
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
yarn-no-save
Advanced tools
Enabling --no-save
/ -N
option to Yarn cli commands. The option prevents saving to package.json when you do yarn add
stuff.
First you should have yarn installed globally. https://classic.yarnpkg.com/en/docs/install#mac-stable
install yarn-no-save globally:
$ yarn global add yarn-no-save
Now you can use Yarn with --no-save
/ -N
option in your command:
$ yarn add --no-save xxxxxxxx
The --no-save / -N option will be available in help message by typing "yarn help add
" or "yarn add --help
".
You are free to uninstall any packages installed with --no-save
/ -N
option by executing "yarn uninstall xxxxx
" (postuninstall scripts will be executed by doing this, while the same thing won't happen by just deleting the folders from node_modules).
You can reset Yarn to default at anytime by reinstall yarn:
$ npm i -g yarn
If you want --no-save
option available again after reinstalling Yarn, just run the following command again:
$ yns
FAQs
Enabling --no-save/-N option to Yarn cli commands
The npm package yarn-no-save receives a total of 9 weekly downloads. As such, yarn-no-save popularity was classified as not popular.
We found that yarn-no-save demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.