Security News
New Python Packaging Proposal Aims to Solve Phantom Dependency Problem with SBOMs
PEP 770 proposes adding SBOM support to Python packages to improve transparency and catch hidden non-Python dependencies that security tools often miss.
yarn-no-save
Advanced tools
Enabling --no-save
/ -N
option to Yarn cli commands. The option prevents saving to package.json when you do yarn add
stuff.
First you should have yarn installed globally. https://classic.yarnpkg.com/en/docs/install#mac-stable
install yarn-no-save globally:
$ yarn global add yarn-no-save
Now you can use Yarn with --no-save
/ -N
option in your command:
$ yarn add --no-save xxxxxxxx
The --no-save / -N option will be available in help message by typing "yarn help add
" or "yarn add --help
".
You are free to uninstall any packages installed with --no-save
/ -N
option by executing "yarn uninstall xxxxx
" (postuninstall scripts will be executed by doing this, while the same thing won't happen by just deleting the folders from node_modules).
You can reset Yarn to default at anytime by reinstall yarn:
$ npm i -g yarn
If you want --no-save
option available again after reinstalling Yarn, just run the following command again:
$ yns
FAQs
Enabling --no-save/-N option to Yarn cli commands
The npm package yarn-no-save receives a total of 5 weekly downloads. As such, yarn-no-save popularity was classified as not popular.
We found that yarn-no-save demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
PEP 770 proposes adding SBOM support to Python packages to improve transparency and catch hidden non-Python dependencies that security tools often miss.
Security News
Socket CEO Feross Aboukhadijeh discusses open source security challenges, including zero-day attacks and supply chain risks, on the Cyber Security Council podcast.
Security News
Research
Socket researchers uncover how threat actors weaponize Out-of-Band Application Security Testing (OAST) techniques across the npm, PyPI, and RubyGems ecosystems to exfiltrate sensitive data.