← All tools

Dependency Lockfile Auditor

Inspect dependency structure and provenance locally without contacting package registries.

Structural inspection only: this tool does not determine vulnerabilities, licenses, package authenticity, freshness, installability, or whether a recorded checksum is correct. Supported inputs: npm package-lock v2/v3, Yarn classic v1, pnpm lockfile 5.4/6/9 subset, and Poetry lock metadata 1.1/2.0/2.1 subset.

Limits: 2 MiB, 50,000 lines, 25,000 package records, 100,000 dependency edges. Credentials in common URL locations are masked before display or export.

Page 0 of 0
Audited package records
Package Version Scope / flags Source Integrity Inbound declarations

Duplicate-version families

Run an audit.

Highest inbound dependency declarations

Run an audit.