gpt4 book ai didi

javascript - node-sass fstream 和 tar 依赖项漏洞

转载 作者:行者123 更新时间:2023-12-02 23:29:53 25 4
gpt4 key购买 nike

这是我在 package-lock.json 中的 node-gyp 依赖项

"node-gyp": {
"version": "3.8.0",
"resolved": "http://nexus.prod-admin11.vip.aws1/nexus/content/groups/npm-edmunds/node-gyp/-/node-gyp-3.8.0.tgz",
"integrity": "sha512-3g8lYefrRRzvGeSowdJKAKyks8oUpLEd/DyPV4eMhVlhJ0aNaZqIrNUIPuEWWTAoPqyFkfGrM67MC69baqn6vA==",
"dev": true,
"requires": {
"fstream": "^1.0.0",
"glob": "^7.0.3",
"graceful-fs": "^4.1.2",
"mkdirp": "^0.5.0",
"nopt": "2 || 3",
"npmlog": "0 || 1 || 2 || 3 || 4",
"osenv": "0",
"request": "^2.87.0",
"rimraf": "2",
"semver": "~5.3.0",
"tar": "^2.0.0",
"which": "1"
},
"dependencies": {
"semver": {
"version": "5.3.0",
"resolved": "http://nexus.prod-admin11.vip.aws1/nexus/content/groups/npm-edmunds/semver/-/semver-5.3.0.tgz",
"integrity": "sha1-myzl094C0XxgEq0yaqa00M9U+U8=",
"dev": true
}
}
},

当我在此包中运行 yarn 审计时,我遇到了很高的漏洞:

node-sass > node-gyp > tar

node-sass > node-gyp > tar > fstream

node-sass > node-gyp > fstream

最佳答案

这两个漏洞均已在次要版本中修复。如果您想获取最新版本的依赖项,您可能需要删除锁定文件并重新安装。

关于javascript - node-sass fstream 和 tar 依赖项漏洞,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/56561592/

25 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com