npm → CycloneDX 1.6

Turn a package-lock.json into a manifest you can check.

No CycloneDX file? If your project has a package-lock.json, you already have everything needed. This converts it — entirely in your browser — into a valid CycloneDX 1.6 SBOM you can download and run through the free check.

Deterministic extraction only. Nothing is uploaded, looked up, or inferred. What's in the lockfile is what comes out.

{ }
Drop your package-lock.json, or click to choose
lockfileVersion 2 or 3 (npm 7+) · stays in your browser
0
components extracted
Format · CycloneDX 1.6
Source · npm lockfile

Read before you use this

This CycloneDX 1.6 document was produced solely by deterministic extraction of the name, version, integrity hash, license, and resolved URL fields present in the supplied npm package-lock.json. No registry queries, source analysis, binary inspection, or inference of missing data were performed. The document therefore contains only the dependency declarations and integrity values that were explicitly recorded in the lockfile at the moment of conversion.

It does not constitute a complete inventory of the software that may actually execute, does not declare cryptographic primitives, key sizes, or usage contexts, and does not assert the presence or absence of any vulnerability.

When this document is submitted for a signed receipt, the receipt attests exclusively to the exact content and timestamp of this generated file. The receipt is not a cryptographic assessment, not a vulnerability scan, not an endorsement of the software, and not evidence of ownership or runtime composition.

Open the free check →

Next: download the file, then open the free check and drop it into the upload box. The check runs on the file you just made.

Runs entirely in your browser — the lockfile never leaves your device.  ·  Home  ·  SBOM vs CBOM →