Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

why can't I fix the vulnerabilities? #7

Open
Woblur opened this issue Jul 6, 2023 · 0 comments
Open

why can't I fix the vulnerabilities? #7

Woblur opened this issue Jul 6, 2023 · 0 comments

Comments

@Woblur
Copy link

Woblur commented Jul 6, 2023

33 vulnerabilities (27 moderate, 6 high)
I attempted to npm audit fix --force

Will install react-scripts@4.0.3, which is a breaking change
node_modules/eslint-plugin-import/node_modules/semver
node_modules/eslint-plugin-jsx-a11y/node_modules/semver
node_modules/eslint-plugin-react/node_modules/semver
node_modules/istanbul-lib-instrument/node_modules/semver
node_modules/make-dir/node_modules/semver
eslint-plugin-import >=2.27.4
Depends on vulnerable versions of semver
node_modules/eslint-plugin-import
eslint-plugin-jsx-a11y >=6.6.0
Depends on vulnerable versions of semver
node_modules/eslint-plugin-jsx-a11y
eslint-plugin-react 7.19.0 || >=7.26.0
Depends on vulnerable versions of semver
node_modules/eslint-plugin-react
eslint-config-react-app >=7.0.0-next.75
Depends on vulnerable versions of eslint-plugin-react
node_modules/eslint-config-react-app
istanbul-lib-instrument >=1.2.0
Depends on vulnerable versions of semver
node_modules/istanbul-lib-instrument
@jest/reporters *
Depends on vulnerable versions of @jest/transform
Depends on vulnerable versions of istanbul-lib-instrument
Depends on vulnerable versions of istanbul-lib-report
Depends on vulnerable versions of istanbul-reports
node_modules/@jest/reporters
@jest/core *
Depends on vulnerable versions of @jest/reporters
Depends on vulnerable versions of @jest/transform
Depends on vulnerable versions of jest-config
Depends on vulnerable versions of jest-resolve-dependencies
Depends on vulnerable versions of jest-runner
Depends on vulnerable versions of jest-runtime
Depends on vulnerable versions of jest-snapshot
node_modules/@jest/core
jest >=24.2.0-alpha.0
Depends on vulnerable versions of @jest/core
Depends on vulnerable versions of jest-cli
node_modules/jest
jest-watch-typeahead >=0.6.0
Depends on vulnerable versions of jest
node_modules/jest-watch-typeahead
jest-cli >=23.0.0-alpha.0
Depends on vulnerable versions of @jest/core
Depends on vulnerable versions of jest-config
node_modules/jest-cli
babel-plugin-istanbul >=3.1.0-candidate.0
Depends on vulnerable versions of istanbul-lib-instrument
node_modules/babel-plugin-istanbul
@jest/transform *
Depends on vulnerable versions of babel-plugin-istanbul
node_modules/@jest/transform
babel-jest >=18.5.0-alpha.7da3df39
Depends on vulnerable versions of @jest/transform
Depends on vulnerable versions of babel-plugin-istanbul
node_modules/babel-jest
jest-config >=23.0.0-alpha.0
Depends on vulnerable versions of @jest/test-sequencer
Depends on vulnerable versions of babel-jest
Depends on vulnerable versions of jest-circus
Depends on vulnerable versions of jest-jasmine2
Depends on vulnerable versions of jest-runner
node_modules/jest-config
jest-runner >=24.2.0-alpha.0
Depends on vulnerable versions of @jest/transform
Depends on vulnerable versions of jest-runtime
node_modules/jest-runner
jest-runtime >=24.2.0-alpha.0
Depends on vulnerable versions of @jest/transform
Depends on vulnerable versions of jest-snapshot
node_modules/jest-runtime
@jest/test-sequencer <=28.0.0-alpha.11
Depends on vulnerable versions of jest-runtime
node_modules/@jest/test-sequencer
jest-circus >=25.2.4
Depends on vulnerable versions of jest-runtime
Depends on vulnerable versions of jest-snapshot
node_modules/jest-circus
jest-jasmine2 >=24.2.0-alpha.0
Depends on vulnerable versions of jest-runtime
Depends on vulnerable versions of jest-snapshot
node_modules/jest-jasmine2
jest-snapshot >=27.0.0-next.0
Depends on vulnerable versions of @jest/transform
node_modules/jest-snapshot
jest-resolve-dependencies >=27.0.0-next.0
Depends on vulnerable versions of jest-snapshot
node_modules/jest-resolve-dependencies
make-dir 2.0.0 - 3.1.0
Depends on vulnerable versions of semver
node_modules/make-dir
babel-loader >=8.1.0
Depends on vulnerable versions of find-cache-dir
Depends on vulnerable versions of make-dir
node_modules/babel-loader
find-cache-dir 2.1.0 - 3.3.2
Depends on vulnerable versions of make-dir
node_modules/find-cache-dir
istanbul-lib-report >=2.0.5
Depends on vulnerable versions of make-dir
node_modules/istanbul-lib-report
istanbul-reports >=3.0.0-alpha.0
Depends on vulnerable versions of istanbul-lib-report
node_modules/istanbul-reports

33 vulnerabilities (27 moderate, 6 high)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant