Docs/Platform

Dependency integrity

live

Check supported package changes before an agent installs them or writes an npm lockfile.

01

npm install commands

For recognized npm install commands with explicit package arguments, the hook resolves the proposed packages and requests a dependency check before the command proceeds. Bare npm install and npm ci are not intercepted by this install-command parser.

02

Python packages

The pip path checks visible exact version pins, including pins read from a requirements file passed with -r. Unpinned dependencies and version ranges cannot be treated as resolved package checks; the hook warns and allows those unresolved inputs.

03

npm lockfile writes

Proposed writes to package-lock.json and npm-shrinkwrap.json have a separate dependency-diff path for added or changed package versions. This is different from intercepting a shell command that updates a lockfile.

04

What the check considers

FlowRail uses registry and package signals alongside known vulnerability data. An active design review can supply approved dependency constraints. Read the returned finding to see why a package was blocked; a declared dependency is not a blanket assurance about its safety.

05

Coverage limits

Other package managers, including Yarn, pnpm, Poetry and uv, do not have equivalent install-hook coverage. An allowed result means the evaluated checks did not block that package set; it does not prove every dependency is safe.

06

Dependency checks in CI

The CI gate evaluates supported changed dependency manifests. Its scope is manifest-only; lockfile-only and transitive-resolution changes are outside that scope.

Check a package manually →