Upon cloning a project and executing npm install, I want to have a list of all the urls used for downloading the files. Is there a way to possibly get that list?
Upon cloning a project and executing npm install, I want to have a list of all the urls used for downloading the files. Is there a way to possibly get that list?
The package-lock.json or yarn.lock file can provide the list of resolved registry files:
$ cat yarn.lock | grep -E -e '^\s+resolved\s+'
resolved "https://registry.npmjs.org/wtfnode/-/wtfnode-0.9.1.tgz"
$ cat package-lock.json | jq '.dependencies[] | .resolved'
"https://registry.npmjs.org/ms/-/ms-2.0.0.tgz"
There can be additional files that are fetched outside of a package managers remit, in the install life cycle scripts. As there is no standard for how this should happen, these URL's are harder to list.
You might be able to catch some retrieved via Javascript in Node by adding some debug environment variables:
NODE_DEBUG=http,https,tls DEBUG='*' npm install
The only guaranteed way to capture everything would be remove network access from where npm is running force all traffic via an inspection proxy like mitmproxy