Read saved npm package-lock v3 files alongside a timestamped package-metadata export. The report identifies how old the recorded release was at the metadata snapshot time, summarizes the exporter's supported 365-day release history, and optionally marks age-based review candidates. It does not say when a package was installed, whether it is vulnerable, or whether it should be upgraded. No registry, database, browser, host, or live package manager is contacted.
This walkthrough uses the tool's public README and checked-in example files. Run the command from a repository checkout with Node.js 22+; inspect the source before using it on your own files.
Run the checked-in example
node bin/dependency-age-report.mjs --root examples/clean --lock package-lock.json --snapshot metadata.json
node bin/dependency-age-report.mjs --root examples/failing --lock package-lock.json --snapshot metadata.json --review-after-days 30
node bin/dependency-age-report.mjs --root examples/incomplete --lock package-lock.json --snapshot metadata.json
npm run checkRead the result
These examples exit 0, 1 and 2 respectively. --help prints usage. JSON goes to stdout; a fixed human summary goes to stderr unless --json is specified. The tool has no report-file option and never writes an input or output file.
Where this check stops
The input dialect is deliberately narrow and only reports saved evidence. It does not run npm, inspect a live installation, resolve packages, infer semver compatibility, score maintainer health, classify vulnerabilities, edit lockfiles, or produce an upgrade plan. The metadata exporter must supply complete history for cadence; a null or later completeness date is unknown. Every test runs under an active network-denial preload, with a negative control proving denial works without contacting a host.
Before adapting the command to your own workflow, review the accepted inputs, exit codes and safety boundaries in the README.
Compiled with AI assistance from checked-in public documentation and example scripts. Run the example and review the repository's current documentation before relying on its result.