如何修复需要 semver-major 依赖项更新的 npm 漏洞?

AHJ*_*Jss 9 npm

我从https://github.com/kitware/paraviewweb克隆了 ParaViewWeb,然后执行了以下操作;-

$ npm install
$ npm audit fix
Run Code Online (Sandbox Code Playgroud)

留给我这个:

found 42 vulnerabilities (9 low, 23 moderate, 10  high) in 41716 scanned packages
14 vulnerabilities require semver-major dependency updates.
28 vulnerabilities require manual review.
Run Code Online (Sandbox Code Playgroud)

如何修复需要 semver-major 依赖项更新的 14 个漏洞?

vau*_*ett 5

当你运行时npm audit,应该有一行告诉你如何更新它,例如:

# Run  npm install --save-dev example@5.0.2  to resolve 1 vulnerability
# SEMVER WARNING: Recommended action is a potentially breaking change
Run Code Online (Sandbox Code Playgroud)

只需执行它来修复它。