npm Lockfile Security Auditor avatar

npm Lockfile Security Auditor

Pricing

from $6.00 / 1,000 npm lockfile security audits

Go to Apify Store
npm Lockfile Security Auditor

npm Lockfile Security Auditor

Audit package-lock.json files for missing integrity, insecure or non-registry sources, install scripts, duplicate versions and unsupported formats.

Pricing

from $6.00 / 1,000 npm lockfile security audits

Rating

0.0

(0)

Developer

Q Services

Q Services

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

2 days ago

Last modified

Categories

Share

Audit package-lock.json files without contacting npm. The Actor checks integrity digests, source transport and registries, Git or local dependencies, install scripts, lockfile formats, non-ASCII names and duplicate package versions.

Input

  • lockfiles: lockfile objects, JSON strings, or { name, content } objects.
  • allowedRegistries: registry host allowlist.
  • allowInstallScripts: lower install-script findings to informational.
  • maxResults: maximum lockfiles to process.

Output

One dataset item per lockfile with package counters, score and structured findings. Package contents and credentials are never fetched.

Pricing

Pay per event: one actor-start event per run and one dataset-item event per completed lockfile audit.