📦🐈 Fast, reliable, and secure dependency management.
83%
Total Score
65
100
100
100
50
| Title | Versions | Severity |
|---|---|---|
CVE-2021-4435 yarn is vulnerable to Untrusted Search Path in versions 0.0.0 - 1.22.13. | 0.0.0 - 1.22.13 | High |
CVE-2019-15608 yarn is vulnerable to Time-of-check Time-of-use (TOCTOU) Race Condition in versions 0.0.0 - 1.19.0. | 0.0.0 - 1.19.0 | Medium |
CVE-2020-8131 yarn is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 0.0.0 - 1.21.1. | 0.0.0 - 1.21.1 | High |
CVE-2019-10773 yarn is vulnerable to Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in versions 0.0.0 - 1.21.1. | 0.0.0 - 1.21.1 | High |
CVE-2019-5448 yarn is vulnerable to Missing Encryption of Sensitive Data in versions 0.0.0 - 1.17.3. | 0.0.0 - 1.17.3 | High |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant