Index › programming › yarn yarn 2 tools · 1 release line Yarn package manager. Every tool here carries the same sandbox boundary. $ kapsl yarn ⧉ $ kapsl yarnpkg ⧉ Source ↗ Registry ↗ Release lines we maintain · the project decides these findings shown are the whole project at that line Tag Resolves to Lifecycle Updated Findings What the tag promises ▸ latest 1.22.22 stable 2026-08-26 58 tracks the newest supported release stable — floats, carries security updates unstable — tracks pre-releases, may break eol — frozen, upstream is done Tools in this project · pick one to inspect all share one boundary Tool Capabilities Seccomp Findings Image Description ▸ yarn netrw default C6H30M18L4 yarn Package manager for JavaScript ▸ yarnpkg netrw default C6H30M18L4 yarn Package manager for JavaScript (alias of yarn) ▸ showing yarn yarnpkg from yarn@latest → 1.22.22 stable Findings C6H30M18L4 identical on amd64, arm64 — one table describes both CVE Sev CVSS Affects Description GHSA-29xr-v42j-r956 ↗ C 9.8 thenify thenify before 3.3.1 made use of unsafe calls to `eval`. GHSA-76p3-8jx3-jpfq ↗ C 9.8 loader-utils Prototype pollution in webpack loader-utils GHSA-896r-f27r-55mw ↗ C 9.8 json-schema json-schema is vulnerable to Prototype Pollution GHSA-xvch-5gv4-984h ↗ C 9.8 minimist Prototype Pollution in minimist GHSA-fjxv-7rqg-78g4 ↗ C 9.4 form-data form-data uses unsafe random function in form-data for choosing boundary GHSA-jf85-cpcp-j695 ↗ C 9.1 lodash Prototype Pollution in lodash GHSA-3ppc-4f35-3m26 ↗ H 8.7 minimatch minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern GHSA-8cj5-5rvv-wf4v ↗ H 8.7 tar-fs tar-fs can extract outside the specified dir with a specific tarball GHSA-vj76-c3g6-qr5v ↗ H 8.7 tar-fs tar-fs has a symlink validation bypass if destination directory is predictable with a specific tarball GHSA-r5fr-rjxr-66jc ↗ H 8.1 lodash lodash vulnerable to Code Injection via `_.template` imports key names GHSA-cwx2-736x-mf6w ↗ H 7.7 object-path Prototype pollution in object-path GHSA-ph9p-34f9-6g65 ↗ H 7.7 tmp tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape GHSA-23c5-xmqv-rm74 ↗ H 7.5 minimatch minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions GHSA-3rfm-jhwj-7488 ↗ H 7.5 loader-utils loader-utils is vulnerable to Regular Expression Denial of Service (ReDoS) via url variable GHSA-52cp-r559-cp3m ↗ H 7.5 js-yaml js-yaml: YAML merge-key chains can force quadratic CPU consumption GHSA-5p4m-2wfm-xmqj ↗ H 7.5 js-yaml JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported GHSA-6c8f-qphg-qjgp ↗ H 7.5 kind-of Validation Bypass in kind-of GHSA-7r86-cg39-jmmj ↗ H 7.5 minimatch minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments GHSA-8v63-cqqc-6r2c ↗ H 7.5 object-path Prototype Pollution in object-path GHSA-93q8-gq69-wqmw ↗ H 7.5 ansi-regex Inefficient Regular Expression Complexity in chalk/ansi-regex GHSA-c2qf-rxjj-qqgw ↗ H 7.5 semver semver vulnerable to Regular Expression Denial of Service GHSA-f8q6-p94x-37v3 ↗ H 7.5 minimatch minimatch ReDoS vulnerability GHSA-grv7-fg5c-xmjg ↗ H 7.5 braces Uncontrolled resource consumption in braces GHSA-hhq3-ff78-jv3g ↗ H 7.5 loader-utils loader-utils is vulnerable to Regular Expression Denial of Service (ReDoS) GHSA-hmw2-7cc7-3qxx ↗ H 7.5 form-data form-data: CRLF injection in form-data via unescaped multipart field names and filenames GHSA-hrpp-h998-j3pp ↗ H 7.5 qs qs vulnerable to Prototype Pollution GHSA-mh99-v99m-4gvg ↗ H 7.5 brace-expansion brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash GHSA-pq67-2wwv-3xjx ↗ H 7.5 tar-fs tar-fs Vulnerable to Link Following and Path Traversal via Extracting a Crafted tar File GHSA-rgw5-rvv9-x895 ↗ H 7.5 brace-expansion brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation GHSA-vx3p-948g-6vhq ↗ H 7.5 ssri Regular Expression Denial of Service (ReDoS) GHSA-w573-4hg7-7wgq ↗ H 7.5 decode-uri-component decode-uri-component vulnerable to Denial of Service (DoS) GHSA-w5hq-g745-h8pq ↗ H 7.5 uuid uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided GHSA-p6mc-m468-83gw ↗ H 7.4 lodash Prototype Pollution in lodash GHSA-qqgx-2p2h-9c37 ↗ H 7.3 ini ini before 1.3.6 vulnerable to Prototype Pollution via ini.parse GHSA-35jh-r3h4-6jhm ↗ H 7.2 lodash Command Injection in lodash GHSA-9c47-m6qq-7p4h ↗ H 7.1 json5 Prototype Pollution in JSON5 via Parse Method GHSA-72xf-g2v4-qvf3 ↗ M 6.5 tough-cookie tough-cookie Prototype Pollution vulnerability GHSA-f23m-r3pf-42rh ↗ M 6.5 lodash lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit` GHSA-f886-m6hf-6m8v ↗ M 6.5 brace-expansion brace-expansion: Zero-step sequence causes process hang and memory exhaustion GHSA-pp7h-53gx-mx7r ↗ M 6.5 bl Remote Memory Exposure in bl GHSA-x5rq-j2xg-h7qm ↗ M 6.5 lodash Regular Expression Denial of Service (ReDoS) in lodash GHSA-xxjr-mmjv-4gpg ↗ M 6.5 lodash Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions GHSA-p8p7-x288-28g6 ↗ M 6.1 request Server-Side Request Forgery in Request GHSA-4xc9-xhrj-v574 ↗ M 5.6 lodash Prototype Pollution in lodash GHSA-v39p-96qg-c8rf ↗ M 5.6 object-path Prototype Pollution in object-path GHSA-v88g-cgmw-v5xw ↗ M 5.6 ajv Prototype Pollution in Ajv GHSA-vh95-rmgr-6w4m ↗ M 5.6 minimist Prototype Pollution in minimist GHSA-2g4f-4pwh-qvx6 ↗ M 5.5 ajv ajv has ReDoS when using `$data` option GHSA-29mw-wpgm-hmr9 ↗ M 5.3 lodash Regular Expression Denial of Service (ReDoS) in lodash GHSA-3jxr-9vmj-r5cp ↗ M 5.3 brace-expansion brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups GHSA-952p-6rrq-rcjv ↗ M 5.3 micromatch Regular Expression Denial of Service (ReDoS) in micromatch GHSA-h67p-54hq-rp68 ↗ M 5.3 js-yaml JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases GHSA-hj48-42vr-x3v9 ↗ M 5.3 path-parse Regular Expression Denial of Service in path-parse GHSA-mh29-5h37-fv8m ↗ M 5.3 js-yaml js-yaml has prototype pollution in merge (<<) GHSA-6rw7-vpxm-498p ↗ L 3.7 qs qs's arrayLimit bypass in its bracket notation allows DoS via memory exhaustion GHSA-v6h2-p8h4-qcjw ↗ L 3.1 brace-expansion brace-expansion Regular Expression Denial of Service vulnerability GHSA-52f5-9888-hmc6 ↗ L 2.5 tmp tmp allows arbitrary temporary file / directory write via symbolic link `dir` parameter GHSA-c6rq-rjc2-86v2 ↗ L 2.5 chownr Time-of-check Time-of-use (TOCTOU) Race Condition in chownr These are the findings of yarn, which ships every tool in this project. kapsl reports and gates; it never edits an image to clear a finding. Composition default + bash, env runtime node composes bash, env, node Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly. Composition default + bash, env runtime node composes bash, env, node Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly. Image image ghcr.io/kapsl-sh/yarn:1.22.22 digest sha256:e547…03ab copy platforms amd64 sha256:1002…5362 copy arm64 sha256:b33a…9e82 copy size 5 MB unpacked · 1 layer base scratch signed cosign · verified last scan 2026-08-26 Sandbox boundary yarn capabilities netrw Filled is granted to every invocation; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted none env passed through none none Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. env set by kapsl none none per-subcommand no overrides Every invocation gets the same boundary. Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere. Sandbox boundary yarnpkg capabilities netrw Filled is granted to every invocation; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted none env passed through none none Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. env set by kapsl none none per-subcommand no overrides Every invocation gets the same boundary. Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere. Provenance sbom amd64 ↗ arm64 ↗ attestation amd64 ↗ arm64 ↗ scan report amd64 ↗ arm64 ↗ grype · 2026-08-26 vex amd64 ↗ arm64 ↗ Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust. 58 findings across this project at latest. Counted once per advisory across every image the project builds.