vuejs / vue-cli

🛠️ webpack-based tooling for Vue.js Development
https://cli.vuejs.org/
MIT License
29.75k stars 6.32k forks source link

@vue/cli-shared-utils@3.12.1 relies on the node-ipc version #7406

Open fencer-yd opened 1 year ago

fencer-yd commented 1 year ago

What problem does this feature solve?

the version dependency of node-ipc needs to be fixed to 9.2.1

What does the proposed API look like?

Because node-ipc^9.1.4 downloads the 9.2.2 version with the virus in a different npm mirror source, node-ipc will load the peacenotwar third-party library, and peacenotwar will generate a "WITH- love-fro-America.txt" on the user's desktop without the user's permission, which will bring great panic to the user.