# lockfile-prune

> Lockfiles have needs too and this package takes care of them

Latest version **1.0.4** (published 2026-05-17) · Apache-2.0 license · 0 weekly downloads

## Install

```sh
npm install lockfile-prune
pnpm add lockfile-prune
yarn add lockfile-prune
bun add lockfile-prune
```

Provides the command `lockfile-prune`.

## Health

**Score 55/100 (C)** — status: active.

Positive: no vulnerabilities; has provenance; high maintenance score.

Warnings: low downloads; no types; no esm support.

## Facts

| | |
|---|---|
| Version | 1.0.4 |
| Published | 2026-05-17 |
| First published | 2020-04-25 |
| Weekly downloads | 0 |
| License | Apache-2.0 |
| TypeScript types | none |
| Module format | CommonJS |
| Node | >=10.0.0 |
| Dependencies | 1 |
| Unpacked size | 677.8 KB |
| Known vulnerabilities | 0 |
| Install scripts | no |
| Provenance | attested (GitHub Actions) |
| GitHub stars | 4 |
| Author | Liran Tal |
| Maintainers | lirantal, lirantal_bot |
| Keywords | lockfile, shrinkwrap, prune, package-lock, package-lock.json |

## Links

- npm: https://www.npmjs.com/package/lockfile-prune
- Repository: https://github.com/lirantal/lockfile-prune
- Issues: https://github.com/lirantal/lockfile-prune/issues
- npm.io page: https://npm.io/package/lockfile-prune

## Dependencies (1)

- [debug](https://npm.io/package/debug.md) ^4.1.1

## Alternatives

- [@mapbox/jsonlint-lines-primitives](https://npm.io/package/@mapbox/jsonlint-lines-primitives.md) — 5.3M weekly downloads
- [reftools](https://npm.io/package/reftools.md) — 3.5M weekly downloads
- [@hey-api/openapi-ts](https://npm.io/package/@hey-api/openapi-ts.md) — 3.5M weekly downloads
- [@mapbox/geojson-rewind](https://npm.io/package/@mapbox/geojson-rewind.md) — 2.4M weekly downloads
- [turbo-stream](https://npm.io/package/turbo-stream.md) — 1.7M weekly downloads

## Recent versions

- 1.0.4 (latest) — 2026-05-17
- 1.0.3 — 2026-05-17
- 1.0.2 — 2026-04-29
- 1.0.1 — 2026-04-27
- 1.0.0 — 2020-04-25

## README

<p align="center"><h1 align="center">
  lockfile-prune
</h1>

<p align="center">
  Lockfiles have needs too and this package takes care of them
</p>

<p align="center">
  <a href="https://www.npmjs.org/package/lockfile-prune"><img src="https://badgen.net/npm/v/lockfile-prune" alt="npm version"/></a>
  <a href="https://www.npmjs.org/package/lockfile-prune"><img src="https://badgen.net/npm/license/lockfile-prune" alt="license"/></a>
  <a href="https://www.npmjs.org/package/lockfile-prune"><img src="https://badgen.net/npm/dt/lockfile-prune" alt="downloads"/></a>
  <a href="https://github.com/lirantal/lockfile-prune/actions/workflows/main.yml"><img src="https://github.com/lirantal/lockfile-prune/actions/workflows/main.yml/badge.svg?branch=master" alt="build"/></a>
  <a href="https://codecov.io/gh/lirantal/lockfile-prune"><img src="https://badgen.net/codecov/c/github/lirantal/lockfile-prune" alt="codecov"/></a>
  <a href="./SECURITY.md"><img src="https://img.shields.io/badge/Security-Responsible%20Disclosure-yellow.svg" alt="Responsible Disclosure Policy" /></a>
</p>

# About

This package prunes any devDependencies entries in an npm's lockfile, supporting
either `npm-shrinkwrap.json` or `package-lock.json`.

# Usage

```bash
npx lockfile-prune <path/to/lockfile>
```

# Example

If you use this as part of an automated flow for releasing packages with
something like `semantic-release` then you only need to npx' the lockfile
before the release process.

However, you can also automate it in the following way, by adding these
run-script hooks into `package.json`:

```json
 "scripts": {
   "prepublishOnly": "npx lockfile-prune npm-shrinkwrap.json",
   "postpublish": "git checkout npm-shrinkwrap.json"
}
```

The `postpublish` hook isn't strictly necessary on build systems but
can prove useful to maintain the same git tree if you are publishing
from a local development machine.

# Contributing

Please consult [CONTRIBUTING](./CONTRIBUTING.md) for guidelines on contributing to this project.

# Author

**lockfile-prune** © [Liran Tal](https://github.com/lirantal), Released under the [Apache-2.0](./LICENSE) License.

---
_Source: https://npm.io/package/lockfile-prune · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
