You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Hosted mode pinned a patched yarn berry package as an npm: locator
(npm:<v>::__archiveUrl=<url>). Yarn fetches npm: locators with its
npm fetcher, which attaches the configured registry token
(npmAuthToken, YARN_NPM_AUTH_TOKEN, npmScopes) to every scoped
package request, and to every request under npmAlwaysAuth, so the
token was sent to the patch server on each cold install.
The lock now pins a plain tarball-URL locator (<name>@<url>). Yarn
fetches it with its tarball fetcher, which sends no registry auth
and builds the same cache zip, so the 10c0 checksum is unchanged and
--immutable still passes. Rollback, VEX and the mode takeovers keep
recognizing the old form, and the next hosted scan re-pins it. An
artifact URL yarn could not fetch as a tarball is refused instead of
written.
Fixes#404
Assisted-by: Claude Code:claude-opus-5-5
0 commit comments