Open ghost opened 2 years ago
@abbykimi 谢谢提醒,已经更新了一波依赖版本,谢谢你治好了我的懒癌 😂
还剩了一个暂时处理不了,等待后续 react-scripts 更新后会处理。
➜ react-hello git:(master) npm audit
# npm audit report
nth-check <2.0.1
Severity: moderate
Inefficient Regular Expression Complexity in nth-check - https://github.com/advisories/GHSA-rp65-9cf3-cjxr
fix available via `npm audit fix --force`
Will install react-scripts@2.1.3, which is a breaking change
node_modules/svgo/node_modules/nth-check
css-select <=3.1.0
Depends on vulnerable versions of nth-check
node_modules/svgo/node_modules/css-select
svgo 1.0.0 - 1.3.2
Depends on vulnerable versions of css-select
node_modules/svgo
@svgr/plugin-svgo <=5.5.0
Depends on vulnerable versions of svgo
node_modules/@svgr/plugin-svgo
@svgr/webpack 4.0.0 - 5.5.0
Depends on vulnerable versions of @svgr/plugin-svgo
node_modules/@svgr/webpack
react-scripts >=2.1.4
Depends on vulnerable versions of @svgr/webpack
node_modules/react-scripts
@craco/craco >=6.0.0
Depends on vulnerable versions of react-scripts
node_modules/@craco/craco
craco-less >=1.7.0
Depends on vulnerable versions of @craco/craco
Depends on vulnerable versions of react-scripts
node_modules/craco-less
大佬,你好,我是@abbykimi,我IDE运行您这个项目的时候,提示有几个漏洞,项目调用了tar等1214个开源组件,存在15个安全漏洞,建议你升级下。
另外14个漏洞,如需查看详细报告、复测或持续监测您的项目,戳这里https://www.mfsec.cn/jr?p=m6e352
如果你对这个issues有任何疑问可以回复我哈( @abbykimi ),我会及时回复你的。