Definition
A lockfile (package-lock.json, yarn.lock, pnpm-lock.yaml, bun.lock, poetry.lock, Cargo.lock and others) records the exact resolved version, download URL and integrity hash of every direct and transitive dependency, so installs are reproducible.
Why lockfiles matter for security
- No surprise versions: a version range like
^4.17.0would otherwise pull in a malicious4.17.99the day it is published. - Integrity checks: each entry carries a hash (
integrity: sha512-...), so a tampered tarball fails to install. - Inventory: it is the complete list of what you run, which is what an SBOM or a scanner needs.
Using lockfiles safely
- Commit the lockfile and install in CI with
npm ci,yarn install --immutable,pnpm install --frozen-lockfileorpoetry sync. - Review lockfile diffs. A pull request that changes a
resolvedURL to an unfamiliar host, or adds dozens of new transitive packages, deserves a closer look (lockfile injection). - Scan the packages a lockfile change introduces. Upload a lockfile to Togoder Security for a free parse and price quote, or run it in CI.
Frequently asked questions
Should libraries commit their lockfile?
Yes for development and CI reproducibility, although consumers of a library resolve their own versions; the lockfile protects the library's own builds and contributors.
What is lockfile injection?
Editing a lockfile in a pull request so that a package resolves to an attacker-controlled URL or tarball. The change is easy to miss because reviewers rarely read lockfile diffs.