Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

npm audit 检查出的高危漏洞 #146

Open
adseng opened this issue Dec 28, 2022 · 0 comments
Open

npm audit 检查出的高危漏洞 #146

adseng opened this issue Dec 28, 2022 · 0 comments

Comments

@adseng
Copy link

adseng commented Dec 28, 2022

版本 2.5.13
当我用npm audit,检查出大量高危漏洞
下面是部分检查报告内容

  High            Inefficient Regular Expression Complexity in                  
                  chalk/ansi-regex                                              

  Package         ansi-regex                                                    

  Dependency of   @umijs/fabric [dev]                                           

  Path            @umijs/fabric > stylelint-config-rational-order > stylelint   
                  > table > string-width > strip-ansi > ansi-regex              

  More info       https://github.com/advisories/GHSA-93q8-gq69-wqmw             



# Run  npm update minimatch --depth 8  to resolve 6 vulnerabilities

  High            minimatch ReDoS vulnerability                                 

  Package         minimatch                                                     

  Dependency of   @umijs/fabric [dev]                                           

  Path            @umijs/fabric > eslint > minimatch                            

  More info       https://github.com/advisories/GHSA-f8q6-p94x-37v3             

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant