Skip to content

findPackageLockEntriesMissingIntegrity

Finds the packages entries of a lockfile that have no resolved field, or that have a registry resolved field and no integrity field.

Some entries never have these fields in a healthy lock, so they are skipped: the root (''), a link, a workspace source folder (its key has no node_modules/ segment), and a bundled dependency (inBundle), which comes inside its parent’s tarball. integrity is only required when resolved is a registry URL, because npm records no integrity for a git dependency.

Import:

import { findPackageLockEntriesMissingIntegrity } from 'obsidian-dev-utils/script-utils/package-lock-integrity';

Signature:

function findPackageLockEntriesMissingIntegrity(packageLockJson: PackageLockJson): string[]

Parameters:

Parameter Type Description
packageLockJson PackageLockJson The parsed package-lock.json.

Returns: string[] — The keys of the offending entries, in lockfile order.