Package management nerd. Creator of @octoboxio, @Librariesio, @24pullrequests and co-host of @manifestpodcast.
Yeah we take transitive dependencies into account for all package managers that have a concept of a lockfile
Agreed, that area really is not very clear, it’s high on my todo list to make the output and explanations much better with less double negatives!
justin maurer Thanks! Bitbucket support is on the todo list but might take a couple of months to complete