Add yarn v4 support in Dependency Scanning
We are getting "unsupported yarn.lock file version 8" error in Gemnasium with yarn v4.
We really hope you can add support for the new yarn version.
NOTE if you are a user who also would like to see this feature, please UPVOTE 👍 it and comment to help it get prioritized (So it’s raised as part of our [sensing mechanisms]( https://about.gitlab.com/handbook/product/product-management/process/#sensing-mechanism). Comments ideally should include what you want, how it would help you, what your pain point/frustration is today, and anything else that can help us focus on solving the problem.
If you are a team member commenting on behalf of a user (not ideal, as you can only upvote once!) Please remember to upvote and include as much information (what they are trying to solve for, their setup) as possible in addition to a salesforce or zendesk link.
<!-- The first section "Release notes" is required if you want to have your release post blog MR auto generated. Currently in BETA, details on the **release post item generator** can be found in the handbook: https://about.gitlab.com/handbook/marketing/blog/release-posts/#release-post-item-generator and this video: https://www.youtube.com/watch?v=rfn9ebgTwKg. The next four sections: "Problem to solve", "Intended users", "User experience goal", and "Proposal", are strongly recommended in your first draft, while the rest of the sections can be filled out during the problem validation or breakdown phase. However, keep in mind that providing complete and relevant information early helps our product team validate the problem and start working on a solution. -->
### Release notes
<!-- What is the problem and solution you're proposing? This content sets the overall vision for the feature and serves as the release notes that will populate in various places, including the [release post blog](https://about.gitlab.com/releases/categories/releases/) and [Gitlab project releases](https://gitlab.com/gitlab-org/gitlab/-/releases). " -->
### Problem to solve
Yarn v4 projects are not supported by our SCA features (Dependency Scanning and License Scanning): https://yarnpkg.com/blog/release/4.0
<!-- What problem do we solve? Try to define the who/what/why of the opportunity as a user story. For example, "As a (who), I want (what), so I can (why/value)." -->
### Intended users
<!-- Who will use this feature? If known, include any of the following: types of users (e.g. Developer), personas, or specific company roles (e.g. Release Manager). It's okay to write "Unknown" and fill this field in later.
Personas are described at https://about.gitlab.com/handbook/marketing/product-marketing/roles-personas/
* [Cameron (Compliance Manager)](https://about.gitlab.com/handbook/marketing/product-marketing/roles-personas/#cameron-compliance-manager)
* [Parker (Product Manager)](https://about.gitlab.com/handbook/marketing/product-marketing/roles-personas/#parker-product-manager)
* [Delaney (Development Team Lead)](https://about.gitlab.com/handbook/marketing/product-marketing/roles-personas/#delaney-development-team-lead)
* [Presley (Product Designer)](https://about.gitlab.com/handbook/marketing/product-marketing/roles-personas/#presley-product-designer)
* [Sasha (Software Developer)](https://about.gitlab.com/handbook/marketing/product-marketing/roles-personas/#sasha-software-developer)
* [Devon (DevOps Engineer)](https://about.gitlab.com/handbook/marketing/product-marketing/roles-personas/#devon-devops-engineer)
* [Sidney (Systems Administrator)](https://about.gitlab.com/handbook/marketing/product-marketing/roles-personas/#sidney-systems-administrator)
* [Sam (Security Analyst)](https://about.gitlab.com/handbook/marketing/product-marketing/roles-personas/#sam-security-analyst)
* [Rachel (Release Manager)](https://about.gitlab.com/handbook/marketing/product-marketing/roles-personas/#rachel-release-manager)
* [Alex (Security Operations Engineer)](https://about.gitlab.com/handbook/marketing/product-marketing/roles-personas/#alex-security-operations-engineer)
* [Simone (Software Engineer in Test)](https://about.gitlab.com/handbook/marketing/product-marketing/roles-personas/#simone-software-engineer-in-test)
* [Allison (Application Ops)](https://about.gitlab.com/handbook/marketing/product-marketing/roles-personas/#allison-application-ops)
* [Priyanka (Platform Engineer)](https://about.gitlab.com/handbook/marketing/product-marketing/roles-personas/#priyanka-platform-engineer)
* [Dana (Data Analyst)](https://about.gitlab.com/handbook/marketing/product-marketing/roles-personas/#dana-data-analyst)
-->
### User experience goal
<!-- What is the single user experience workflow this problem addresses?
