# nodesecurity-npm-utils

> ## Methods:

Latest version **6.0.0** (published 2017-09-15) · MIT license · 0 weekly downloads

## Install

```sh
npm install nodesecurity-npm-utils
pnpm add nodesecurity-npm-utils
yarn add nodesecurity-npm-utils
bun add nodesecurity-npm-utils
```

## Health

**Score 15/100 (F)** — status: abandoned.

Positive: no vulnerabilities.

Warnings: low downloads; no types; no esm support.

Negative: abandoned; low maintenance score.

## Facts

| | |
|---|---|
| Version | 6.0.0 |
| Published | 2017-09-15 |
| First published | 2015-11-02 |
| Weekly downloads | 0 |
| License | MIT |
| TypeScript types | none |
| Module format | CommonJS |
| Dependencies | 0 |
| Known vulnerabilities | 0 |
| Install scripts | no |
| GitHub stars | 11 |
| Author | ^lift security |
| Maintainers | adam_baldwin, nlf |
| Keywords | npm, package, nsp, security, shrinkwrap |

## Links

- npm: https://www.npmjs.com/package/nodesecurity-npm-utils
- Repository: https://github.com/nodesecurity/npm-utils
- Homepage: https://github.com/nodesecurity/npm-utils#readme
- Issues: https://github.com/nodesecurity/npm-utils/issues
- npm.io page: https://npm.io/package/nodesecurity-npm-utils

## Alternatives

- [@openai/codex-sdk](https://npm.io/package/@openai/codex-sdk.md) — 731.4K weekly downloads
- [babel-plugin-transform-react-jsx](https://npm.io/package/babel-plugin-transform-react-jsx.md) — 565.0K weekly downloads
- [babel-helper-remove-or-void](https://npm.io/package/babel-helper-remove-or-void.md) — 508.5K weekly downloads
- [@pnpm/store-controller-types](https://npm.io/package/@pnpm/store-controller-types.md) — 186.9K weekly downloads
- [react-native-signature-canvas](https://npm.io/package/react-native-signature-canvas.md) — 155.6K weekly downloads

## Recent versions

- 6.0.0 (latest) — 2017-09-15
- 5.0.0 — 2016-06-21
- 4.0.1 — 2015-12-31
- 4.0.0 — 2015-12-31
- 3.2.0 — 2015-12-21
- 3.0.0 — 2015-11-02

## README

# node security project npm utilities

## Methods:

### getPackageJson = function (module, callback)

Return the full package document for the given `module`.

### getShrinkwrapDependencies = function (shrinkwrapJson, callback)

Get a [depTree](#deptree-format) for the module from a full npm-shrinkwrap.json. `shrinkwrapJson` should be an object from a parsed npm-shrinkwrap.json file (or look like one): required keys: `name`, `version`, `dependencies`.

```js
var fs = require('fs');

getShrinkwrapDependencies(JSON.parse(fs.readFileSync('./npm-shrinkwrap.json')), function (err, depTree) {
    console.log(depTree);
});
```

#### depTree format

The returned `depTree` representing the full dependency tree object is in a format that's easier to traverse than a full tree. Each module in the full heirarchy has a key in the object of `module@version`. It's value is an object with `parents`, `children` and `source`.

Note that the root module has a key too.

e.g.:

```js
//depTree for some-module version 1.1.0
{
    //root module
    "some-module@1.1.0": {
        parents: [],
        children: ["depA@0.1.0", "depB@1.0.1", "depC@0.2.0"],
    },

    //root's dependencies
    "depA@0.1.0": {
        parents: ["some-module@1.1.0"],
        children: ["underscore@1.6.0"],
        source: "npm"
    },
    "depB@1.0.1": {
        parents: ["some-module@1.1.0"],
        children: ["underscore@1.6.0", "backbone@1.0.0"],
        source: "npm"
    },
    "depC@0.2.0": {
        parents: ["some-module@1.1.0"],
        children: [],
        source: "unknown" //not on npm, maybe it's private/local?
    }

    //deeper dependencies
    "underscore@1.6.0": {
        parents: ["depA@0.1.0", "depB@1.0.1", "backbone@1.6.0"], //modules can be required multiple places in the tree
        children: [],
        source: "npm"
    },
    "backbone@1.6.0": {
        parents: ["depB@1.0.1"], //modules can be required multiple places in the tree
        children: ["underscore@1.6.0"],
        source: "npm"
    }
}
```

---
_Source: https://npm.io/package/nodesecurity-npm-utils · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
