Skip to main content
Glama

Diff two package.json/lockfile snapshots

diff_dependencies
Read-only

Compares two raw snapshots of a package.json, package-lock.json (npm v1-v3), yarn.lock (classic v1 or Berry), or pnpm-lock.yaml — e.g. before/after a PR — and reports which packages were added, removed, or version-bumped. An npm alias (e.g. "totally-safe": "npm:minimist@0.0.8") is followed to its real target in every format — actualName names the real package that vulnerability/install-script data attaches to (name stays the declared/alias key); this is NOT silently skipped, since doing so would let a vulnerable package hide behind whatever name a project calls it. For every added or bumped package (up to 100 per call), also checks whether its resolved version carries a preinstall/install/postinstall/prepare lifecycle script that the before-version did NOT have (installScriptIntroduced, a headline signal — a routine-looking patch bump quietly adding a postinstall is exactly the shape of a compromised-maintainer supply-chain attack) and batch-checks it against OSV.dev, reporting vulnerabilityDelta (introduced/fixed/still-vulnerable/still-clean) rather than just a bare isVulnerable flag. installScriptIntroduced is a boolean across all four lifecycle keys, so it treats a bare "prepare": "husky" bump the same as a newly-added network-capable postinstall — read installScriptKeysIntroduced (null when only npm-lock's boolean hint was available, not the real scripts object; otherwise the actual key(s) added) to tell those apart before treating a flag as high-severity. sourceIntegrityChanged catches a DIFFERENT attack shape than a version bump: a lockfile entry whose resolved tarball URL or integrity hash changed while the version string stayed IDENTICAL — e.g. a compromised registry mirror or a hand-edited lockfile pointing a legitimate-looking "lodash@4.17.21" at a different, unverified artifact — which a version-only diff would report as "no change" (resolvedUrl/integrity are null when a format doesn't record either, package.json has neither). Scope notes: package.json is diffed as its own declared dependency list only (a manifest has no transitive data at all, and this includes peerDependencies, unlike batch_query_vulnerabilities/generate_sbom which exclude them by default — a diff should catch a peerDependency change just like any other); every lockfile format (package-lock.json, pnpm-lock.yaml, yarn.lock) reports its FULL resolved graph — direct and transitive alike — so a transitive-only change (e.g. a nested qs bumped while the direct express version is untouched) is caught, not just direct dependency changes; check comparisonNote when the two snapshots are different formats/scopes. The install-script check is presence-only (read from the registry packument or lockfile metadata, not a tarball content scan) — use analyze_install_script for a deep-dive on anything flagged here. projectLifecycleChanges diffs the SCANNED PROJECT's own root preinstall/install/postinstall/prepare scripts (package.json only — null when neither snapshot is one) — independent of the dependency list above, since a PR that only adds a root postinstall ("postinstall": "curl ... | sh") changes nothing about added/removed/changed and would otherwise be invisible to this tool entirely; introduced/changed on a preinstall/install/postinstall key is counted in flaggedCount. overridesChanges similarly diffs package.json's overrides (npm), resolutions (yarn), or pnpm.overrides — these force a specific version onto a transitive dependency (often to pin past a known vulnerability), so a PR that quietly removes, downgrades, or introduces one is exactly the kind of change a dependency diff should catch, and previously nothing here read this field at all; ANY change here (introduced/removed/changed) is counted in flaggedCount, since an override can be a security control being weakened just as easily as an attack forcing a compromised version onto an otherwise-untouched dependency. Ideal for a CI gate reviewing a dependency-changing PR.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
afterYesRaw file content of the "after" snapshot — a package.json, package-lock.json (npm v1-v3), yarn.lock (classic v1 or Berry), or pnpm-lock.yaml. Format is auto-detected; before/after may be different formats.
beforeYesRaw file content of the "before" snapshot — a package.json, package-lock.json (npm v1-v3), yarn.lock (classic v1 or Berry), or pnpm-lock.yaml. Format is auto-detected; before/after may be different formats.

