Offline, read-only ranking of changes between two exported, normalized dependency lock snapshots. No package manager, advisory service or network is contacted. The caller supplies explicit use/rollback factors, advisory status and API compatibility notes for every changed dependency; absent context is unknown, never an assumed clean bill.
This walkthrough uses the tool's public README and checked-in example files. Run the command from a repository checkout with Node.js 22+; inspect the source before using it on your own files.
Run the checked-in example
node bin/dependency-update-risk-map.mjs --root examples --input passing.json
node bin/dependency-update-risk-map.mjs --root examples --input failing.json
npm run checkRead the result
--root confines reads by real path; --input is a relative path within it. Optional --human prints one summary to stderr. Stdout is only the JSON report; nothing is written. Invalid options/configuration: exit 2, empty stdout. Unreadable, undecodable, malformed, incomplete or unsupported evidence: incomplete report, exit 2. High-risk evaluated update: fail, exit 1. Fully evaluated updates below the review threshold: pass, exit 0.
Where this check stops
1,048,576 UTF-8 bytes; 100 records per collection (each lock snapshot and each context export); JSON depth 4 from root depth 0; 5,000 ms injectable library clock. Exact N accepted; N+1 incomplete. Strict UTF-8 and duplicate JSON key rejection (including escaped keys) prevent ambiguous evidence. CLI read has a 5-second abort. No package resolution, network, install, upgrade, remediation, or runtime compatibility test.
Before adapting the command to your own workflow, review the accepted inputs, exit codes and safety boundaries in the README.
Compiled with AI assistance from checked-in public documentation and example scripts. Run the example and review the repository's current documentation before relying on its result.