snyk / nodejs-lockfile-parser

Generate a Snyk dependency tree from package-lock.json or yarn.lock file
Other
59 stars 28 forks source link

Yarn 2 workspaces: private flag is no longer required #139

Closed betalb closed 4 months ago

betalb commented 2 years ago

Current implementation of getYarnWorkspaces function verifies that private flag is set in package.json before analysing workspaces property. This was indeed requried for yarn v1, but no longer required for yarn v2: https://yarnpkg.com/features/workspaces