I haven't dug in yet, but we should definitely start researching exactly how to leverage `yarn.lock` for dependency validation.