# Dependency Pinning Checker (`junipr/dependency-pinning-checker`) Actor

Check dependency manifests, lockfiles, Dockerfiles, and workflow references for exact pinning, floating ranges, missing lockfiles, mutable tags, integrity metadata, and dependency hygiene warnings.

- **URL**: https://apify.com/junipr/dependency-pinning-checker.md
- **Developed by:** [junipr](https://apify.com/junipr) (community)
- **Categories:** SEO tools, Automation
- **Stats:** 2 total users, 1 monthly users, 100.0% runs succeeded, 0 bookmarks
- **User rating**: No ratings yet

## Pricing

from $4.90 / 1,000 page auditeds

This Actor is paid per event. You are not charged for the Apify platform usage, but only a fixed price for specific events.

Learn more: https://docs.apify.com/platform/actors/running/actors-in-store#pay-per-event

## What's an Apify Actor?

Actors are web data automations that power AI and operations. They run on the Apify platform to scrape websites, process data, connect APIs, and automate workflows.
In Batch mode, an Actor accepts a well-defined JSON input, performs an action which can take anything from a few seconds to a few hours,
and optionally produces a well-defined JSON output, datasets with results, or files in key-value store.
In Standby mode, an Actor provides a web server which can be used as a website, API, or an MCP server.
Actors are written with capital "A".

## How to integrate an Actor?

If asked about integration, you help developers integrate Actors into their projects.
You adapt to their stack and deliver integrations that are safe, well-documented, and production-ready.
The best way to integrate Actors is as follows.

- **AI agents and MCP clients** — the [Apify MCP server](https://docs.apify.com/integrations/mcp.md) at `https://mcp.apify.com` (remote, streamable HTTP, OAuth on first use).
- **Agentic workflows and local Actor development** — [Agent Skills](https://apify.com/.well-known/agent-skills/index.json) with the [Apify CLI](https://docs.apify.com/cli/docs.md): `npm install -g apify-cli`, then `apify login`.
- **JavaScript/TypeScript projects** — the official [JS/TS client](https://docs.apify.com/api/client/js/docs.md): `npm install apify-client`.
- **Python projects** — the official [Python client](https://docs.apify.com/api/client/python/docs.md): `pip install apify-client`.
- **Any other language** — the [REST API](https://docs.apify.com/api/v2.md).

For usage examples, see the [API](#api) section below.

For more details, see Apify documentation as [Markdown index](https://docs.apify.com/llms.txt) and [Markdown full-text](https://docs.apify.com/llms-full.txt).

# README

## Dependency Pinning Checker

### Store Positioning

**Store title:** Dependency Pinning Checker

**Short description:** Check dependency manifests, lockfiles, Dockerfiles, and workflow references for exact pinning, floating ranges, missing lockfiles, mutable tags, integrity metadata, and dependency hygiene warnings.

**SEO title:** Dependency Pinning Checker — technical SEO, web, and domain audit

**SEO description:** Check dependency manifests, lockfiles, Dockerfiles, and workflow references for exact pinning, floating ranges, missing lockfiles, mutable tags, integrity metadata, and dependency hygiene warnings. Use it to find crawlability, indexability, security, metadata, and page-quality issues with evidence-backed rows and audit reports.

**Categories:** SEO\_TOOLS, AUTOMATION

**Keywords:** dependency, pinning, checker, data qa, web/domain audit

### Pay-Per-Event Pricing

This actor uses pay-per-event pricing. Event prices include Apify platform usage; users are not expected to pay a separate platform-usage pass-through charge for the configured pricing model.

- Tier: W1 — Web/domain audit
- Primary event: `page-audited` at $0.00490 base
- Default max charge: $10.00
- Store discounts: FREE/BRONZE base, SILVER discounted, GOLD deepest approved discount

Event set:

- `actor-start`: base $0.00500, GOLD $0.00400. Dependency Pinning Checker: charged when actor start is completed. The price includes Apify platform usage; no separate usage pass-through is intended.
- `page-audited`: base $0.00490, GOLD $0.00392. Dependency Pinning Checker: charged when page audited is completed. The price includes Apify platform usage; no separate usage pass-through is intended.
- `record-extracted`: base $0.00372, GOLD $0.00298. Dependency Pinning Checker: charged when record extracted is completed. The price includes Apify platform usage; no separate usage pass-through is intended.
- `finding-emitted`: base $0.00372, GOLD $0.00298. Dependency Pinning Checker: charged when finding emitted is completed. The price includes Apify platform usage; no separate usage pass-through is intended.
- `audit-report-generated`: base $0.05000, GOLD $0.04000. Dependency Pinning Checker: charged when audit report generated is completed. The price includes Apify platform usage; no separate usage pass-through is intended.

