Togoder security

Glossary

What is a lockfile?

Also called: package-lock.json, yarn.lock, dependency lock fileUpdated

Definition

A lockfile (package-lock.json, yarn.lock, pnpm-lock.yaml, bun.lock, poetry.lock, Cargo.lock and others) records the exact resolved version, download URL and integrity hash of every direct and transitive dependency, so installs are reproducible.

Why lockfiles matter for security

  • No surprise versions: a version range like ^4.17.0 would otherwise pull in a malicious 4.17.99 the day it is published.
  • Integrity checks: each entry carries a hash (integrity: sha512-...), so a tampered tarball fails to install.
  • Inventory: it is the complete list of what you run, which is what an SBOM or a scanner needs.

Using lockfiles safely

  • Commit the lockfile and install in CI with npm ci, yarn install --immutable, pnpm install --frozen-lockfile or poetry sync.
  • Review lockfile diffs. A pull request that changes a resolved URL to an unfamiliar host, or adds dozens of new transitive packages, deserves a closer look (lockfile injection).
  • Scan the packages a lockfile change introduces. Upload a lockfile to Togoder Security for a free parse and price quote, or run it in CI.

Frequently asked questions

Should libraries commit their lockfile?

Yes for development and CI reproducibility, although consumers of a library resolve their own versions; the lockfile protects the library's own builds and contributors.

What is lockfile injection?

Editing a lockfile in a pull request so that a package resolves to an attacker-controlled URL or tarball. The change is easy to miss because reviewers rarely read lockfile diffs.