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
addedYes
changedYes
removedYes
summaryYes
truncatedYes
totalAddedYes
afterFormatYes
beforeFormatYes
flaggedCountYes
totalChangedYes
totalRemovedYes
comparisonNoteYes
enrichmentNoteYes
truncationNoteYes
overridesChangesYes
projectLifecycleChangesYes

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed10 schema fields changed
    • addedOutput schema / properties / added / items / properties / actualName
      Added value: +{
      +  "type": [
      +    "string",
      +    "null"
      +  ]
      +}
    • addedOutput schema / properties / added / items / properties / integrity
      Added value: +{
      +  "type": [
      +    "string",
      +    "null"
      +  ]
      +}
    • addedOutput schema / properties / added / items / properties / resolvedUrl
      Added value: +{
      +  "type": [
      +    "string",
      +    "null"
      +  ]
      +}
    • addedOutput schema / properties / added / items / properties / sourceIntegrityChanged
      Added value: +{
      +  "type": [
      +    "boolean",
      +    "null"
      +  ]
      +}
    • changedOutput schema / properties / added / items / required
      Previous value: -[
      -  "name",
      -  "npmscanUrl",
      -  "beforeVersion",
      -  "afterVersion",
      -  "coexistingVersions",
      -  "changeType",
      -  "hasInstallScript",
      -  "installScriptIntroduced",
      -  "installScriptKeys",
      -  "installScriptKeysIntroduced",
      -  "isVulnerable",
      -  "highestSeverity",
      -  "vulnerabilities",
      -  "vulnerabilityDelta",
      -  "resolutionNote"
      -]New value: +[
      +  "name",
      +  "actualName",
      +  "npmscanUrl",
      +  "beforeVersion",
      +  "afterVersion",
      +  "coexistingVersions",
      +  "changeType",
      +  "hasInstallScript",
      +  "installScriptIntroduced",
      +  "installScriptKeys",
      +  "installScriptKeysIntroduced",
      +  "sourceIntegrityChanged",
      +  "resolvedUrl",
      +  "integrity",
      +  "isVulnerable",
      +  "highestSeverity",
      +  "vulnerabilities",
      +  "vulnerabilityDelta",
      +  "resolutionNote"
      +]
    • addedOutput schema / properties / overridesChanges
      Added value: +{
      +  "anyOf": [
      +    {
      +      "additionalProperties": false,
      +      "properties": {
      +        "changed": {
      +          "additionalProperties": {
      +            "additionalProperties": false,
      +            "properties": {
      +              "after": {
      +                "type": "string"
      +              },
      +              "before": {
      +                "type": "string"
      +              }
      +            },
      +            "required": [
      +              "before",
      +              "after"
      +            ],
      +            "type": "object"
      +          },
      +          "type": "object"
      +        },
      +        "introduced": {
      +          "additionalProperties": {
      +            "type": "string"
      +          },
      +          "type": "object"
      +        },
      +        "removed": {
      +          "additionalProperties": {
      +            "type": "string"
      +          },
      +          "type": "object"
      +        }
      +      },
      +      "required": [
      +        "introduced",
      +        "removed",
      +        "changed"
      +      ],
      +      "type": "object"
      +    },
      +    {
      +      "type": "null"
      +    }
      +  ]
      +}
    • addedOutput schema / properties / projectLifecycleChanges
      Added value: +{
      +  "anyOf": [
      +    {
      +      "additionalProperties": false,
      +      "properties": {
      +        "changed": {
      +          "additionalProperties": {
      +            "additionalProperties": false,
      +            "properties": {
      +              "after": {
      +                "type": "string"
      +              },
      +              "before": {
      +                "type": "string"
      +              }
      +            },
      +            "required": [
      +              "before",
      +              "after"
      +            ],
      +            "type": "object"
      +          },
      +          "type": "object"
      +        },
      +        "introduced": {
      +          "additionalProperties": {
      +            "type": "string"
      +          },
      +          "type": "object"
      +        },
      +        "removed": {
      +          "additionalProperties": {
      +            "type": "string"
      +          },
      +          "type": "object"
      +        }
      +      },
      +      "required": [
      +        "introduced",
      +        "removed",
      +        "changed"
      +      ],
      +      "type": "object"
      +    },
      +    {
      +      "type": "null"
      +    }
      +  ]
      +}
    • addedOutput schema / properties / removed / items / properties / actualName
      Added value: +{
      +  "type": [
      +    "string",
      +    "null"
      +  ]
      +}
    • changedOutput schema / properties / removed / items / required
      Previous value: -[
      -  "name",
      -  "version",
      -  "npmscanUrl"
      -]New value: +[
      +  "name",
      +  "actualName",
      +  "version",
      +  "npmscanUrl"
      +]
    • changedOutput schema / required
      Previous value: -[
      -  "summary",
      -  "beforeFormat",
      -  "afterFormat",
      -  "comparisonNote",
      -  "added",
      -  "removed",
      -  "changed",
      -  "totalAdded",
      -  "totalRemoved",
      -  "totalChanged",
      -  "flaggedCount",
      -  "truncated",
      -  "truncationNote",
      -  "enrichmentNote"
      -]New value: +[
      +  "summary",
      +  "beforeFormat",
      +  "afterFormat",
      +  "comparisonNote",
      +  "added",
      +  "removed",
      +  "changed",
      +  "totalAdded",
      +  "totalRemoved",
      +  "totalChanged",
      +  "flaggedCount",
      +  "truncated",
      +  "truncationNote",
      +  "enrichmentNote",
      +  "projectLifecycleChanges",
      +  "overridesChanges"
      +]
  2. Changed3 schema fields changed
    • addedOutput schema / properties / added / items / properties / installScriptKeys
      Added value: +{
      +  "anyOf": [
      +    {
      +      "items": {
      +        "enum": [
      +          "preinstall",
      +          "install",
      +          "postinstall",
      +          "prepare"
      +        ],
      +        "type": "string"
      +      },
      +      "type": "array"
      +    },
      +    {
      +      "type": "null"
      +    }
      +  ]
      +}
    • addedOutput schema / properties / added / items / properties / installScriptKeysIntroduced
      Added value: +{
      +  "anyOf": [
      +    {
      +      "items": {
      +        "enum": [
      +          "preinstall",
      +          "install",
      +          "postinstall",
      +          "prepare"
      +        ],
      +        "type": "string"
      +      },
      +      "type": "array"
      +    },
      +    {
      +      "type": "null"
      +    }
      +  ]
      +}
    • changedOutput schema / properties / added / items / required
      Previous value: -[
      -  "name",
      -  "npmscanUrl",
      -  "beforeVersion",
      -  "afterVersion",
      -  "coexistingVersions",
      -  "changeType",
      -  "hasInstallScript",
      -  "installScriptIntroduced",
      -  "isVulnerable",
      -  "highestSeverity",
      -  "vulnerabilities",
      -  "vulnerabilityDelta",
      -  "resolutionNote"
      -]New value: +[
      +  "name",
      +  "npmscanUrl",
      +  "beforeVersion",
      +  "afterVersion",
      +  "coexistingVersions",
      +  "changeType",
      +  "hasInstallScript",
      +  "installScriptIntroduced",
      +  "installScriptKeys",
      +  "installScriptKeysIntroduced",
      +  "isVulnerable",
      +  "highestSeverity",
      +  "vulnerabilities",
      +  "vulnerabilityDelta",
      +  "resolutionNote"
      +]
  3. Added

