Severity
High
Short Description
One or more dependencies declared in package.json have no matching entry in yarn.lock. Stale lockfiles may result in unexpected SBOM output.
Suggestion
Run yarn install and commit the updated yarn.lock so package.json and the lockfile agree, then re-scan.