Neatbo.

npm lock declared-copy inventory

Inspect package-lock v2/v3 installation declarations and separate repeated names, aliases, links, workspaces and unknown versions.

Browser-local processingInputpackage-lock v2 / v3 JSONOutputJSON / CSVUp to 1 MiB per file · File limit: 1
  1. 1Add input
  2. 2Review and run
  3. 3Get your result

Tool input and files are processed in this browser without being uploaded.

Your input

Inputs are kept temporarily in this tab when switching tools. Refreshing or closing clears them; large results may need to be regenerated.

⌘ / Ctrl + Enter to run

or drag and drop it here

Files stay on this device. Your originals stay unchanged.

.json

Up to 1 MiB per file · File limit: 1

    0 characters · 0 bytes
    Preparing the tool…

    Before you start

    Review what a lockfile declares before investigating dependency duplication. Preserve installation paths and versions without assuming that every entry exists on disk.

    How to use this tool

    1. Paste or open package-lock.json and confirm that its version is 2 or 3.
    2. Inspect declared copies and repeated names, then review aliases, links, workspaces and unknown versions separately.
    3. Download the JSON snapshot or path-level CSV. Use package-manager and filesystem checks separately before changing dependencies.

    Supported inputs and limits

    One UTF-8 package-lock JSON file or pasted input up to 1 MiB; a selected file takes precedence. Supports lockfileVersion 2 or 3 with a packages object, up to 10,000 entries and 512-character relative paths. Duplicate JSON keys and invalid descriptors/paths are rejected.

    The root package entry is excluded from copies. Non-link node_modules entries are installation declarations, and repeated descriptor names are grouped across paths. An explicit name differing from the install slot is classified as an alias. Missing versions stay unknown; version strings are not assumed to be SemVer.

    link:true entries are listed separately with their declared targets, and non-node_modules locations are workspace declarations. v2 legacy dependencies are ignored when packages is read, so the compatibility snapshot is not counted twice. The source kind is a label only; URLs and local targets are never opened.

    This is a lockfile snapshot, not a disk scan, installation verification, vulnerability audit or proof that npm can dedupe packages. JSON keeps exact declared versions; CSV uses spreadsheet-safe cells. Preview shows up to 200 installation declarations.

    Worked example

    Example input

    {"lockfileVersion":3,"packages":{"":{},"node_modules/a":{"version":"1.0.0"},"node_modules/b/node_modules/a":{"version":"2.0.0"}}}
    Example options
    {"params": {}}

    Example output

    {
      "lockfileVersion": "3",
      "snapshot": "lockfile declarations only",
      "copies": [
        {
          "path": "node_modules/a",
          "slotName": "a",
          "name": "a",
          "alias": false,
          "version": "1.0.0",
          "sourceKind": "unspecified"
        },
        {
          "path": "node_modules/b/node_modules/a",
          "slotName": "a",
          "name": "a",
          "alias": false,
          "version": "2.0.0",
          "sourceKind": "unspecified"
        }
      ],
      "duplicates": [
        {
          "name": "a",
          "copies": 2,
          "versions": [
            "1.0.0",
            "2.0.0"
          ],
          "paths": [
            "node_modules/a",
            "node_modules/b/node_modules/a"
          ]
        }
      ],
      "links": [],
      "workspaces": []
    }

    When something does not work

    Use a v2/v3 lockfile with a packages object. Fix malformed/duplicate-key JSON and invalid relative paths or descriptor types. For older formats, create a current lockfile with the project’s package manager before inspecting it.

    Frequently asked questions

    Are these packages definitely installed?

    No. The report reads declarations from the supplied lockfile and does not inspect node_modules on disk.

    Can every repeated package name be deduplicated?

    No. Version and dependency constraints, links and installation layout require a separate package-manager analysis.

    Why is an entry’s version unknown?

    Some descriptors do not declare version. The report keeps that absence visible rather than guessing from resolved URLs.

    Documentation & further reading

    Related tools