is there a way to get the list of all the urls needed to download the packages from node modules

Viewed 44

Upon cloning a project and executing npm install, I want to have a list of all the urls used for downloading the files. Is there a way to possibly get that list?

1 Answers

The package-lock.json or yarn.lock file can provide the list of resolved registry files:

$ cat yarn.lock | grep -E -e '^\s+resolved\s+'
resolved "https://registry.npmjs.org/wtfnode/-/wtfnode-0.9.1.tgz"

$ cat package-lock.json | jq '.dependencies[] | .resolved'
"https://registry.npmjs.org/ms/-/ms-2.0.0.tgz"

There can be additional files that are fetched outside of a package managers remit, in the install life cycle scripts. As there is no standard for how this should happen, these URL's are harder to list.

You might be able to catch some retrieved via Javascript in Node by adding some debug environment variables:

NODE_DEBUG=http,https,tls DEBUG='*' npm install

The only guaranteed way to capture everything would be remove network access from where npm is running force all traffic via an inspection proxy like mitmproxy

Related