npm dependency tree

npm transitive dependency trees and license-policy flags

This Actor walks npm dependency trees (maxDepth, optional includeDevDeps) and flags licenses against allowList/denyList or licensePolicy. It is a license/tree scraper, not an OSV CVE feed.

Not OSV vulnerability matching. Not legal advice on license compatibility. Public npm registry only.

from $8.00 / 1,000 result ($0.008 per delivered apify-default-dataset-item). $0.001 Actor Start. Unchanged runs that write zero default-dataset rows typically charge $0.00 on current PPE.

Open npm Dependency Tree & License Scraper on Apify

npm Dependency Tree & License Scraper, not a neighboring Actor

Use this page for this Actor’s job. Use npm License & Deprecation Checker for npm license/deprecation; Use npm Package & Dependency Scraper for npm deps/versions; Use OSS Vulnerability Monitor for OSV/GitHub advisories.

This Actornpm License & Deprecation Checkernpm Package & Dependency ScraperOSS Vulnerability Monitor
Intent npm Dependency Tree & License Scrapernpm license/deprecationnpm deps/versionsOSV/GitHub advisories
Primary input see schemapackagespackagespackages
What it reads Public sources listed on the Store pageregistry.npmjs.orgnpm registryOSV + GitHub Advisories
Primary output Dataset rows billed per live PPEnpm package rowsnpm dep rowsvuln rows
Not this job Not OSV vulnerability matching. Not legal advice on license compatibility. Public npm registry only.Not OSV vulnerability matchingNot license-policy auditsNot license-policy trees

Store ID: taroyamada/open-source-license-dependency-audit. Respect source terms, robots.txt, and rate limits.

Use cases

How is npm Dependency Tree & License Scraper different from npm License & Deprecation Checker and npm Package & Dependency Scraper?

npm Dependency Tree & License Scraper (taroyamada/open-source-license-dependency-audit): This Actor walks npm dependency trees (maxDepth, optional includeDevDeps) and flags licenses against allowList/denyList or licensePolicy. It is a license/tree scraper, not an OSV CVE feed. Not OSV vulnerability matching. Not legal advice on license compatibility. Public npm registry only. npm License & Deprecation Checker is for npm license/deprecation (input packages; registry.npmjs.org; npm package rows). Not OSV vulnerability matching. npm Package & Dependency Scraper is for npm deps/versions (input packages; npm registry; npm dep rows). Not license-policy audits. OSS Vulnerability Monitor is for OSV/GitHub advisories (input packages; OSV + GitHub Advisories; vuln rows). Not license-policy trees.

What input is required?

Live required fields: packages. Published exampleRunInput is shown below. Configure packages to audit for license compliance, dependency risk, and maintainer health.

Field Type Default Notes
packages any[] required empty required Package Names. npm package names to audit (max 200).
licensePolicy string enum permissive License Policy. Which license policy to apply: 'permissive' flags copyleft licenses as high risk, 'copyleft-ok' treats copyleft as medium risk, 'custom' uses allowList/denyList. enum: permissive, copyleft-ok, custom
allowList any[] [] Allowed Licenses (custom policy). SPDX identifiers to treat as approved (only used when licensePolicy=custom).
denyList any[] [] Denied Licenses (custom policy). SPDX identifiers to treat as denied (only used when licensePolicy=custom).
maxDepth integer 1 Max Dependency Depth. Maximum transitive dependency depth to crawl (0 = direct only, 1 = one level deep, etc.). min=0 max=3
includeDevDeps boolean false Include devDependencies. Also audit devDependencies of each package.
concurrency integer 5 Concurrency. Number of parallel requests min=1 max=10
timeoutMs integer 15000 Timeout (ms). Request timeout in milliseconds min=1000 max=30000
delivery string enum dataset Delivery. Where to send results: dataset or webhook enum: dataset, webhook
webhookUrl string empty Webhook URL. Webhook URL to POST results to (if delivery=webhook)
dryRun boolean false Dry Run. Run without saving results (for testing)

Published Store example run input (omitted fields take schema defaults):

{
  "packages": [
    "express",
    "react",
    "lodash"
  ],
  "licensePolicy": "permissive",
  "maxDepth": 1,
  "concurrency": 3,
  "delivery": "dataset",
  "dryRun": false
}

Run npm Dependency Tree & License Scraper on Apify

How do dataset, webhook, and dry-run delivery work?

delivery defaults to dataset on the live schema. Dataset output is the billable surface when rows are written. webhookUrl is used when delivery is webhook (and typically not during dryRun). dryRun true validates or samples without the usual dataset/webhook side effects described on the Store schema. Unchanged runs that write zero default-dataset rows typically charge $0.00 on current PPE.

What does a result contain?

Published README Output Example / Sample Output JSON. Treat README samples as illustrations, not a live coverage guarantee. There is no published output JSON schema on the Store page.

How is npm Dependency Tree & License Scraper priced?

Billing is pay per event. The live Store card is from $8.00 / 1,000 result ($0.008 per delivered apify-default-dataset-item). $0.001 Actor Start. Unchanged runs that write zero default-dataset rows typically charge $0.00 on current PPE. Current PPE:

Event Price Emitted when
apify-default-dataset-item (result) $0.008 Single result in the default dataset.
apify-actor-start (Actor Start) $0.001 Charged when the Actor starts running. Number of events charged depends on Actor memory (one event per GB, minimum one event).

The published README Cost block is stale versus the live Store pricing tab. README Cost quotes actor-start $0.01; live Actor Start is $0.001. README Cost quotes dataset-item $0.003; live primary is $0.008 (result). Live: result $0.008, Actor Start $0.001. This page quotes live PPE only.

from $8.00 / 1,000 result ($0.008 per delivered apify-default-dataset-item). $0.001 Actor Start. Unchanged runs that write zero default-dataset rows typically charge $0.00 on current PPE.

See npm Dependency Tree & License Scraper pricing on Apify

Limits to keep in mind

Open npm Dependency Tree & License Scraper on Apify

Related pages