Mode B · Offline upload
Upload a lockfile
Scan offline from package-lock.json. Optional files improve pipeline coverage.
When to use this mode
Use when your repo isn't on GitHub, contains private context, or you want to scan a specific lockfile offline.
package-lock.json is required.
Without the workflows zip, the pipeline lens vetoes auto-merge on every finding.
Files never stored after scan
JSON-only parsing, no code execution