Alexandro.Net

Version 1.0.0

@stackline/yarn

๐Ÿ“ฆ๐Ÿˆ Fast, reliable, and secure dependency management.

Independent maintenance of yarn 1.22.22. Original authors and licenses are retained.

Installation

# Preserve existing imports with an npm alias
npm install yarn@npm:@stackline/yarn@1.0.0
# Or use the scoped package name in your imports
npm install @stackline/yarn@1.0.0

Node.js: >=20.19.0. Read the compatibility and maintenance notes before migrating.

Usage and API

The reference below may retain upstream package names. Use the alias installation above to run those imports with this Stackline release.

@stackline/yarn

A maintained fork of Yarn Classic 1.22.22, rebuilt from its source history. Requires Node.js >=20.19.0. Published package version: 1.0.0.

npm install --global @stackline/yarn@1.0.0
yarn --version
yarnpkg install --frozen-lockfile

For a project-local toolchain:

npm install --save-dev yarn@npm:@stackline/yarn@1.0.0
npx yarn install

The yarn and yarnpkg commands retain Classic's v1 lockfile, dependency protocols, cache/offline behavior and script/bin invocation. Existing Classic documentation describes those commands. This fork is independent of the Yarn project.

Packaging and compatibility

This release raises the Node.js minimum from upstream's Node 4 baseline to 20.19. It rebuilds the CLI and lockfile parser with current tools and security updates. Third-party runtime dependencies are external and declared in package.json, so normal npm installation is required. lib/cli.js copied alone is no longer a standalone distribution. OS installers and Corepack integration are outside this release's packaging contract.

lib/build-inventory.json lists the bundled project modules and external runtime dependency specifications. The build rejects undeclared imports and embedded third-party modules. package-lock.json records the exact CI graph. The published tarball is the tested CI artifact, with npm provenance and a matching immutable GitHub release.

Development

npm ci --ignore-scripts
npm run build
npm test
npm run test:cli
npm run test:security
npm run test:package
npm audit --audit-level=low

See UPSTREAM.md for issue triage, compatibility decisions and known qualifications, CHANGELOG.md for changes, and SECURITY.md for private vulnerability reporting.

Upstream issues and maintenance review

Upstream and security review

Base: Yarn Classic 1.22.22 source. The native fork retains upstream history and BSD notices. This distribution is rebuilt from source, not a claim that upstream's precompiled bundle was rebuilt byte-for-byte. Node >=20.19 and external runtime dependencies are explicit compatibility changes; CLI names, v1 lockfile and Classic protocols remain.

Security scope

The original npm bundle contains tar-fs 1.16.3, confirmed by exact module-source comparison after rewriting only webpack require references. An isolated symlink/hardlink extraction fixture reproduced the directory escape documented in GHSA-pq67-2wwv-3xjx and GHSA-vj76-c3g6-qr5v. The rebuilt fork uses external tar-fs 1.16.6; that same fixture must reject the archive and leave its outside sentinel unchanged. No upstream bundle is shipped.

The build inventory rejects node_modules content embedded in the new outputs. Full and runtime npm audits therefore cover the actual third-party graph. CodeQL analyzes source, bin and the rebuilt non-minified CLI/parser, with minified-file extraction explicitly enabled as documented in CodeQL 2.24.

This request covers the original parent packages rather than recursively creating forks for every dependency of this new tool. Inherited deprecated dependency versions include glob@7.2.3, inflight@1.0.6, rimraf@2.7.1, mkdirp-promise@5.0.1 and lodash.clone@4.5.0. Exact installed versions and warnings are recorded by installation verification; this is not an unrestricted Production Dependency Closure Policy pass. Vulnerabilities, invalid engines, peers, integrity, lifecycle failures and deprecation of this maintained package remain release blockers.

Issues reviewed

The sorting fixture now expects the redundant lockfile name to be omitted, matching both unchanged source and the integrity-verified upstream 1.22.22 bundle used as an independent oracle.

No upstream maintainer was contacted. The original tests are retained while obsolete Jest APIs, expired fixture certificates and snapshot rendering are adapted to the modern toolchain. Publication requires their recorded CI result.

The original disabled info-command suite and three individually skipped upstream cases remain disabled (15 cases total); they are not reported as passed. The maintained CLI is additionally tested from its installed tarball.

Release changes

Changelog

1.0.0

Release files and references

Package bytes, npm provenance and the immutable GitHub release were verified for this version. Security checks describe the reviewed release; documented compatibility risks and upstream reports are not blanket claims of resolution.