node_modules
, and if it finds that, it scans for npm, if it finds bower.json
, it scans with bower. We don't have an option where it merges them quite yet. sonatype-nexus-community/auditjs#178 is an issue to give an option to force a bower scan, since we realized people might be using BOTH!