npm 2,036 also wrote package-lock.json (lockfileVersion 3). Its packages map is keyed by each package's path on disk, so it records the node_modules layout itself, not only versions.
jq -r '.packages | keys[] | select(test("node_modules/.*/node_modules/"))' package-lock.jsonOutput
node_modules/body-parser/node_modules/content-type node_modules/negotiator/node_modules/content-type node_modules/type-is/node_modules/content-type
Each entry also pins a resolved tarball URL and a SHA-512 integrity hash that npm checks on every later install. Every manager in this chapter writes its own lockfile format (3), and none treats another's as its source of truth, so commit exactly one.
| Package manager | Lockfile | Format | Keyed by |
|---|---|---|---|
| npm 11 | package-lock.json | JSON | Install path |
| Yarn Classic 1.22 11,798 | yarn.lock | Yarn 11,798 's own text format | Name and range |
| Yarn Berry 4 | yarn.lock | YAML | Name and range |
| pnpm 12 69,400 | pnpm-lock.yaml | YAML | Name and version |
| Bun 1.4 73,307 | bun.lock | JSON with comments | Name |