Supply chain toolsLocal review / optional AI
Supply chain / FREE TOOL
npm configuration review
Catch the quiet configuration risks: insecure registries, disabled TLS checks, and credentials with overly broad scope.
02 Your results
A closer look starts here.
Add your input and run the check. We will show the observations and explain what needs review.
A QUICK WALKTHROUGH
How to use it
- 01Paste an .npmrc file, preferably with token values removed.
- 02Review transport and authentication settings.
- 03Check effective configuration in your actual build environment.
What this check can tell you
Reviews this file only. Environment variables, user configuration, command-line overrides, and npm version can change effective behavior. Credential values are omitted from results.
The initial review processes files in this tab. If you choose the optional AI summary, the displayed findings are sent to Cloudflare AI; your raw file, result tables and decoded token claims are excluded.
npm configuration and credential scoping