npm Lockfile Supply-Chain Audit Prompt
Review a package-lock.json or pnpm-lock.yaml for supply-chain risk: unpinned versions, suspicious registries, install scripts, and dependency confusion exposure
- Target user
- security-minded DevOps and frontend platform engineers hardening JavaScript build pipelines
- Difficulty
- Intermediate
- Tools
- Claude, ChatGPT
The prompt
You are a senior DevSecOps engineer (defensive/blue-team) who specializes in JavaScript/Node supply-chain security and reviews lockfiles for tampering and dependency-confusion risk. I will provide: - My lockfile (package-lock.json, pnpm-lock.yaml, or yarn.lock) and package.json - My .npmrc / registry configuration and any scoped-registry settings - Context on whether the project publishes packages and which internal scopes it uses Your job: 1. **Registry & integrity review** — flag any resolved URLs pointing at non-official or http registries, missing `integrity` hashes, and mismatches between declared and resolved versions. 2. **Pinning & drift analysis** — identify floating ranges (`^`, `~`, `*`, `latest`) and explain where they allow silent transitive upgrades; recommend exact pins and `--frozen-lockfile`/`npm ci` enforcement. 3. **Install-script exposure** — list dependencies with `preinstall`/`postinstall`/`prepare` scripts and assess blast radius; recommend `--ignore-scripts` policy and allowlisting. 4. **Dependency-confusion check** — compare internal scopes against public registry namespace ownership and flag any unscoped internal names that could be hijacked. 5. **Maintenance & provenance signals** — call out abandoned, recently-transferred, or low-trust packages and note where npm provenance/signed attestations are available. 6. **Remediation plan** — give prioritized, low-to-high-effort fixes (config, CI gate, pinning) with the exact commands or settings. 7. **CI gate recommendation** — propose a blocking pipeline check (e.g. lockfile diff, `npm audit signatures`, allowlist). Output as: a findings table (severity, package, issue, fix), followed by a prioritized remediation checklist and a ready-to-paste hardened .npmrc snippet. Do not suggest installing or executing any flagged package to "test" it; reason from the lockfile metadata only.
Run this prompt with AI
Test it, get an AI-improved version, or compare models — live in the Prompt Workspace. No copy-paste.
Related prompts
-
Terraform Provider Checksum Verification Prompt
Review the Terraform dependency lock file and provider sourcing for missing checksums, unpinned versions, untrusted mirrors, and supply-chain tampering risk
-
Dependency CVE Triage & Prioritization Prompt
Turn a noisy dependency vulnerability scan into a ranked, actionable remediation plan using reachability, exploitability, and exposure — instead of chasing every red CVE.
-
Package Repository & GPG Signing Trust Review Prompt
Audit apt/yum/dnf repository configuration and GPG/key trust to catch unsigned repos, insecure HTTP mirrors, stale or overly broad signing keys, and gaps that allow malicious package injection.
-
Golden Image Pipeline Hardening Prompt
Harden the build pipeline that produces golden VM images (AMIs/Packer templates) — provenance, hardening baselines, vulnerability gates, and signing — so every instance starts from a trusted, minimal base.
More DevOps Security & Hardening prompts & error guides
Browse every DevOps Security & Hardening prompt and troubleshooting guide in one place.
Reading prompts? Get all 500 in one free PDF
500 battle-tested, copy-paste AI prompts engineered by a senior systems engineer — every one with fill-in placeholders and safety/back-out notes. Drop your email and it's yours.
- 500 prompts: Linux · Kubernetes · Terraform · OpenStack · GitLab · Docker · Monitoring · Incident Response
- Instant PDF download — yours free, forever
- Plus one practical AI-workflow email a week (no spam)
Single opt-in · unsubscribe anytime · no spam.