能否仅禁用单个模块/注册表的Yarn依赖哈希验证?
Absolutely, you don't have to resort to global integrity check skips for this scenario! Yarn provides ways to disable integrity validation only for specific packages or your internal registry, which keeps the rest of your dependencies secure while fixing your CI issue with snapshot modules. The approach varies slightly depending on your Yarn version:
For Yarn Classic (1.x)
You can target individual packages, entire scopes, or registries using Yarn's config system:
Disable for a single internal package:
Run this command in your project root (it adds the setting to your.yarnrcfile):yarn config set "@your-internal/snapshot-package:skipIntegrityCheck" trueReplace
@your-internal/snapshot-packagewith your actual snapshot module name.Disable for an entire internal scope:
If all your snapshot modules share a scope (like@company-internal), use:yarn config set "@company-internal/*:skipIntegrityCheck" trueDisable for your internal registry:
To skip checks for all packages pulled from your internal registry:yarn config set "registry.your-internal-registry-url.com:skipIntegrityCheck" true
For Yarn Berry (2.x and above)
Yarn Berry uses a .yarnrc.yml file for configuration, with more granular control via packageExtensions or registry-specific settings:
Disable for a specific package:
Add this to your project's.yarnrc.yml:packageExtensions: "@your-internal/snapshot-package@*": skipIntegrityCheck: trueThe
@*ensures this applies to all versions of the package—ideal for frequently updated snapshots.Disable for your internal registry:
To skip checks for all packages from your internal registry, add this to.yarnrc.yml:registries: "https://your-internal-registry-url.com": skipIntegrityCheck: true
Key Notes
- Commit the updated
.yarnrc(Classic) or.yarnrc.yml(Berry) to version control—this ensures your CI environment picks up the setting automatically. - This approach keeps integrity checks enabled for all external dependencies, so you don't lose the security benefits of Yarn's validation for third-party packages.
内容的提问来源于stack exchange,提问作者neves