For example, "The user should be able to use the UI/API/.gitlab-ci.yml with GitLab to <perform a specific task>"
https://about.gitlab.com/handbook/engineering/ux/ux-research-training/user-story-mapping/ -->
### Proposal
<!-- How are we going to solve the problem? Try to include the user journey! https://about.gitlab.com/handbook/journeys/#user-journey -->
Make the existing Gemnasium Yarn parser capable of parsing lock files for yarn v4.
### Implementation Plan
1. Update the [`yarnV3LockfileVersion` variable](https://gitlab.com/gitlab-org/security-products/analyzers/gemnasium/-/blob/9840b56b81d261dd09175e4230209266d3ef5956/scanner/parser/yarn/berry/berry.go#L17) to `yarnV4LockfileVersion = 8`.
### Further details
The lockfile version for Yarn has been updated twice since we last added support for v6 versions. Here are the git blames from v5 to v8.
* [v5](https://github.com/yarnpkg/berry/blame/e64af835177f64fc4820f1bb582e0f918b73ebfc/packages/yarnpkg-core/sources/Project.ts#L45)
* Added a new [conditions](https://github.com/yarnpkg/berry/pull/3575/files#diff-c821f4d18a5e2edb5e03c14629e22bed75589331b20aaed25b77ec0ed45def1e) field to the `Package` type. Not used by the Yarn Berry parser.
* [v6](https://github.com/yarnpkg/berry/blame/e4a5b234766ecfd21c2e6a9c29289defc93144c2/packages/yarnpkg-core/sources/Project.ts)
* Added a [`libc`](https://github.com/yarnpkg/berry/pull/3981/files#diff-b01a87c06fe4fcff175c46ad8ff70fb33b849c6e650e380146ff170b24b8c722R711) field to the `Package` type indirectly.
* [v7](https://github.com/yarnpkg/berry/blame/4e6f9836f035405096da295f4b2606008af11a64/packages/yarnpkg-core/sources/Project.ts)
* Always require the [`npm:` protocol](https://github.com/yarnpkg/berry/pull/4305) to ensure data is normalized with a protocol prefix.
* [v8](https://github.com/yarnpkg/berry/blame/9b640e68b0410c33e1fee658569545fe64b116f5/packages/yarnpkg-core/sources/Project.ts#L47)
* Set the [default compression level to `0`](https://github.com/yarnpkg/berry/pull/5526)
We don't use the `libc`field, `conditions` field, or the compression level so this does not affect us. In addition, we only check for the [`workspace` and `patch` prefixes](https://gitlab.com/gitlab-org/security-products/analyzers/gemnasium/-/blob/9840b56b81d261dd09175e4230209266d3ef5956/scanner/parser/yarn/berry/berry.go#L46-52), so the `npm:` prefix normalization does not impact us either.
### Permissions and Security
<!-- What permissions are required to perform the described actions? Are they consistent with the existing permissions as documented for users, groups, and projects as appropriate? Is the proposed behavior consistent between the UI, API, and other access methods (e.g. email replies)?
