PkgRadar

Cargo · crates.io

yarn

Credential File Packaged: yarn-0.4.0/.env

Why PkgRadar flagged 0.4.0

SeveritySignalEvidence
highCredential File Packagedyarn-0.4.0/.env · yarn-0.4.0/.env

Scanned versions

VersionVerdictScoreScanned (UTC)
0.4.0High risk352026-06-15

Block this in CI

PkgRadar gates yarn (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]