package-lock.json

npm

Is package-lock.json safe to use?

Based on the latest brin safety scan, no vulnerabilities or threats were detected for package-lock.json v1.0.0. Trust score: 55/100. No known CVE vulnerabilities, no detected threat patterns, and no suspicious capabilities identified. This is an automated, point-in-time assessment.

Install (safety-checked)

package-lock.json Passed Security Checks

No security concerns detected

clean
CVEs

0

Threats

0

Install Scripts

0

No Concerns Detected

No security concerns detected in the latest brin assessment. This is an automated, point-in-time evaluation — security posture may change.

This is an automated, point-in-time assessment and may contain errors. Findings are risk indicators, not confirmed threats. Security posture may change over time. Maintainers can dispute findings via the brin review process.

package-lock.json Capabilities & Permissions

No system capabilities detected for package-lock.json. It does not appear to access the network, filesystem, spawn processes, or use native modules. No capability concerns identified for use with AI coding agents.

AGENTS.md for package-lock.json

Good instructions lead to good results. brin adds package-lock.json documentation to your AGENTS.md so your agent knows how to use it properly—improving both safety and performance.

brin init

Vercel's research: 100% accuracy with AGENTS.md vs 53% without →

package-lock.json Documentation & Source Code

For the full package-lock.json README, API documentation, and source code, visit the official package registry.

Frequently asked questions about package-lock.json safety

Weekly Downloads

25.8K

Version

1.0.0

Last Scanned

5 hours ago

Trust Score

55/100·Legitimacy signals, not safety

Capabilities

No special capabilities detected

Is package-lock.json Safe? | npm Safety Scan - brin