Hub rules-yarn

rules-yarn

v3 public Verified

Yarn

Yarn is a package manager that doubles as a project manager. These rules govern dependency version pinning and lockfile integrity for AI agents.

@sigmashakeinc 2 pulls 13 rules published Apr 8, 2026 synced Oct 4, 2026 sigmashakeinc/rules/rulesets/rules-yarn →
Severity
6 error 7 warn 0 info
demo.cast
Yarn is a package manager that doubles as a project manager. These rules govern dependency version pinning and lockfile integrity for AI agents.

Rules index

13 governance rules

Indexed from the repository's .rules files, grouped by technology. Expand any rule to read the raw source.

yarn

ask-yarn-dlx warning ask

yarn dlx downloads and executes a package without installing it. Without a version pin, it always fetches the latest release — a compromised release executes immediately in your project.

Rule source requires an active Pro or Enterprise subscription.
ask-yarn-patch warning ask

'yarn patch' modifies a dependency directly. The patch must be committed via 'yarn patch-commit' to the .yarn/patches directory to persist across reinstalls.

Rule source requires an active Pro or Enterprise subscription.
ask-yarn-publish warning ask

Publishing via yarn is permanent (except within 72 hours). Verify version, build output, and .npmignore before publishing.

Rule source requires an active Pro or Enterprise subscription.
ask-yarn-resolutions warning log

yarn resolutions silently override transitive dependency versions across the entire dependency tree. Incorrect resolutions can mask security vulnerabilities or introduce incompatible versions.

Rule source requires an active Pro or Enterprise subscription.
ask-yarnrc-plugins warning log

Yarn plugins listed in .yarnrc.yml execute code during yarn operations. A malicious or compromised plugin can intercept installs, intercept publishes, or alter dependency resolution.

Rule source requires an active Pro or Enterprise subscription.
no-caret-tilde-yarn error block

Caret (^) and tilde (~) version ranges produce non-reproducible installs. Use exact version pins to ensure every 'yarn install' resolves identically.

Rule source requires an active Pro or Enterprise subscription.
no-edit-yarn-lockfile error block

yarn.lock must not be hand-edited. It is machine-generated by 'yarn install'. Manual edits corrupt integrity checksums and break reproducible installs.

Rule source requires an active Pro or Enterprise subscription.
no-postinstall-script warning ask

postinstall/preinstall/install lifecycle scripts execute automatically when any consumer runs 'yarn install' on your package (CWE-829, supply-chain RCE). This is the primary vector used in malicious npm/yarn packages (e.g., event-stream, node-ipc). Audit the script body carefully and strongly prefer moving setup steps to an explicit 'yarn prepare' that only runs locally.

Rule source requires an active Pro or Enterprise subscription.
no-yarn-unpublish error block

yarn unpublish is blocked. Removing a published package version breaks all projects depending on it and cannot be undone after 72 hours. Use 'yarn npm deprecate' to discourage use without removing.

Rule source requires an active Pro or Enterprise subscription.
no-yarnrc-authtoken error block

Hardcoded npmAuthToken in .yarnrc.yml exposes registry credentials in source control. Use environment variable substitution: npmAuthToken: '${NPM_AUTH_TOKEN}'

Rule source requires an active Pro or Enterprise subscription.
no-yarnrc-enable-scripts-false-override warning log

enableScripts: true re-enables lifecycle script execution if it was disabled globally (e.g., via a parent .yarnrc.yml or CI policy). Lifecycle scripts are the primary supply-chain RCE vector in the npm/yarn ecosystem. Only set this if every package in your dependency tree is audited. Prefer the default (false in Yarn 4+) or per-package allowlisting.

Rule source requires an active Pro or Enterprise subscription.
no-yarnrc-http-registry error block

npmRegistryServer is set to a plain-HTTP URL. All registry traffic must use HTTPS to prevent a network attacker from serving tampered packages (CWE-319). Change the URL scheme to https://.

Rule source requires an active Pro or Enterprise subscription.
no-yarnrc-unsafe-http error block

unsafeHttpWhitelist in .yarnrc.yml permits Yarn to download packages over plain HTTP. Plain HTTP connections have no transport security and allow a network attacker to replace a package with malicious code (MiTM, CWE-319). Remove this key; all registry traffic must go over HTTPS.

Rule source requires an active Pro or Enterprise subscription.

Version metadata

Published metadata

The hash-locked record of this published ruleset. When source contents change, the maintainer resyncs and the version bumps.

Version
v3
Published
Apr 8, 2026
Source commits
0
Synced
Oct 4, 2026
Hash
07bb3636f5cfd7188a2653d1251abfacc994269365248d6a17c84ba6b417bd6b
Signature
Verified (publisher key)
Tested with
claude-code@current
Plan
Starter (free)
Visibility
Public

Source history

Recent commits

Latest commits touching rulesets/rules-yarn/.sigmashake/rules in sigmashakeinc/rules/rulesets/rules-yarn. The published version only bumps when a maintainer resyncs.

No commit history available.