gpt4 book ai didi

reactjs - 我的 React 应用程序有无法修复的高严重性警告,我该如何解决?

转载 作者:行者123 更新时间:2023-12-03 18:54:13 24 4
gpt4 key购买 nike

  • 我为 React 应用程序克隆了我的 repo。
  • npm i
  • 收到 3 个高严重性警告。
  • 在尝试修复 (npm audit fix --force) 时,我总共得到 31 个漏洞

  • 以下是警告:
    npm WARN deprecated request-promise-native@1.0.9: request-promise-native has been deprecated because it extends the now deprecated request package, see https://github.com/request/request/issues/3142
    npm WARN deprecated @hapi/topo@3.1.6: This version has been deprecated and is no longer supported or maintained
    npm WARN deprecated @hapi/bourne@1.3.2: This version has been deprecated and is no longer supported or maintained
    npm WARN deprecated urix@0.1.0: Please see https://github.com/lydell/urix#deprecated
    npm WARN deprecated har-validator@5.1.5: this library is no longer supported
    npm WARN deprecated resolve-url@0.2.1: https://github.com/lydell/resolve-url#deprecated
    npm WARN deprecated fsevents@1.2.13: fsevents 1 will break on node v14+ and could be using insecure binaries. Upgrade to fsevents 2.
    npm WARN deprecated chokidar@2.1.8: Chokidar 2 will break on node v14+. Upgrade to chokidar 3 with 15x less dependencies.
    npm WARN deprecated fsevents@1.2.13: fsevents 1 will break on node v14+ and could be using insecure binaries. Upgrade to fsevents 2.
    npm WARN deprecated chokidar@2.1.8: Chokidar 2 will break on node v14+. Upgrade to chokidar 3 with 15x less dependencies.
    npm WARN deprecated babel-eslint@10.1.0: babel-eslint is now @babel/eslint-parser. This package will no longer receive updates.
    npm WARN deprecated @hapi/address@2.1.4: Moved to 'npm install @sideway/address'
    npm WARN deprecated rollup-plugin-babel@4.4.0: This package has been deprecated and is no longer maintained. Please use @rollup/plugin-babel.
    npm WARN deprecated request@2.88.2: request has been deprecated, see https://github.com/request/request/issues/3142
    npm WARN deprecated @hapi/hoek@8.5.1: This version has been deprecated and is no longer supported or maintained
    npm WARN deprecated @hapi/joi@15.1.1: Switch to 'npm install joi'
    npm WARN deprecated core-js@2.6.12: core-js@<3 is no longer maintained and not recommended for usage due to the number of issues. Please, upgrade your dependencies to the actual version of core-js@3.

    added 1988 packages, and audited 1988 packages in 8s

    126 packages are looking for funding
    run `npm fund` for details

    3 high severity vulnerabilities

    To address all issues (including breaking changes), run:
    npm audit fix --force

    Run `npm audit` for details.
    审计结果是这样的:
    # npm audit report

    immer <8.0.1
    Severity: high
    Prototype Pollution - https://npmjs.com/advisories/1603
    fix available via `npm audit fix --force`
    Will install react-scripts@2.0.5, which is a breaking change
    node_modules/immer
    react-dev-utils >=6.0.6-next.9b4009d7
    Depends on vulnerable versions of immer
    node_modules/react-dev-utils
    react-scripts >=2.0.6-next.9b4009d7
    Depends on vulnerable versions of react-dev-utils
    node_modules/react-scripts

    3 high severity vulnerabilities

    To address all issues (including breaking changes), run:
    npm audit fix --force

    最佳答案

    我昨天和今天早上在这个问题上争论了几个小时,发现这个线程似乎是原因:
    https://github.com/facebook/create-react-app/issues/10411
    除了这个提议的修复:
    https://github.com/facebook/create-react-app/pull/10412
    看起来这是 immer、react-scripts 和 react-dev-tools 的依赖问题。他们说他们会在本周末尝试推出更新,所以我会期待迟早的更新。

    关于reactjs - 我的 React 应用程序有无法修复的高严重性警告,我该如何解决?,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/66285849/

    24 4 0
    Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
    广告合作:1813099741@qq.com 6ren.com