npm install commands
For recognized npm install commands with explicit package arguments, the hook resolves the proposed packages and requests a dependency check before the command proceeds. Bare npm install and npm ci are not intercepted by this install-command parser.
Python packages
The pip path checks visible exact version pins, including pins read from a requirements file passed with -r. Unpinned dependencies and version ranges cannot be treated as resolved package checks; the hook warns and allows those unresolved inputs.
npm lockfile writes
Proposed writes to package-lock.json and npm-shrinkwrap.json have a separate dependency-diff path for added or changed package versions. This is different from intercepting a shell command that updates a lockfile.
What the check considers
FlowRail uses registry and package signals alongside known vulnerability data. An active design review can supply approved dependency constraints. Read the returned finding to see why a package was blocked; a declared dependency is not a blanket assurance about its safety.
Coverage limits
Other package managers, including Yarn, pnpm, Poetry and uv, do not have equivalent install-hook coverage. An allowed result means the evaluated checks did not block that package set; it does not prove every dependency is safe.
Dependency checks in CI
The CI gate evaluates supported changed dependency manifests. Its scope is manifest-only; lockfile-only and transitive-resolution changes are outside that scope.