Github Actions中Yarn依赖解析失败:json5版本冲突求安全方案
Github Actions中Yarn 4.3.1执行yarn install失败(json5版本冲突)
本地环境执行yarn install可正常完成,但在Github Actions中执行该命令时失败。已配置与项目一致的Node.js 20和Yarn 4.3.1版本,具体CI工作流配置如下:
- name: Checkout code uses: actions/checkout@v2 - name: Set up Node.js uses: actions/setup-node@v2 with: node-version: "20" cache: 'yarn' - name: Enable Corepack run: corepack enable - name: Set Yarn version run: corepack prepare yarn@4.3.1 --activate - name: Install dependencies run: yarn install
执行过程中出现如下错误:
Run yarn install ➤ YN0000: Yarn detected that the current workflow is executed from a public pull request. For safety the hardened mode has been enabled. ➤ YN0000: It will prevent malicious lockfile manipulations, in exchange for a slower install time. You can opt-out if necessary; check our documentation for more details. ➤ YN0000: · Yarn 4.3.1 ➤ YN0000: ┌ Resolution step Resolution step ➤ YN0078: Invalid resolution json5@npm:^2.2.2 → npm:1.0.2 ➤ YN0000: └ Completed in 11s 745ms ➤ YN0000: · Failed with errors in 11s 757ms Error: Process completed with exit code 1.
我尝试过以下方法,但均无法解决问题:
- 在package.json的resolutions字段中指定json5为2.2.2版本
- 使用
yarn install --immutable命令 - 设置环境变量
YARN_ENABLE_IMMUTABLE_INSTALLS: false - 直接执行
yarn add json5@2.2.2安装指定版本
目前通过设置环境变量YARN_ENABLE_HARDENED_MODE: 0临时解决,但该方案存在安全隐患,希望找到安全的解决办法。
内容的提问来源于stack exchange,提问作者nayounsang
相关产品推荐
相关产品推荐

