npm dependencies

npm versions, declared dependencies, and release-cadence rows

This Actor reads official npm registry metadata for packages you list and emits version, dependency, maintainer-hint, and cadence rows. It is not a license-policy tree walker.

Not license allow/deny policy (use npm Dependency Tree & License Scraper). Not OSV CVE matching. Public npm only.

from $3.00 / 1,000 npm package or dependency row ($0.003 per delivered apify-default-dataset-item). No Actor Start. Unchanged runs that write zero default-dataset rows typically charge $0.00 on current PPE.

Open npm Package & Dependency Scraper on Apify

npm Package & Dependency Scraper, not a neighboring Actor

Use this page for this Actor’s job. Use npm License & Deprecation Checker for npm license/deprecation; Use npm Dependency Tree & License Scraper for npm license trees; Use PyPI Package & Dependency Scraper for PyPI deps/releases.

This Actornpm License & Deprecation Checkernpm Dependency Tree & License ScraperPyPI Package & Dependency Scraper
Intent npm Package & Dependency Scrapernpm license/deprecationnpm license treesPyPI deps/releases
Primary input see schemapackagespackages + licensePolicypackages
What it reads Public sources listed on the Store pageregistry.npmjs.orgnpm registry treePyPI JSON + OSV
Primary output Dataset rows billed per live PPEnpm package rowslicense/dep rowsPyPI dep rows
Not this job Not license allow/deny policy (use npm Dependency Tree & License Scraper). Not OSV CVE matching. Public npm only.Not OSV vulnerability matchingNot OSV CVEsNot npm trees

Store ID: taroyamada/npm-package-dependency-intelligence. Respect source terms, robots.txt, and rate limits.

Use cases

How is npm Package & Dependency Scraper different from npm License & Deprecation Checker and npm Dependency Tree & License Scraper?

npm Package & Dependency Scraper (taroyamada/npm-package-dependency-intelligence): This Actor reads official npm registry metadata for packages you list and emits version, dependency, maintainer-hint, and cadence rows. It is not a license-policy tree walker. Not license allow/deny policy (use npm Dependency Tree & License Scraper). Not OSV CVE matching. Public npm only. npm License & Deprecation Checker is for npm license/deprecation (input packages; registry.npmjs.org; npm package rows). Not OSV vulnerability matching. npm Dependency Tree & License Scraper is for npm license trees (input packages + licensePolicy; npm registry tree; license/dep rows). Not OSV CVEs. PyPI Package & Dependency Scraper is for PyPI deps/releases (input packages; PyPI JSON + OSV; PyPI dep rows). Not npm trees.

What input is required?

Live required fields: packages. Published exampleRunInput is shown below. Analyze npm package metadata, versions, and dependency declarations from the official registry.npmjs.org packument endpoint.

Field Type Default Notes
packages string[] required empty required Packages. npm package names such as react, vite, express, or @types/node. minItems=1
includeVersionHistory boolean true Include version history. Emit package_version rows. When disabled, only the latest version row is emitted.
includeDevDependencies boolean true Include dev dependencies. Include devDependencies from emitted package versions.
maxVersionRowsPerPackage integer 100 Max version rows per package. Maximum package_version rows to emit per package. min=1 max=1000
maxDependencyRowsPerPackage integer 250 Max dependency rows per package. Maximum dependency rows to emit per package across emitted versions. min=1 max=5000
concurrency integer 5 Concurrency. Number of npm package registry requests to run in parallel. min=1 max=10
timeoutMs integer 15000 Timeout (ms). HTTP request timeout for registry.npmjs.org calls. min=1000 max=30000
delivery string enum dataset Delivery. Where to send results. Webhook delivery does not also push dataset rows. enum: dataset, webhook
webhookUrl string empty Webhook URL. Webhook URL to POST the full normalized payload to when delivery=webhook.
dryRun boolean false Dry run. Run without pushing rows to the dataset or webhook.

Published Store example run input (omitted fields take schema defaults):

{
  "packages": [
    "react",
    "vite",
    "@types/node"
  ],
  "includeVersionHistory": true,
  "includeDevDependencies": true,
  "maxVersionRowsPerPackage": 25,
  "maxDependencyRowsPerPackage": 250,
  "concurrency": 3,
  "timeoutMs": 15000,
  "delivery": "dataset",
  "dryRun": false
}

Run npm Package & Dependency Scraper on Apify

How do dataset, webhook, and dry-run delivery work?

delivery defaults to dataset on the live schema. Dataset output is the billable surface when rows are written. webhookUrl is used when delivery is webhook (and typically not during dryRun). dryRun true validates or samples without the usual dataset/webhook side effects described on the Store schema. Unchanged runs that write zero default-dataset rows typically charge $0.00 on current PPE.

What does a result contain?

Published README Output Example / Sample Output JSON. Treat README samples as illustrations, not a live coverage guarantee. There is no published output JSON schema on the Store page.

How is npm Package & Dependency Scraper priced?

Billing is pay per event. The live Store card is from $3.00 / 1,000 npm package or dependency row ($0.003 per delivered apify-default-dataset-item). No Actor Start. Unchanged runs that write zero default-dataset rows typically charge $0.00 on current PPE. Current PPE:

Event Price Emitted when
apify-default-dataset-item (npm package or dependency row) $0.003 Charged for one delivered npm package, version, or dependency row.

from $3.00 / 1,000 npm package or dependency row ($0.003 per delivered apify-default-dataset-item). No Actor Start. Unchanged runs that write zero default-dataset rows typically charge $0.00 on current PPE.

See npm Package & Dependency Scraper pricing on Apify

Limits to keep in mind

Open npm Package & Dependency Scraper on Apify

Related pages