Ecosyste.ms: OpenCollective

An open API service for software projects hosted on Open Collective.

github.com/yarnpkg/yarn

The 1.x line is frozen - features and bugfixes now happen on https://github.com/yarnpkg/berry
https://github.com/yarnpkg/yarn

High
GSA_kwCzR0hTQS1tcHdqLWZjcjYteDM0Y84AA5DS
Yarn untrusted search path vulnerability
Ecosystems: npm
Packages: yarn
Source: github
Published: 11 months ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWhqeGMtNDYyeC14Nzdq
TOCTOU Race Condition in Yarn
Ecosystems: npm
Packages: yarn
Source: github
Published: almost 3 years ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLThtZmMtdjd3di1wNjJn
Path Traversal in Yarn
Ecosystems: npm
Packages: yarn
Source: github
Published: almost 3 years ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTV4ZjQtZjJmcS1mNjlq
Yarn Improper link resolution before file access (Link Following)
Ecosystems: npm
Packages: yarn
Source: github
Published: almost 5 years ago