TDQS

A4.5/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations only convey read-only/non-destructive hints, so the description carries the full burden of behavioral disclosure. It exposes alias-following semantics, installScriptIntroduced boolean behavior, sourceIntegrityChanged, format scope differences, presence-only script detection, comparisonNote, projectLifecycleChanges, and overridesChanges, plus null-case caveats. This far exceeds what annotations provide and never contradicts them.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness3/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is a single dense paragraph of several hundred words with no bullet points or sectioning. It front-loads the core purpose and every sentence does carry useful edge-case detail, but the lack of structure makes it hard to scan and would benefit from bullets or short sections. Acceptable for the complexity, but not concise.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

The description is exhaustive for a tool of this complexity: supported formats, attack shapes, scope differences, output semantics, counters, null cases, and alternative routing are all covered. With an output schema present, return values need not be described, and even the 100-package cap is mentioned. Nothing an agent needs to invoke it correctly is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Both parameters are already fully documented in the schema with their format list and auto-detection behavior, reaching 100% coverage. The description adds only marginal parameter-level meaning (e.g., before/after PR context, scope notes), most of which is tool behavior rather than parameter semantics. Baseline 3 is appropriate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The opening sentence names the exact resource (two raw dependency snapshot files) and the specific verb (compares), and lists concrete outputs (added/removed/version-bumped). It also explicitly distinguishes itself from siblings like analyze_install_script, batch_query_vulnerabilities, and generate_sbom, so an agent can route correctly without opening schemas.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description explicitly states it is 'Ideal for a CI gate reviewing a dependency-changing PR' and gives concrete when-to-use/alternatives guidance: use analyze_install_script for deep-dive on flags, and notes that batch_query_vulnerabilities/generate_sbom exclude peerDependencies by default while this tool includes them. It even explains why a root postinstall change would be invisible without this tool.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources