Back to Dependencycheck

Yarn Audit

src/site/markdown/analyzers/yarn-audit.md

12.2.2288 B
Original Source

Yarn Audit Analyzer

Uses the Yarn CLI audit command to analyze yarn.lock files and retrieve vulnerabilities from the NPM Audit APIs.

Supports Yarn v1 and Yarn v2+ (Berry) and is corepack-aware.

Files Types Scanned: package.json, yarn.lock