-
Notifications
You must be signed in to change notification settings - Fork 2.7k
Closed
Description
Do you want to request a feature or report a bug?
feature
What is the current behavior?
npm added audit to warn about packages with known security issues. There was some conversation about this previously and one of the core npm folks said the API was likely to be open/public to pull this info. Therefore, yarn should be able to add this feature.
What is the expected behavior?
- Add a
yarn auditcommand that mimicsnpm audit - Add warnings when adding/installing packages with known issues.
Please mention your node.js, yarn and operating system version.
This would be a minor version bump, so likely target yarn v1.7.0 or v1.8.0 depending on timing.
This is probably too important to wait for v2.0.
tkharuk, PatrickNausha, ExE-Boss, rasmus-storjohann-PG, eduardb and 313 moremoffsugita, webdevbyjoss, adam2k, raphaguasta, mxmzb and 13 moremblackritter, blobor, JasonPan, Lau-Ren, juliandavidmr and 6 moregillesdemey, mknapik, kitsunde, Arnaud73, DrPep and 48 more