package-analysis
package-analysis copied to clipboard
Save analyzed packages
Sometimes package versions are removed from package registries. We should save them somewhere so we can go back and reference them from our results.
It also appears as though packages are not immutable for the same version.
I suspect we want to name them based on a hash of the file (or the integrity data from npm)