Sure, just run `npm install` and try to come up with a reasonable number that will look like something i'll be willing to pay for.
Sure, just run `npm install` and try to come up with a reasonable number that will look like something i'll be willing to pay for.
Crazy to think of how many thousands of man hours have gone into something as simple as allowing me to argue with someone over the internet.
The incentive to report accurately is that subscription benefits only apply to packages we know someone's using. Some of those benefits are dependency analysis results, others are services or assurances. For example, we'd only know to tell them about security vulnerabilities in a package they actually say they use.
You now have a list of everything used by your program. Remove all of the internal imports. That is imports from other parts of your own software. (Hint: this is easy since they are sorted by package name.)
Now you have a list of all third party software used.
I suspect this same procedure works for C / C++ / Python and probably other languages.
You don't have to give anyone your source code to discover what third party and open source software you are using.