Category:** Syft\
**Created:** [September 29, 2024, 3:01am UTC](https://anchorecommunity.discourse.group/t/syft-own-format-how-to-distinguish-dependency-vs-devdependency-for-npm/151 "2024-09-29T03:01:56Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![West\_Farmer](https://yyz2.discourse-cdn.com/free1/user_avatar/anchorecommunity.discourse.group/west_farmer/32/118_2.png) [@West\_Farmer](https://anchorecommunity.discourse.group/u/West_Farmer)\
**Post date:** [September 29, 2024, 3:01am UTC](https://anchorecommunity.discourse.group/t/syft-own-format-how-to-distinguish-dependency-vs-devdependency-for-npm/151/1 "2024-09-29T03:01:56Z")

</div>

Also, where is the docs for syft’s own format?

---

<div class="post-metadata">

**Author:** ![spiffcs](https://yyz2.discourse-cdn.com/free1/user_avatar/anchorecommunity.discourse.group/spiffcs/32/14_2.png) [@spiffcs](https://anchorecommunity.discourse.group/u/spiffcs)\
**Post date:** [October 2, 2024, 7:57pm UTC](https://anchorecommunity.discourse.group/t/syft-own-format-how-to-distinguish-dependency-vs-devdependency-for-npm/151/2 "2024-10-02T19:57:39Z")

</div>

👋 Thanks for the question @West_Farmer!

Currently we’re looking to enhance the npm cataloger to include dev dependencies in the final SBOM for a directory scan.

Take for example the npm cli: `https://github.com/npm/cli`

If we scan this with Syft we don’t see packages like `@npmcli/eslint-config` or `mock-globals`.

Here is a link to the current code that parses this:

> <https://github.com/anchore/syft/blob/263ea6b1bb7a250fb7134de5722072d3ce5b1294/syft/pkg/cataloger/javascript/parse_package_json.go#L24C1-L38C1>

As far as documentation for syft’s own format here isa link to the current [schema](https://raw.githubusercontent.com/anchore/syft/refs/heads/main/schema/json/schema-16.0.17.json).

We’re working on getting more formal documentation generated around the schema, but until then I would recommend dumping the above raw data into a visualizer like [https://json-schema-viewer.vercel.app](https://json-schema-viewer.vercel.app)