The actor accepts `actor-start` before work, accepts the primary event before each dataset row, and accepts the configured report event before writing report files. If `maxChargeUsd` or the live PPE limit blocks a charge, the corresponding row or report is not written.

### Public Task Concepts

- Audit Dependency Pinning controls on a capped public sample
- Find high-priority Dependency Pinning issues before release
- Validate Dependency Pinning evidence from supplied pages
- Prioritize Dependency Pinning fixes with severity and proof
- Export Dependency Pinning QA rows for client review

Check dependency manifests, lockfiles, Dockerfiles, and workflow references for exact pinning, floating ranges, missing lockfiles, mutable tags, integrity metadata, and dependency hygiene warnings.

### What it does

- Accept package manifests, lockfiles, Dockerfiles, workflow YAML, dependency snippets, or public file URLs.
- Support common manifest styles such as npm, Python, Ruby, PHP, Go, Rust, Java, container image tags, and workflow action references where feasible.
- Classify exact pins, ranges, wildcards, floating tags, Git refs, branch refs, digest pins, lockfile presence, and integrity hashes.
- Emit dependency-level rows with manager, package, declared version, pinning status, risk category, and recommendation.
- Generate dependency pinning summary and unpinned dependency report.

### What it does not do

- No vulnerability database lookup, license audit, dependency installation, package registry login, or private repo scraping unless content is supplied.
- No guarantee exact pinning is always the right policy.

### Input fields

Primary inputs from the locked actor spec: `manifestFiles`, `lockFiles`, `dockerfiles`, `workflowFiles`, `fileUrls`, `packageManagers`, `pinningPolicy`, `allowRanges`, `requireLockfiles`, `requireDigestPins`, `includeDevDependencies`, `maxFiles`, `timeoutMs`. `maxChargeUsd` keeps runs capped during production use.

### Output fields

Dataset rows include: `sourceUrl`, `filePath`, `packageManager`, `dependencyName`, `dependencyType`, `declaredVersion`, `resolvedVersion`, `pinningStatus`, `pinningCategory`, `hasLockfile`, `hasIntegrityHash`, `lineNumber`, `riskCategory`, `recommendation`, `evidence`.

### Starter example

Use `examples/input.tiny.json` as a small starter input. Keep the first run capped and review the dataset before increasing limits.

### Public task examples

- Run Dependency Pinning Checker on supplied sample data: Run Dependency Pinning Checker on supplied sample data using a small bounded input.
- Generate a Dependency Pinning Checker QA report: Generate a Dependency Pinning Checker QA report using a small bounded input.
- Find invalid rows with Dependency Pinning Checker: Find invalid rows with Dependency Pinning Checker using a small bounded input.
- Create a capped local endpoint readiness check for Dependency Pinning Checker: Create a capped local endpoint readiness check for Dependency Pinning Checker using a small bounded input.
- Prepare Dependency Pinning Checker output for downstream automation: Prepare Dependency Pinning Checker output for downstream automation using a small bounded input.

### Public source provenance

The starter input checks Express's public package manifest at immutable commit `ba006766fb964571723138708eacaba0f55759cd`. Public tasks also inspect immutable Docker `awesome-compose` and `actions/checkout` files, covering manifests, lockfiles, Python requirements, container images, and action references.

### Reports

- `dependency-pinning-report.md`
- `unpinned-dependencies.csv`
- `dependency-pinning-summary.json`
- `lockfile-coverage.json`
- `container-image-pin-report.csv`

### Limitations and safe use

Start with supplied-input runs, then enable live endpoints only with tight caps, domain allowlists, and no secrets in public examples.

# Actor input Schema

## `manifestFiles` (type: `array`):

Manifest Files to inspect during the run.

## `lockFiles` (type: `array`):

Lock Files to inspect during the run.

## `dockerfiles` (type: `array`):

Dockerfiles to inspect during the run.

## `workflowFiles` (type: `array`):

Workflow Files to inspect during the run.

