yarn-osv-audit
JSON →A lightweight, zero-dependency CLI tool (v0.1.8, active development) that audits Yarn Classic (v1) lockfiles against the OSV.dev vulnerability database. It supports four output formats (compact, table, json, summary), config files, severity filtering, and allowlisting. Unlike npm audit or yarn audit, it uses the open-source OSV database and works with Yarn v1 lockfiles. Requires Node >=18. Released via GitHub Actions with npm provenance.
Traffic · last 30 days stale · no recent hits
total hits 26
actors 6 distinct systems
last hit 16d ago human
top countries 🇺🇸 United States · 🇸🇬 Singapore · VN · TN · BD
Resources
API endpoints
full doc /v1/registry/yarn-osv-audit
compatibility /v1/registry/yarn-osv-audit/compatibility