小编use*_*455的帖子

Npm依赖项审核错误,除了最新的依赖项版本外,还更新了cloud-s4-sdk-pipeline

我们切换到了cloud-s4-sdk-pipeline的最新版本(21)。新功能可以正常工作,但是除了最新的依赖版本之外,我们还会收到npm依赖审核错误。

调查结果摘要

•  High Arbitrary File Overwrite vulnerability found in dependency "tar", see https://npmjs.com/advisories/803 for details.
•  High Code Injection vulnerability found in dependency "js-yaml", see https://npmjs.com/advisories/813 for details.
•  Moderate Regular Expression Denial of Service vulnerability found in dependency "mime", see https://npmjs.com/advisories/535 for details.
•  Moderate Regular Expression Denial of Service vulnerability found in dependency "underscore.string", see https://npmjs.com/advisories/745 for details.
•  Moderate Prototype Pollution vulnerability found in dependency "lodash", see https://npmjs.com/advisories/782 for details.
•  Moderate …
Run Code Online (Sandbox Code Playgroud)

sap-cloud-sdk

5
推荐指数
1
解决办法
38
查看次数

标签 统计

sap-cloud-sdk ×1