npm lock declared-copy inventory
Inspect package-lock v2/v3 installation declarations and separate repeated names, aliases, links, workspaces and unknown versions.
- 1Add input
- 2Review and run
- 3Get your result
Tool input and files are processed in this browser without being uploaded.
Before you start
Review what a lockfile declares before investigating dependency duplication. Preserve installation paths and versions without assuming that every entry exists on disk.
How to use this tool
- Paste or open package-lock.json and confirm that its version is 2 or 3.
- Inspect declared copies and repeated names, then review aliases, links, workspaces and unknown versions separately.
- Download the JSON snapshot or path-level CSV. Use package-manager and filesystem checks separately before changing dependencies.
Supported inputs and limits
One UTF-8 package-lock JSON file or pasted input up to 1 MiB; a selected file takes precedence. Supports lockfileVersion 2 or 3 with a packages object, up to 10,000 entries and 512-character relative paths. Duplicate JSON keys and invalid descriptors/paths are rejected.
The root package entry is excluded from copies. Non-link node_modules entries are installation declarations, and repeated descriptor names are grouped across paths. An explicit name differing from the install slot is classified as an alias. Missing versions stay unknown; version strings are not assumed to be SemVer.
link:true entries are listed separately with their declared targets, and non-node_modules locations are workspace declarations. v2 legacy dependencies are ignored when packages is read, so the compatibility snapshot is not counted twice. The source kind is a label only; URLs and local targets are never opened.
This is a lockfile snapshot, not a disk scan, installation verification, vulnerability audit or proof that npm can dedupe packages. JSON keeps exact declared versions; CSV uses spreadsheet-safe cells. Preview shows up to 200 installation declarations.
Worked example
Example input
{"lockfileVersion":3,"packages":{"":{},"node_modules/a":{"version":"1.0.0"},"node_modules/b/node_modules/a":{"version":"2.0.0"}}}Example options
{"params": {}}Example output
{
"lockfileVersion": "3",
"snapshot": "lockfile declarations only",
"copies": [
{
"path": "node_modules/a",
"slotName": "a",
"name": "a",
"alias": false,
"version": "1.0.0",
"sourceKind": "unspecified"
},
{
"path": "node_modules/b/node_modules/a",
"slotName": "a",
"name": "a",
"alias": false,
"version": "2.0.0",
"sourceKind": "unspecified"
}
],
"duplicates": [
{
"name": "a",
"copies": 2,
"versions": [
"1.0.0",
"2.0.0"
],
"paths": [
"node_modules/a",
"node_modules/b/node_modules/a"
]
}
],
"links": [],
"workspaces": []
}When something does not work
Use a v2/v3 lockfile with a packages object. Fix malformed/duplicate-key JSON and invalid relative paths or descriptor types. For older formats, create a current lockfile with the project’s package manager before inspecting it.
Frequently asked questions
Are these packages definitely installed?
No. The report reads declarations from the supplied lockfile and does not inspect node_modules on disk.
Can every repeated package name be deduplicated?
No. Version and dependency constraints, links and installation layout require a separate package-manager analysis.
Why is an entry’s version unknown?
Some descriptors do not declare version. The report keeps that absence visible rather than guessing from resolved URLs.
Documentation & further reading
Related tools
JSON formatting workspace
Format or minify strict JSON, sort object keys, and encode or decode strings while preserving raw number tokens.
Regex tester
Try a pattern and see what it matches in your text.
Compare text
See what changed, side by side.
HTML formatter
Format HTML indentation so its structure is easier to read.