Skip to content

Conversation

@sam-byng
Copy link
Contributor

@sam-byng sam-byng commented Sep 17, 2025

See ADO task TASK 2576673

NOTE: SHA-1 is not allowed for any purpose, visit Microsoft.Security.Cryptography.10021 for details.

Therefore bumped to latest yarn javascript package manager to avoid sha1 hashing of package binaries.

This adds the yarn berry config / package files: .yarn/ project-local workspace and .yarnrc.yml berry config
Note: Here we bootstrap yarn in devcontainer postCreate. WE also download yarn 4.9.4 locally and refer to it from package.json. Just in case devcontainers not used.

@sam-byng sam-byng requested a review from a team as a code owner September 17, 2025 17:57
devcontainers-bot added 2 commits September 17, 2025 18:06
This removes sha1 hashes from yarn.lock. Compliant with microsoft hashing.

This adds the yarn berry config / package files: .yarn/ project-local workspace and .yarnrc.yml berry config

Here we bootstrap yarnin devcontainer postCreate
@sam-byng
Copy link
Contributor Author

@microsoft-github-policy-service agree company="Microsoft"

@sam-byng sam-byng self-assigned this Sep 17, 2025
@AlvaroRausell
Copy link
Contributor

@sam-byng I approved, but can you create an issue against the features repo, so that we can allow for newer versions of yarn please?

@AlvaroRausell AlvaroRausell merged commit 7e1df86 into main Sep 19, 2025
3 checks passed
@AlvaroRausell AlvaroRausell deleted the sb/test-yarn-berry branch September 19, 2025 11:43
@Kaniska244 Kaniska244 mentioned this pull request Sep 24, 2025
1 task
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants