You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

能否仅禁用单个模块/注册表的Yarn依赖哈希验证?

Solution for Disabling Yarn Integrity Checks Only for Specific Internal Snapshot Modules

Absolutely, you don't have to resort to global integrity check skips for this scenario! Yarn provides ways to disable integrity validation only for specific packages or your internal registry, which keeps the rest of your dependencies secure while fixing your CI issue with snapshot modules. The approach varies slightly depending on your Yarn version:

For Yarn Classic (1.x)

You can target individual packages, entire scopes, or registries using Yarn's config system:

  • Disable for a single internal package:
    Run this command in your project root (it adds the setting to your .yarnrc file):

    yarn config set "@your-internal/snapshot-package:skipIntegrityCheck" true
    

    Replace @your-internal/snapshot-package with your actual snapshot module name.

  • Disable for an entire internal scope:
    If all your snapshot modules share a scope (like @company-internal), use:

    yarn config set "@company-internal/*:skipIntegrityCheck" true
    
  • Disable for your internal registry:
    To skip checks for all packages pulled from your internal registry:

    yarn config set "registry.your-internal-registry-url.com:skipIntegrityCheck" true
    

For Yarn Berry (2.x and above)

Yarn Berry uses a .yarnrc.yml file for configuration, with more granular control via packageExtensions or registry-specific settings:

  • Disable for a specific package:
    Add this to your project's .yarnrc.yml:

    packageExtensions:
      "@your-internal/snapshot-package@*":
        skipIntegrityCheck: true
    

    The @* ensures this applies to all versions of the package—ideal for frequently updated snapshots.

  • Disable for your internal registry:
    To skip checks for all packages from your internal registry, add this to .yarnrc.yml:

    registries:
      "https://your-internal-registry-url.com":
        skipIntegrityCheck: true
    

Key Notes

  • Commit the updated .yarnrc (Classic) or .yarnrc.yml (Berry) to version control—this ensures your CI environment picks up the setting automatically.
  • This approach keeps integrity checks enabled for all external dependencies, so you don't lose the security benefits of Yarn's validation for third-party packages.

内容的提问来源于stack exchange,提问作者neves

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 07:53:01