Skip to main content
Supply chain tools

Supply chain / FREE TOOL

Lockfile diff

See what a dependency update really changed. Compare versions, download sources, integrity hashes, and installation hooks.

Local review / optional AI

01 Your input

Local processing only. Maximum file size: 2 MB.

02 Your results

A closer look starts here.

Add your input and run the check. We will show the observations and explain what needs review.

 

A QUICK WALKTHROUGH

How to use it

  1. 01Add the previous and proposed npm lockfiles.
  2. 02Compare added, removed, and changed packages.
  3. 03Review unexpected sources and install hooks before merging.

What this check can tell you

Compares npm lockfile metadata by installation path. An integrity change is a review signal, not evidence of compromise. Yarn, pnpm, and npm v1 lockfiles are not supported.

The initial review processes files in this tab. If you choose the optional AI summary, the displayed findings are sent to Cloudflare AI; your raw file, result tables and decoded token claims are excluded.

npm lockfile format