Reading package-lock.json

npm 2,036 also wrote package-lock.json (lockfileVersion 3). Its packages map is keyed by each package's path on disk, so it records the node_modules layout itself, not only versions.

Finding the nested packages in BookNest's lockfileShell
jq -r '.packages | keys[] | select(test("node_modules/.*/node_modules/"))' package-lock.json
Output
node_modules/body-parser/node_modules/content-type
node_modules/negotiator/node_modules/content-type
node_modules/type-is/node_modules/content-type

Each entry also pins a resolved tarball URL and a SHA-512 integrity hash that npm checks on every later install. Every manager in this chapter writes its own lockfile format (3), and none treats another's as its source of truth, so commit exactly one.

The lockfile each JavaScript package manager writes
Package manager Lockfile Format Keyed by
npm 11 package-lock.json JSON Install path
Yarn Classic 1.22 11,798 yarn.lock Yarn 11,798 's own text format Name and range
Yarn Berry 4 yarn.lock YAML Name and range
pnpm 12 69,400 pnpm-lock.yaml YAML Name and version
Bun 1.4 73,307 bun.lock JSON with comments Name