
Product
Socket for Jira Is Now Available
Socket for Jira lets teams turn alerts into Jira tickets with manual creation, automated ticketing rules, and two-way sync.
compact-yarn-audit
Advanced tools
compact-yarn-audit presents yarn audit output in a compact table, ordered by severity.
yarn audit --json --verbose | npx compact-yarn-audit@latest
Note: yarn's audit output can be quite large (gigabytes for a sizeable monorepo that hasn't had updates for a while), so it can take some time to process all that data.
severity title module via "resolutions" string
critical Command Injection destructomatic vertex-cli no fix available
critical Remote code execution wh… steering-wheel beach-cruiser "steering-wheel": ">=4.7.7"
critical Prototype Pollution steering-wheel beach-cruiser "steering-wheel": ">=4.1.2"
high Regular Expression Denia… oedipus-regex vertexql-types no fix available
high Command Injection snowdash beach-cruiser "snowdash": ">=4.17.21"
high Prototype Pollution snowdash beach-cruiser "snowdash": ">=4.17.12"
high Prototype Pollution snowdash beach-cruiser "snowdash": ">=4.17.11"
high Command Injection snowdash . "snowdash": ">=4.17.21"
high Prototype Pollution snowdash . "snowdash": ">=4.17.12"
high Prototype Pollution snowdash . "snowdash": ">=4.17.11"
high Prototype Pollution steering-wheel beach-cruiser "steering-wheel": ">=4.5.3"
high Arbitrary Code Execution steering-wheel beach-cruiser "steering-wheel": ">=4.5.3"
high Arbitrary Code Execution steering-wheel beach-cruiser "steering-wheel": ">=4.5.2"
high Prototype Pollution steering-wheel beach-cruiser "steering-wheel": ">=4.3.0"
moderate Information Exposure mars-server-core mars-server "mars-server-core": ">=2.14.2"
moderate Regular Expression Denia… chestnut beach-cruiser "chestnut": ">=7.1.1"
moderate Denial of Service steering-wheel beach-cruiser "steering-wheel": ">=4.4.5"
low Prototype Pollution minifog beach-cruiser "minifog": "<1.0.0 || >=1.2.3"
low Prototype Pollution snowdash beach-cruiser "snowdash": ">=4.17.19"
low Prototype Pollution snowdash . "snowdash": ">=4.17.19"
low Prototype Pollution snowdash . "snowdash": ">=4.17.5"
The default output of yarn's audit is verbose (just like npm's audit is).
When there's more than 3 vulnerabilities it doesn't fit on a screen anymore.
It also contains information I'm not interested in when I want to know what
to fix and with what urgency:
This module attempts to fix that by leaving out all information not essential to my use case.
FAQs
Presents output from yarn audit in a compact table
We found that compact-yarn-audit demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Product
Socket for Jira lets teams turn alerts into Jira tickets with manual creation, automated ticketing rules, and two-way sync.

Company News
Socket won two 2026 Reppy Awards from RepVue, ranking in the top 5% of all sales orgs. AE Alexandra Lister shares what it's like to grow a sales career here.

Security News
NIST will stop enriching most CVEs under a new risk-based model, narrowing the NVD's scope as vulnerability submissions continue to surge.