Supply chain toolsLocal review / optional AI
Supply chain / FREE TOOL
Lockfile diff
See what a dependency update really changed. Compare versions, download sources, integrity hashes, and installation hooks.
02 Your results
A closer look starts here.
Add your input and run the check. We will show the observations and explain what needs review.
A QUICK WALKTHROUGH
How to use it
- 01Add the previous and proposed npm lockfiles.
- 02Compare added, removed, and changed packages.
- 03Review unexpected sources and install hooks before merging.
What this check can tell you
Compares npm lockfile metadata by installation path. An integrity change is a review signal, not evidence of compromise. Yarn, pnpm, and npm v1 lockfiles are not supported.
The initial review processes files in this tab. If you choose the optional AI summary, the displayed findings are sent to Cloudflare AI; your raw file, result tables and decoded token claims are excluded.
npm lockfile format