npm dependency tree
npm transitive dependency trees and license-policy flags
This Actor walks npm dependency trees (maxDepth, optional includeDevDeps) and flags licenses against allowList/denyList or licensePolicy. It is a license/tree scraper, not an OSV CVE feed.
Not OSV vulnerability matching. Not legal advice on license compatibility. Public npm registry only.
from $8.00 / 1,000 result ($0.008 per delivered apify-default-dataset-item). $0.001 Actor Start. Unchanged runs that write zero default-dataset rows typically charge $0.00 on current PPE.
Open npm Dependency Tree & License Scraper on Apify
npm Dependency Tree & License Scraper, not a neighboring Actor
Use this page for this Actor’s job. Use npm License & Deprecation Checker for npm license/deprecation; Use npm Package & Dependency Scraper for npm deps/versions; Use OSS Vulnerability Monitor for OSV/GitHub advisories.
| This Actor | npm License & Deprecation Checker | npm Package & Dependency Scraper | OSS Vulnerability Monitor | |
|---|---|---|---|---|
| Intent | npm Dependency Tree & License Scraper | npm license/deprecation | npm deps/versions | OSV/GitHub advisories |
| Primary input | see schema | packages | packages | packages |
| What it reads | Public sources listed on the Store page | registry.npmjs.org | npm registry | OSV + GitHub Advisories |
| Primary output | Dataset rows billed per live PPE | npm package rows | npm dep rows | vuln rows |
| Not this job | Not OSV vulnerability matching. Not legal advice on license compatibility. Public npm registry only. | Not OSV vulnerability matching | Not license-policy audits | Not license-policy trees |
Store ID: taroyamada/open-source-license-dependency-audit. Respect source terms, robots.txt, and rate limits.
Use cases
- Transitive license inventories
- Deny-list license hits
- maxDepth-capped tree extracts
How is npm Dependency Tree & License Scraper different from npm License & Deprecation Checker and npm Package & Dependency Scraper?
npm Dependency Tree & License Scraper (taroyamada/open-source-license-dependency-audit): This Actor walks npm dependency trees (maxDepth, optional includeDevDeps) and flags licenses against allowList/denyList or licensePolicy. It is a license/tree scraper, not an OSV CVE feed. Not OSV vulnerability matching. Not legal advice on license compatibility. Public npm registry only. npm License & Deprecation Checker is for npm license/deprecation (input packages; registry.npmjs.org; npm package rows). Not OSV vulnerability matching. npm Package & Dependency Scraper is for npm deps/versions (input packages; npm registry; npm dep rows). Not license-policy audits. OSS Vulnerability Monitor is for OSV/GitHub advisories (input packages; OSV + GitHub Advisories; vuln rows). Not license-policy trees.
What input is required?
Live required fields: packages. Published exampleRunInput is shown below. Configure packages to audit for license compliance, dependency risk, and maintainer health.
| Field | Type | Default | Notes |
|---|---|---|---|
packages |
any[] required | empty |
required Package Names. npm package names to audit (max 200). |
licensePolicy |
string enum | permissive |
License Policy. Which license policy to apply: 'permissive' flags copyleft licenses as high risk, 'copyleft-ok' treats copyleft as medium risk, 'custom' uses allowList/denyList. enum: permissive, copyleft-ok, custom |
allowList |
any[] | [] |
Allowed Licenses (custom policy). SPDX identifiers to treat as approved (only used when licensePolicy=custom). |
denyList |
any[] | [] |
Denied Licenses (custom policy). SPDX identifiers to treat as denied (only used when licensePolicy=custom). |
maxDepth |
integer | 1 |
Max Dependency Depth. Maximum transitive dependency depth to crawl (0 = direct only, 1 = one level deep, etc.). min=0 max=3 |
includeDevDeps |
boolean | false |
Include devDependencies. Also audit devDependencies of each package. |
concurrency |
integer | 5 |
Concurrency. Number of parallel requests min=1 max=10 |
timeoutMs |
integer | 15000 |
Timeout (ms). Request timeout in milliseconds min=1000 max=30000 |
delivery |
string enum | dataset |
Delivery. Where to send results: dataset or webhook enum: dataset, webhook |
webhookUrl |
string | empty |
Webhook URL. Webhook URL to POST results to (if delivery=webhook) |
dryRun |
boolean | false |
Dry Run. Run without saving results (for testing) |
Published Store example run input (omitted fields take schema defaults):
{
"packages": [
"express",
"react",
"lodash"
],
"licensePolicy": "permissive",
"maxDepth": 1,
"concurrency": 3,
"delivery": "dataset",
"dryRun": false
}
Run npm Dependency Tree & License Scraper on Apify
How do dataset, webhook, and dry-run delivery work?
delivery defaults to dataset on the live schema. Dataset output is the billable surface when rows are written. webhookUrl is used when delivery is webhook (and typically not during dryRun). dryRun true validates or samples without the usual dataset/webhook side effects described on the Store schema. Unchanged runs that write zero default-dataset rows typically charge $0.00 on current PPE.
What does a result contain?
Published README Output Example / Sample Output JSON. Treat README samples as illustrations, not a live coverage guarantee. There is no published output JSON schema on the Store page.
How is npm Dependency Tree & License Scraper priced?
Billing is pay per event. The live Store card is from $8.00 / 1,000 result ($0.008 per delivered apify-default-dataset-item). $0.001 Actor Start. Unchanged runs that write zero default-dataset rows typically charge $0.00 on current PPE. Current PPE:
| Event | Price | Emitted when |
|---|---|---|
apify-default-dataset-item (result) |
$0.008 | Single result in the default dataset. |
apify-actor-start (Actor Start) |
$0.001 | Charged when the Actor starts running. Number of events charged depends on Actor memory (one event per GB, minimum one event). |
The published README Cost block is stale versus the live Store pricing tab. README Cost quotes actor-start $0.01; live Actor Start is $0.001. README Cost quotes dataset-item $0.003; live primary is $0.008 (result). Live: result $0.008, Actor Start $0.001. This page quotes live PPE only.
from $8.00 / 1,000 result ($0.008 per delivered apify-default-dataset-item). $0.001 Actor Start. Unchanged runs that write zero default-dataset rows typically charge $0.00 on current PPE.
See npm Dependency Tree & License Scraper pricing on Apify
Limits to keep in mind
- packages required
- maxDepth cap
- Public npm only
- Not legal advice
- Respect source terms, robots.txt, and rate limits.
Open npm Dependency Tree & License Scraper on Apify
Related pages
- npm License & Deprecation Checker — Top-level package metadata, not trees.
- npm Package & Dependency Scraper — Declared deps/versions, not license policy.
- OSS Vulnerability Monitor — CVEs, not licenses.
- Tools