Dependency Pinning Checker
Pricing
from $4.90 / 1,000 page auditeds
Dependency Pinning Checker
Check dependency manifests, lockfiles, Dockerfiles, and workflow references for exact pinning, floating ranges, missing lockfiles, mutable tags, integrity metadata, and dependency hygiene warnings.
Pricing
from $4.90 / 1,000 page auditeds
Rating
0.0
(0)
Developer
junipr
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
1
Monthly active users
6 days ago
Last modified
Categories
Share
Store Positioning
Store title: Dependency Pinning Checker
Short description: Check dependency manifests, lockfiles, Dockerfiles, and workflow references for exact pinning, floating ranges, missing lockfiles, mutable tags, integrity metadata, and dependency hygiene warnings.
SEO title: Dependency Pinning Checker — technical SEO, web, and domain audit
SEO description: Check dependency manifests, lockfiles, Dockerfiles, and workflow references for exact pinning, floating ranges, missing lockfiles, mutable tags, integrity metadata, and dependency hygiene warnings. Use it to find crawlability, indexability, security, metadata, and page-quality issues with evidence-backed rows and audit reports.
Categories: SEO_TOOLS, AUTOMATION
Keywords: dependency, pinning, checker, data qa, web/domain audit
Pay-Per-Event Pricing
This actor uses pay-per-event pricing. Event prices include Apify platform usage; users are not expected to pay a separate platform-usage pass-through charge for the configured pricing model.
- Tier: W1 — Web/domain audit
- Primary event:
page-auditedat $0.00490 base - Default max charge: $10.00
- Store discounts: FREE/BRONZE base, SILVER discounted, GOLD deepest approved discount
Event set:
actor-start: base $0.00500, GOLD $0.00400. Dependency Pinning Checker: charged when actor start is completed. The price includes Apify platform usage; no separate usage pass-through is intended.page-audited: base $0.00490, GOLD $0.00392. Dependency Pinning Checker: charged when page audited is completed. The price includes Apify platform usage; no separate usage pass-through is intended.record-extracted: base $0.00372, GOLD $0.00298. Dependency Pinning Checker: charged when record extracted is completed. The price includes Apify platform usage; no separate usage pass-through is intended.finding-emitted: base $0.00372, GOLD $0.00298. Dependency Pinning Checker: charged when finding emitted is completed. The price includes Apify platform usage; no separate usage pass-through is intended.audit-report-generated: base $0.05000, GOLD $0.04000. Dependency Pinning Checker: charged when audit report generated is completed. The price includes Apify platform usage; no separate usage pass-through is intended.
The actor accepts actor-start before work, accepts the primary event before each dataset row, and accepts the configured report event before writing report files. If maxChargeUsd or the live PPE limit blocks a charge, the corresponding row or report is not written.
Public Task Concepts
- Audit Dependency Pinning controls on a capped public sample
- Find high-priority Dependency Pinning issues before release
- Validate Dependency Pinning evidence from supplied pages
- Prioritize Dependency Pinning fixes with severity and proof
- Export Dependency Pinning QA rows for client review
Check dependency manifests, lockfiles, Dockerfiles, and workflow references for exact pinning, floating ranges, missing lockfiles, mutable tags, integrity metadata, and dependency hygiene warnings.
What it does
- Accept package manifests, lockfiles, Dockerfiles, workflow YAML, dependency snippets, or public file URLs.
- Support common manifest styles such as npm, Python, Ruby, PHP, Go, Rust, Java, container image tags, and workflow action references where feasible.
- Classify exact pins, ranges, wildcards, floating tags, Git refs, branch refs, digest pins, lockfile presence, and integrity hashes.
- Emit dependency-level rows with manager, package, declared version, pinning status, risk category, and recommendation.
- Generate dependency pinning summary and unpinned dependency report.
What it does not do
- No vulnerability database lookup, license audit, dependency installation, package registry login, or private repo scraping unless content is supplied.
- No guarantee exact pinning is always the right policy.
Input fields
Primary inputs from the locked actor spec: manifestFiles, lockFiles, dockerfiles, workflowFiles, fileUrls, packageManagers, pinningPolicy, allowRanges, requireLockfiles, requireDigestPins, includeDevDependencies, maxFiles, timeoutMs. maxChargeUsd keeps runs capped during production use.
Output fields
Dataset rows include: sourceUrl, filePath, packageManager, dependencyName, dependencyType, declaredVersion, resolvedVersion, pinningStatus, pinningCategory, hasLockfile, hasIntegrityHash, lineNumber, riskCategory, recommendation, evidence.
Starter example
Use examples/input.tiny.json as a small starter input. Keep the first run capped and review the dataset before increasing limits.
Public task examples
- Run Dependency Pinning Checker on supplied sample data: Run Dependency Pinning Checker on supplied sample data using a small bounded input.
- Generate a Dependency Pinning Checker QA report: Generate a Dependency Pinning Checker QA report using a small bounded input.
- Find invalid rows with Dependency Pinning Checker: Find invalid rows with Dependency Pinning Checker using a small bounded input.
- Create a capped local endpoint readiness check for Dependency Pinning Checker: Create a capped local endpoint readiness check for Dependency Pinning Checker using a small bounded input.
- Prepare Dependency Pinning Checker output for downstream automation: Prepare Dependency Pinning Checker output for downstream automation using a small bounded input.
Public source provenance
The starter input checks Express's public package manifest at immutable commit ba006766fb964571723138708eacaba0f55759cd. Public tasks also inspect immutable Docker awesome-compose and actions/checkout files, covering manifests, lockfiles, Python requirements, container images, and action references.
Reports
dependency-pinning-report.mdunpinned-dependencies.csvdependency-pinning-summary.jsonlockfile-coverage.jsoncontainer-image-pin-report.csv
Limitations and safe use
Start with supplied-input runs, then enable live endpoints only with tight caps, domain allowlists, and no secrets in public examples.