Consider adding checkboxes and expectations of users with certain levels of membership https://docs.gitlab.com/ee/user/permissions.html
* [ ] Add expected impact to members with no access (0)
* [ ] Add expected impact to Guest (10) members
* [ ] Add expected impact to Reporter (20) members
* [ ] Add expected impact to Developer (30) members
* [ ] Add expected impact to Maintainer (40) members
* [ ] Add expected impact to Owner (50) members -->
No change
### Documentation
<!-- See the Feature Change Documentation Workflow https://docs.gitlab.com/ee/development/documentation/workflow.html#for-a-product-change
* Add all known Documentation Requirements in this section. See https://docs.gitlab.com/ee/development/documentation/feature-change-workflow.html#documentation-requirements
* If this feature requires changing permissions, update the permissions document. See https://docs.gitlab.com/ee/user/permissions.html -->
We need to update the relevant section in the [documentation](https://docs.gitlab.com/ee/user/application_security/dependency_scanning/index.html#obtaining-dependency-information-by-parsing-lockfiles), saying that we do support Yarn v4.
### Availability & Testing
<!-- This section needs to be retained and filled in during the workflow planning breakdown phase of this feature proposal, if not earlier.
What risks does this change pose to our availability? How might it affect the quality of the product? What additional test coverage or changes to tests will be needed? Will it require cross-browser testing?
Please list the test areas (unit, integration and end-to-end) that needs to be added or updated to ensure that this feature will work as intended. Please use the list below as guidance.
* Unit test changes
* Integration test changes
* End-to-end test change
See the test engineering planning process and reach out to your counterpart Software Engineer in Test for assistance: https://about.gitlab.com/handbook/engineering/quality/test-engineering/#test-planning -->
The following items need to be processed:
- Unit tests for both Yarn v2 and v3 lock files.
- Integration tests using rspec for Yarn v2. If time permits we can also add tests for Yarn v3. Otherwise we can do it as part of [351841](https://gitlab.com/gitlab-org/gitlab/-/issues/351841)
- Test projects should be created for Yarn v2 and v3. These projects need to follow the [test-common](https://gitlab.com/gitlab-org/security-products/tests/common#how-to-create-a-new-test-project) guidelines.
### What does success look like, and how can we measure that?
<!--
Define both the success metrics and acceptance criteria. Note that success metrics indicate the desired business outcomes, while acceptance criteria indicate when the solution is working correctly. If there is no way to measure success, link to an issue that will implement a way to measure this.
Create tracking issue using the the Snowplow event tracking template. See https://gitlab.com/gitlab-org/gitlab/-/blob/master/.gitlab/issue_templates/Snowplow%20event%20tracking.md
-->
#### Demo
### What is the type of buyer?
<!-- What is the buyer persona for this feature? See https://about.gitlab.com/handbook/marketing/product-marketing/roles-personas/buyer-persona/
In which enterprise tier should this feature go? See https://about.gitlab.com/handbook/product/pricing/#four-tiers -->
### Is this a cross-stage feature?
<!-- Communicate if this change will affect multiple Stage Groups or product areas. We recommend always start with the assumption that a feature request will have an impact into another Group. Loop in the most relevant PM and Product Designer from that Group to provide strategic support to help align the Group's broader plan and vision, as well as to avoid UX and technical debt. https://about.gitlab.com/handbook/product/#cross-stage-features -->
### Links / references
* [Yarn v4.0.0 release](https://yarnpkg.com/blog/release/4.0)
* [Yarn v4.0.2 lockfile version](https://github.com/yarnpkg/berry/blob/a64075561a6476aa79d0fa1012ecf6b1633a88f2/packages/yarnpkg-core/sources/Project.ts#L47)
<!-- Label reminders - you should have one of each of the following labels if you can figure out the correct ones -->
<!-- triage-serverless v3 PLEASE DO NOT REMOVE THIS SECTION -->
*This page may contain information related to upcoming products, features and functionality.
It is important to note that the information presented is for informational purposes only, so please do not rely on the information for purchasing or planning purposes.
Just like with all projects, the items mentioned on the page are subject to change or delay, and the development, release, and timing of any products, features, or functionality remain at the sole discretion of GitLab Inc.*
<!-- triage-serverless v3 PLEASE DO NOT REMOVE THIS SECTION -->
issue