Package Exports
This package does not declare an exports field, so the exports above have been automatically detected and optimized by JSPM instead. If any package subpath is missing, it is recommended to post an issue to the original package (sentinel-check) to support the "exports" field. If that is not possible, create a JSPM override to customize the exports field for this package.
Readme
sentinel-check
Thin npm wrapper for the
sentinelCLI published from the sentinel-npm repository.
Use npx --yes sentinel-check ... for one-shot runs with no manual binary setup.
Sentinel supports lockfile verification for npm, Yarn, and pnpm with automatic manager detection.
Quick start
Run directly with npx
# audit only
npx --yes sentinel-check check
# validate lockfile then install dependencies
npx --yes sentinel-check ci
# install one package with verification
npx --yes sentinel-check install lodash@4.17.21Add to package.json scripts (recommended)
Install once in the project and call sentinel from npm scripts:
npm install -D sentinel-check{
"scripts": {
"sentinel:check": "sentinel check",
"sentinel:ci": "sentinel ci"
}
}npm run sentinel:check
npm run sentinel:ciNeed package install with verification? Run it directly:
npx --yes sentinel-check install lodash@4.17.21CI usage
GitHub Actions:
- name: Verify dependency integrity
run: npx --yes sentinel-check ciIf the workflow needs Sentinel to initialize the lockfile first:
- name: Initialize lockfile and verify dependency integrity
run: npx --yes sentinel-check ci --initNotes
- The wrapper downloads the matching Sentinel release binary on first use.
- Downloaded binaries are cached locally.
- Integrity is verified using release checksums before execution.
- If you see
dependency cycles detected, Sentinel found circular dependency chains in the lockfile graph. Verification continues and cycles are reported as a warning. You'll still see the integrity status of all packages. For a safe first recovery step, removenode_modulesand rerunnpx --yes sentinel-check ci. If lockfile recovery is needed, remove the lockfile and rerunnpx --yes sentinel-check ci --initso Sentinel regenerates it in the guarded flow.
More documentation
- Security policy: SECURITY.md
- Threat model: THREAT_MODEL.md
- Adoption and distribution guide: ADOPTION_DISTRIBUTION.md
Useful environment variables
| Variable | Description |
|---|---|
SENTINEL_BIN |
Use an existing local sentinel binary |
SENTINEL_VERSION |
Pin a specific Sentinel version |
SENTINEL_SKIP_DOWNLOAD=1 |
Disable automatic binary download |
See the main README for full CLI usage and binary installation options.