angular - Npm 审计报告说 'found 1 low severity vulnerability' karma > expand-braces > braces

标签 angular npm npm-audit

Npm 审计报告显示“发现 1 个低严重性漏洞”。 1 个漏洞需要人工审核。

  Low             Regular Expression Denial of Service
  Package         braces
  Patched in      >=2.3.1
  Dependency of   karma [dev]
  Path            karma > expand-braces > braces
  More info       https://nodesecurity.io/advisories/786

然而,手动升级 braces(braces": "^2.3.2") 并没有解决问题。 有什么建议吗?

以下是我的package.json的内容

{
  "name": "myapp",
  "version": "0.0.0",
  "scripts": {
    "ng": "ng",
    "start": "ng serve",
    "build": "ng build",
    "test": "ng test",
    "lint": "ng lint",
    "e2e": "ng e2e"
  },
  "private": true,
  "dependencies": {
    "@angular/animations": "^7.2.6",
    "@angular/cdk": "^7.3.3",
    "@angular/common": "~7.1.0",
    "@angular/compiler": "~7.1.0",
    "@angular/core": "~7.1.0",
    "@angular/flex-layout": "^7.0.0-beta.23",
    "@angular/forms": "~7.1.0",
    "@angular/material": "^7.3.3",
    "@angular/platform-browser": "~7.1.0",
    "@angular/platform-browser-dynamic": "~7.1.0",
    "@angular/router": "~7.1.0",
    "core-js": "^2.5.4",
    "hammerjs": "^2.0.8",
    "mat-video": "^2.6.0",
    "rxjs": "~6.3.3",
    "tslib": "^1.9.0",
    "zone.js": "~0.8.26"
  },
  "devDependencies": {
    "@angular-devkit/build-angular": "^0.13.3",
    "@angular/cli": "~7.1.4",
    "@angular/compiler-cli": "^7.2.6",
    "@angular/language-service": "~7.1.0",
    "@types/jasmine": "~2.8.8",
    "@types/jasminewd2": "~2.0.3",
    "@types/node": "~8.9.4",
    "codelyzer": "~4.5.0",
    "jasmine-core": "~2.99.1",
    "jasmine-spec-reporter": "~4.2.1",
    "karma": "^4.0.0",
    "karma-chrome-launcher": "~2.2.0",
    "karma-coverage-istanbul-reporter": "^2.0.5",
    "karma-jasmine": "~1.1.2",
    "karma-jasmine-html-reporter": "^0.2.2",
    "protractor": "~5.4.0",
    "ts-node": "~7.0.0",
    "tslint": "~5.11.0",
    "typescript": "~3.1.6"
  }
}

最佳答案

自己更新它并不能解决问题的原因是它没有更新您正在使用的包的依赖项。在这种情况下,它是因果报应,它取决于具有此漏洞的牙套版本。

关于angular - Npm 审计报告说 'found 1 low severity vulnerability' karma > expand-braces > braces,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/54891397/

相关文章:

node.js - Node 包 'node-fetch' 语法错误 : Unexpected identifier

json - Artifactory npm 发布失败 PUT 404

npm - 错误 : Can't resolve 'stream' in . ... papaparse

d3.js - Electron 文件已加载但未显示在“网络”选项卡中

Angular2组件ngDoCheck无限执行

node.js - 在 PowerShell 上运行 npm 会询问 "How do you want to open this file?",命令行没问题

angular - 如何修复 npm 审计漏洞 angular 12.0.3

javascript - 如何订阅改变变量?

mongodb - 使用 ids 数组表单数据库获取所有匹配项目