Proyek saya memiliki 6 kerentanan tingkat keparahan tinggi dan saya tidak tahu bagaimana cara memperbaikinya. perbaikan audit npm gagal. Tolong bantu saya untuk memperbaiki ini.
Saya menginstal https://www.npmjs.com/package/toastr ke proyek saya dan setelah itu menginstal kerentanan ditampilkan. Saya tidak tahu apakah ada hubungannya. === npm laporan keamanan audit ===
Manual Review
Some vulnerabilities require your attention to resolve
Visit https://go.npm.me/audit-guide for additional guidance
High Machine-In-The-Middle
Package https-proxy-agent
Patched in >=3.0.0
Dependency of @angular/cli [dev]
Path @angular/cli > @schematics/update > pacote >
make-fetch-happen > https-proxy-agent
More info https://npmjs.com/advisories/1184
High Machine-In-The-Middle
Package https-proxy-agent
Patched in >=3.0.0
Dependency of @angular/cli [dev]
Path @angular/cli > pacote > make-fetch-happen >
https-proxy-agent
More info https://npmjs.com/advisories/1184
High Machine-In-The-Middle
Package https-proxy-agent
Patched in >=3.0.0
Dependency of @angular/cli [dev]
Path @angular/cli > @schematics/update > pacote >
npm-registry-fetch > make-fetch-happen > https-proxy-agent
More info https://npmjs.com/advisories/1184
High Machine-In-The-Middle
Package https-proxy-agent
Patched in >=3.0.0
Dependency of @angular/cli [dev]
Path @angular/cli > pacote > npm-registry-fetch >
make-fetch-happen > https-proxy-agent
More info https://npmjs.com/advisories/1184
High Machine-In-The-Middle
Package https-proxy-agent
Patched in >=3.0.0
Dependency of protractor [dev]
Path protractor > browserstack > https-proxy-agent
More info https://npmjs.com/advisories/1184
High Machine-In-The-Middle
Package https-proxy-agent
Patched in >=3.0.0
Dependency of protractor [dev]
Path protractor > saucelabs > https-proxy-agent
More info https://npmjs.com/advisories/1184
Memperbaiki masalah BUILD dan masalah instalasi umum:
package.json
Maka alih-alih
npm install
jalankan saja dicmd
atauDockerfile
:sumber
Lihat utas ini: Bagaimana cara mengganti versi ketergantungan NPM bersarang?
Cukup ganti paket yang sesuai dengan yang tercantum dalam audit.
sumber