Version 1.0.0
@stackline/yarn
๐ฆ๐ Fast, reliable, and secure dependency management.
Independent maintenance of yarn 1.22.22. Original authors and licenses are retained.
Installation
# Preserve existing imports with an npm alias
npm install yarn@npm:@stackline/yarn@1.0.0
# Or use the scoped package name in your imports
npm install @stackline/yarn@1.0.0Node.js: >=20.19.0. Read the compatibility and maintenance notes before migrating.
Usage and API
The reference below may retain upstream package names. Use the alias installation above to run those imports with this Stackline release.
@stackline/yarn
A maintained fork of Yarn Classic 1.22.22, rebuilt from its source history. Requires Node.js >=20.19.0. Published package version: 1.0.0.
npm install --global @stackline/yarn@1.0.0
yarn --version
yarnpkg install --frozen-lockfile
For a project-local toolchain:
npm install --save-dev yarn@npm:@stackline/yarn@1.0.0
npx yarn install
The yarn and yarnpkg commands retain Classic's v1 lockfile, dependency
protocols, cache/offline behavior and script/bin invocation. Existing
Classic documentation describes
those commands. This fork is independent of the Yarn project.
Packaging and compatibility
This release raises the Node.js minimum from upstream's Node 4 baseline to
20.19. It rebuilds the CLI and lockfile parser with current tools and security
updates. Third-party runtime dependencies are external and declared in
package.json, so normal npm installation is required. lib/cli.js copied
alone is no longer a standalone distribution. OS installers and Corepack
integration are outside this release's packaging contract.
lib/build-inventory.json lists the bundled project modules and external
runtime dependency specifications. The build rejects undeclared imports and
embedded third-party modules. package-lock.json records the exact CI graph.
The published tarball is the tested CI artifact, with npm provenance and a
matching immutable GitHub release.
Development
npm ci --ignore-scripts
npm run build
npm test
npm run test:cli
npm run test:security
npm run test:package
npm audit --audit-level=low
See UPSTREAM.md for issue triage, compatibility decisions and known qualifications, CHANGELOG.md for changes, and SECURITY.md for private vulnerability reporting.
Upstream issues and maintenance review
Upstream and security review
Base: Yarn Classic 1.22.22 source. The native fork retains upstream history and BSD notices. This distribution is rebuilt from source, not a claim that upstream's precompiled bundle was rebuilt byte-for-byte. Node >=20.19 and external runtime dependencies are explicit compatibility changes; CLI names, v1 lockfile and Classic protocols remain.
Security scope
The original npm bundle contains tar-fs 1.16.3, confirmed by exact module-source comparison after rewriting only webpack require references. An isolated symlink/hardlink extraction fixture reproduced the directory escape documented in GHSA-pq67-2wwv-3xjx and GHSA-vj76-c3g6-qr5v. The rebuilt fork uses external tar-fs 1.16.6; that same fixture must reject the archive and leave its outside sentinel unchanged. No upstream bundle is shipped.
The build inventory rejects node_modules content embedded in the new outputs. Full and runtime npm audits therefore cover the actual third-party graph. CodeQL analyzes source, bin and the rebuilt non-minified CLI/parser, with minified-file extraction explicitly enabled as documented in CodeQL 2.24.
This request covers the original parent packages rather than recursively creating forks for every dependency of this new tool. Inherited deprecated dependency versions include glob@7.2.3, inflight@1.0.6, rimraf@2.7.1, mkdirp-promise@5.0.1 and lodash.clone@4.5.0. Exact installed versions and warnings are recorded by installation verification; this is not an unrestricted Production Dependency Closure Policy pass. Vulnerabilities, invalid engines, peers, integrity, lifecycle failures and deprecation of this maintained package remain release blockers.
Issues reviewed
- #9210: Classic still uses url.parse. Node 24's DEP0169 diagnostic remains visible; no general deprecation suppression is installed. It is a known compatibility qualification, not a solved claim.
- #9198: dependency engine selection is not redesigned. Existing package compatibility/resolver tests remain.
- #9196: CLI installs and script/bin arguments are exercised with spaces. This does not claim to fix every external native compiler's quoting behavior.
- #9195 and #9183: real HTTP timeout/retry, local registry and offline cache tests are retained. No claim is made about unprovided Windows/network reproductions.
- #9192: the requested v3/v4 monorepo protocol feature belongs to a different major line and is not added to Classic.
The sorting fixture now expects the redundant lockfile name to be omitted, matching both unchanged source and the integrity-verified upstream 1.22.22 bundle used as an independent oracle.
No upstream maintainer was contacted. The original tests are retained while obsolete Jest APIs, expired fixture certificates and snapshot rendering are adapted to the modern toolchain. Publication requires their recorded CI result.
The original disabled info-command suite and three individually skipped upstream cases remain disabled (15 cases total); they are not reported as passed. The maintained CLI is additionally tested from its installed tarball.
Release changes
Changelog
1.0.0
- Fork Yarn Classic 1.22.22 with upstream Git history, BSD license and notices.
- Require Node >=20.19 and rebuild project code with Webpack 5/Babel 7. Declare all third-party runtime dependencies externally; reject hidden bundled dependencies.
- Replace request with its compatible maintained @cypress/request implementation; update tar-fs, ssri, micromatch, normalize-url, uuid and inquirer.
- Preserve Classic nohoist trailing-glob behavior with strictSlashes, CLI pattern alternation with an explicit group, and invalid-integrity repair under ssri 12.
- Preserve local archive file paths in Node 24 extraction diagnostics.
- Modernize Jest APIs, isolate operator npm configuration, run concurrent legacy cases serially, renew expired test TLS certificates and exercise real HTTP retry/TLS.
- Test the CLI with actual HTTP installation, integrity, offline frozen-lockfile reinstallation, paths/arguments containing spaces, and malicious archive rejection.
- Publish only the reviewed CI archive after CI, full audit and CodeQL checks; verify direct/aliased installations, signatures, provenance and immutable assets.
Release files and references
- README.md
- UPSTREAM.md
- CHANGELOG.md
- LICENSE
- NOTICE
- Package and publication metadata
- Full text documentation
Package bytes, npm provenance and the immutable GitHub release were verified for this version. Security checks describe the reviewed release; documented compatibility risks and upstream reports are not blanket claims of resolution.