ToolAssay

Compare two lockfiles and report what a manifest diff cannot see

Compare two lockfiles and report what a manifest diff cannot see. Reports newly installed transitive packages, resolved version moves with breaking risk, a registry that changed, and the most serious finding available here: the same version with a different integrity hash, meaning the artifact behind a version that was supposed to be immutable is not the one that was there before.

Answeringour last check, 2026-10-04
1 of 1checks answered this week
2476 msmedian answer time
$0.18listed price per call
$0.18price it asked us

Paid test badge: not yet. The checks above are free: we call the tool without paying and read the payment request it sends back. The Verified badge needs paid calls whose answers match the promised output, and nobody can buy a badge.

Endpoint

POST https://api.zfinia.com/x402/v1/lockfile-change-report

CategoryCompany and compliance
Provider hostapi.zfinia.com
Networkseip155:8453
Payment schemesexact
Self-reported calls, 30 days1 from 1 payers (the provider's figure, not ours)

Our checks, last 30 days

DayResultHTTPAskedTime
2026-10-04 valid payment request 402$0.18 2476 ms

Example input (from the provider)

{
  "body": {
    "after": {
      "lockfileVersion": 3,
      "packages": {
        "": {
          "name": "orders-api",
          "version": "2.2.0"
        },
        "node_modules/cookie": {
          "integrity": "sha512-TAMPERED",
          "resolved": "https://registry.npmjs.org/cookie/-/cookie-0.5.0.tgz",
          "version": "0.5.0"
        },
        "node_modules/express": {
          "integrity": "sha512-DDDD",
          "resolved": "https://registry.npmjs.org/express/-/express-5.0.0.tgz",
          "version": "5.0.0"
        },
        "node_modules/router": {
          "integrity": "sha512-EEEE",
          "resolved": "https://packages.internal.example/router/-/router-2.0.0.tgz",
          "version": "2.0.0"
        }
      }
    },
    "before": {
      "lockfileVersion": 3,
      "packages": {
        "": {
          "name": "orders-api",
          "version": "2.1.0"
        },
        "node_modules/cookie": {
          "integrity": "sha512-BBBB",
          "resolved": "https://registry.npmjs.org/cookie/-/cookie-0.5.0.tgz",
          "version": "0.5.0"
        },
        "node_modules/dropped": {
          "integrity": "sha512-CCCC",
          "resolved": "https://registry.npmjs.org/dropped/-/dropped-1.0.0.tgz",
          "version": "1.0.0"
        },
        "node_modules/express": {
          "integrity": "sha512-AAAA",
          "resolved": "https://registry.npmjs.org/express/-/express-4.18.2.tgz",
          "version": "4.18.2"
        }
      }
    },
    "expected_registry": "https://registry.npmjs.org/"
  },
  "bodyType": "json",
  "method": "POST",
  "type": "http"
}

Promised output schema (from the provider)

{
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "properties": {
    "input": {
      "additionalProperties": false,
      "properties": {
        "body": {
          "additionalProperties": false,
          "properties": {
            "after": {
              "type": "object"
            },
            "before": {
              "type": "object"
            },
            "expected_registry": {
              "maxLength": 256,
              "type": "string"
            }
          },
          "required": [
            "before",
            "after"
          ],
          "type": "object"
        },
        "bodyType": {
          "enum": [
            "json",
            "form-data",
            "text"
          ],
          "type": "string"
        },
        "method": {
          "enum": [
            "POST"
          ],
          "type": "string"
        },
        "type": {
          "const": "http",
          "type": "string"
        }
      },
      "required": [
        "type",
        "method",
        "bodyType",
        "body"
      ],
      "type": "object"
    },
    "output": {
      "properties": {
        "example": {
          "type": "object"
        },
        "type": {
          "type": "string"
        }
      },
      "required": [
        "type"
      ],
      "type": "object"
    }
  },
  "required": [
    "input"
  ],
  "type": "object"
}

This page as JSON