## `fileUrls` (type: `array`):

Public file URLs to fetch or inspect for Dependency Pinning Checker.

## `packageManagers` (type: `array`):

Package Managers controls Dependency Pinning Checker processing for the supplied inputs; keep values conservative for first runs.

## `pinningPolicy` (type: `string`):

Pinning Policy that determines how findings are classified.

## `allowRanges` (type: `boolean`):

Allow Ranges controls Dependency Pinning Checker processing for the supplied inputs; keep values conservative for first runs.

## `requireLockfiles` (type: `boolean`):

Require lockfiles during validation and flag rows that do not meet the rule.

## `requireDigestPins` (type: `boolean`):

Require digest pins during validation and flag rows that do not meet the rule.

## `includeDevDependencies` (type: `boolean`):

Include dev dependencies in output rows or reports when available.

## `maxFiles` (type: `number`):

Maximum files to process in one run; keep defaults low for safe first runs.

## `timeoutMs` (type: `number`):

Maximum time in milliseconds allowed for the Dependency Pinning Checker operation before it is treated as timed out.

## `maxChargeUsd` (type: `number`):

Maximum estimated PPE charge allowed for the run before the actor stops gracefully.

## Actor input object example

```json
{
  "manifestFiles": [],
  "lockFiles": [],
  "dockerfiles": [],
  "workflowFiles": [],
  "fileUrls": [
    "https://raw.githubusercontent.com/expressjs/express/ba006766fb964571723138708eacaba0f55759cd/package.json"
  ],
  "packageManagers": [
    "npm",
    "docker",
    "python",
    "github-actions"
  ],
  "pinningPolicy": "strict",
  "allowRanges": false,
  "requireLockfiles": true,
  "requireDigestPins": true,
  "includeDevDependencies": true,
  "maxFiles": 1,
  "timeoutMs": 10000,
  "maxChargeUsd": 1
}
```

# API

You can run this Actor programmatically using our API. Below are code examples in JavaScript, Python, and CLI, as well as the OpenAPI specification and MCP server setup.

## JavaScript example

```javascript
import { ApifyClient } from 'apify-client';

// Initialize the ApifyClient with your Apify API token
// Replace the '<YOUR_API_TOKEN>' with your token
const client = new ApifyClient({
    token: '<YOUR_API_TOKEN>',
});

// Prepare Actor input
const input = {};

// Run the Actor and wait for it to finish
const run = await client.actor("junipr/dependency-pinning-checker").call(input);

// Fetch and print Actor results from the run's dataset (if any)
console.log('Results from dataset');
console.log(`💾 Check your data here: https://console.apify.com/storage/datasets/${run.defaultDatasetId}`);
const { items } = await client.dataset(run.defaultDatasetId).listItems();
items.forEach((item) => {
    console.dir(item);
});

// 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/js/docs

```

## Python example

```python
from apify_client import ApifyClient

# Initialize the ApifyClient with your Apify API token
# Replace '<YOUR_API_TOKEN>' with your token.
client = ApifyClient("<YOUR_API_TOKEN>")

# Prepare the Actor input
run_input = {}

# Run the Actor and wait for it to finish
run = client.actor("junipr/dependency-pinning-checker").call(run_input=run_input)

# Fetch and print Actor results from the run's dataset (if there are any)
print(f"💾 Check your data here: https://console.apify.com/storage/datasets/{run.default_dataset_id}")
for item in client.dataset(run.default_dataset_id).iterate_items():
    print(item)

# 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/python/docs/quick-start

```

## CLI example

```bash
echo '{}' |
apify call junipr/dependency-pinning-checker --silent --output-dataset

```

## MCP server setup

```json
{
    "mcpServers": {
        "apify": {
            "type": "http",
            "url": "https://mcp.apify.com/?tools=fetch-actor-details,junipr/dependency-pinning-checker"
        }
    }
}

```

The hosted server signs you in with OAuth on first connect, so no API token belongs in this config. Clients without OAuth support can send an `Authorization: Bearer <APIFY_API_TOKEN>` header instead, using a token from API & Integrations in Apify Console (https://console.apify.com/settings/integrations).

## OpenAPI specification

Download the OpenAPI definition: https://api.apify.com/v2/actors/4OyUKaLhVjmWqv5xg/builds/4whyX4aU9qvjGVUZH/openapi.json
