id: yarn-lock info: name: Yarn Lock File Disclosure author: oppsec,noraj severity: info description: | The yarn.lock file stores the versions of each Yarn dependency installed. It's a lock file for package.json. reference: - https://classic.yarnpkg.com/lang/en/docs/yarn-lock/ metadata: max-request: 1 tags: exposure,files,yarn http: - method: GET path: - "{{BaseURL}}/yarn.lock" matchers-condition: and matchers: - type: word part: body words: - "# THIS IS AN AUTOGENERATED FILE. DO NOT EDIT THIS FILE DIRECTLY." - "# yarn lockfile v1" condition: and - type: word part: header words: - "text/html" - type: status status: - 200 # digest: 4a0a0047304502206eace0f19af437ac9c319b5a1bc91d0c99e8e860795e06ca784df22f8e0cf8da022100c7fb1383ab9b22fb4f9573c92543d58e74721a9016fcea9b214189a06eae86b0:922c64590222798bb761d5b6d8e72950