Behavioral security analysis and integrity verification for npm packages, from the command line.
npm-sentinel is a CLI tool for supply-chain security: it performs behavioral analysis and integrity verification on npm packages before they land in your project, surfacing risky dependencies, tampered tarballs, and low-trust maintainers.
npm-registry-fetch + tar) and validates them against a .sentinel-lock.json, catching tampered or mismatched artifacts.install command:
--fast — integrity check only.--deep — full transitive dependency analysis via a queue-based crawler, with live progress indicators.check command renders a dashboard scoring a package and flagging Concerns — brand-new packages, single-maintainer packages, and heavy direct-dependency counts — plus suggested Alternatives..sentinelrc.js config, with a --ci mode that fails builds on policy violations.429 rate limits, plus caching of download counts and trust-score results to minimize API calls.# Analyze before installing (shallow, fast by default)
npm-sentinel install express
# Integrity check only
npm-sentinel install express --fast
# Full transitive analysis
npm-sentinel install express --deep
# Inspect a single package's trust dashboard
npm-sentinel check lodash| Component | Technology |
|---|---|
| Language | TypeScript |
| Distribution | npm CLI (npm-sentinel binary) |
| Registry I/O | npm-registry-fetch + tar |
| Config | .sentinelrc.js policy, --ci mode |
| Lockfile | .sentinel-lock.json integrity records |
npm-sentinel is the supply-chain counterpart to ApiShield: where ApiShield hardens the runtime edge of an app, npm-sentinel hardens what you pull into it in the first place.