change yarn telemetry to opt-in - #823
Merged
Merged
Conversation
jmattheis
approved these changes
Aug 8, 2025
jmattheis
left a comment
Member
There was a problem hiding this comment.
Thanks, I didn't knew yarn had this feature.
Signed-off-by: eternal-flame-AD <yume@yumechi.jp>
eternal-flame-AD
force-pushed
the
upgrade-ui-new-pm-telemetry
branch
from
August 8, 2025 11:26
16dc4be to
400cf8b
Compare
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #823 +/- ##
=======================================
Coverage 79.54% 79.54%
=======================================
Files 56 56
Lines 2645 2645
=======================================
Hits 2104 2104
Misses 450 450
Partials 91 91 ☔ View full report in Codecov by Sentry. 🚀 New features to boost your workflow:
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Since we upgraded UI I think we should disable the telemetries newer yarn versions have by default. This sets a default disable for package manager repositories for all builders, users can still opt-in with
--enableTelemetry.The legal reasoning is since we hide
yarnbehindmakeI don't really think telling the user to runmake build-jscounts as providing giving users an opportunity to consent.The technical reasoning is they claim the reason as:
Where? I gave it a quick check and I do not see such debates (at least the problem is not simply "I don't think it is popular enough"). Most are functional, cost, SBOM and security concerns. I don't really believe the appropriate way to be "taken seriously" out of these issues is numerically monetizing your users for your project continuity without an explicit consent.
I also don't see similar telemetry systems being coded into the NPM or PNPM command line. Go also has telemetry but they are opt-in and thus we are not making a choice on behalf of users. Yarn's opt-out approach feels particularly aggressive to me.
Their RFC: yarnpkg/berry#1250