Turn an npm lockfile into a reviewable notice draft.
Compare local package metadata, classify exact license declarations with your policy, attach local LICENSE or NOTICE text and export an evidence ZIP. No package is executed and no registry, repository or URL is contacted.
Import release evidence
Both npm files are required. LICENSE and NOTICE text is optional.
No npm release files selected.
Selected manifest, lockfile and evidence content is processed in this page and is not sent to a WebRynx application endpoint. Package code is not executed and source files are not modified.
Dependency review
Every package remains visible, including missing and unlisted licenses.
Parsing and policy findings
Package decisions
| Package | Version | Declared license | Scope | Policy | Review decision |
|---|
Local evidence mapping
Map each supplied file to one exact package and version, or leave it as unassigned project evidence. Filename guesses are suggestions only.
| File | Kind | Package |
|---|
Draft release pack
The ZIP contains THIRD_PARTY_NOTICES, inventory JSON/CSV, decisions, policy, supplied evidence and a hash receipt. It is a review draft, not legal advice, a compliance conclusion or a certificate.