Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypted authentication data to be sent over the network.
https://github.com/advisories/GHSA-wqfc-cr59-h64p
https://yarnpkg.com/blog/2019/07/12/recommended-security-update/