deps/yarn

Free catalog · v0.0.10

Reviews Yarn projects for unsafe configuration and incomplete dependency-resolution inputs.

Checks

RuleSeverityScans for
yarn.auth-token-inlineHighRegistry auth token committed in Yarn config
yarn.checksum-ignoredHighLockfile integrity verification weakened or bypassed
yarn.docker-missing-patchesHighA container stage copies a patched Yarn lockfile and runs yarn install without copying the referenced patch artifacts
yarn.http-registryHighRegistry or resolved tarball URLs over plain HTTP
yarn.missing-lockfileMediumYarn project without a committed yarn.lock
yarn.mutable-resolutionMediumDependencies resolved to mutable VCS refs
yarn.strict-ssl-disabledHighTLS certificate verification disabled for registry traffic

More from the registry