Allow filtering out of dev dependencies
Release notes
Problem to solve
Some people want to know about Dev dependencies, and some do not (as they are not deployed)
we should allow them to be scanned, or skipped
in addition we should allow them to be shown or not in SBOM
in addition, we should be able to auto-close findings related to them if someone wants (i.e. they want to know but not be bothered with unless they need to dig)
this is a duplicate but i can't find the other issue