npm Lockfile Security Auditor
Pricing
from $6.00 / 1,000 npm lockfile security audits
npm Lockfile Security Auditor
Audit package-lock.json files for missing integrity, insecure or non-registry sources, install scripts, duplicate versions and unsupported formats.
Pricing
from $6.00 / 1,000 npm lockfile security audits
Rating
0.0
(0)
Developer
Q Services
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
1
Monthly active users
2 days ago
Last modified
Categories
Share
Audit package-lock.json files without contacting npm. The Actor checks integrity
digests, source transport and registries, Git or local dependencies, install
scripts, lockfile formats, non-ASCII names and duplicate package versions.
Input
lockfiles: lockfile objects, JSON strings, or{ name, content }objects.allowedRegistries: registry host allowlist.allowInstallScripts: lower install-script findings to informational.maxResults: maximum lockfiles to process.
Output
One dataset item per lockfile with package counters, score and structured findings. Package contents and credentials are never fetched.
Pricing
Pay per event: one actor-start event per run and one dataset-item event per
completed lockfile audit.