
Security News
Risky Biz Podcast: Making Reachability Analysis Work in Real-World Codebases
This episode explores the hard problem of reachability analysis, from static analysis limits to handling dynamic languages and massive dependency trees.
yarn-audit-ci
Advanced tools
CI-friendly yarn audit wrapper. Only returns a non-zero exit code for at least the requested severity level.
$ yarn add yarn-audit-ci --dev
In the console:
$ yarn-audit-ci // only fail on critical issues (default)
$ yarn-audit-ci --critical // only fail on critical issues (explicit)
$ yarn-audit-ci --high // only fail on high or critical issues
$ yarn-audit-ci --moderate // only fail on at least moderate issues
$ yarn-audit-ci --low // only fail on at least low issues
$ yarn-audit-ci --info // fail on any issues
Using shorter options:
$ yarn-audit-ci -c // only fail on critical issues (explicit)
$ yarn-audit-ci -h // only fail on high or critical issues
$ yarn-audit-ci -m // only fail on at least moderate issues
$ yarn-audit-ci -l // only fail on at least low issues
$ yarn-audit-ci -i // fail on any issues
Using a shorter yaudit
alias:
$ yaudit
$ yaudit -h
$ yaudit --high
In the console using yarn:
$ yarn yarn-audit-ci --high
$ yarn yaudit --high
In the package.json
// package.json
"scripts": {
"audit": "yarn-audit-ci"
},
// console
$ yarn run audit
In the package.json
using a script name different from audit
, which is a yarn CLI command thus explicit run
in the previous example:
// package.json
"scripts": {
"audit:ci": "yarn-audit-ci",
"audit:high": "yarn-audit-ci --high"
},
// console
$ yarn audit:ci
$ yarn audit:high
In the package.json
using a yaudit
alias:
// package.json
"scripts": {
"audit:high": "yaudit --high"
},
// console
$ yarn audit:high
In package.json
in combination with the yall-scripts tool:
// package.json
"scripts": {
"audit": "yaudit",
"check": "eslint ./src",
"test": "jest ./src",
"all": "yall audit check test"
},
// console
$ yarn all
FAQs
yarn audit wrapper for ci
The npm package yarn-audit-ci receives a total of 542 weekly downloads. As such, yarn-audit-ci popularity was classified as not popular.
We found that yarn-audit-ci demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
This episode explores the hard problem of reachability analysis, from static analysis limits to handling dynamic languages and massive dependency trees.
Security News
/Research
Malicious Nx npm versions stole secrets and wallet info using AI CLI tools; Socket’s AI scanner detected the supply chain attack and flagged the malware.
Security News
CISA’s 2025 draft SBOM guidance adds new fields like hashes, licenses, and tool metadata to make software inventories more actionable.