You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Next.js/Node.js项目易受攻击子依赖修复问题求助

解决d3-color高风险漏洞与ES模块兼容问题

npm audit 报告

# npm audit report
d3-color  <3.1.0
Severity: high
d3-color vulnerable to ReDoS - https://github.com/advisories/GHSA-36jr-mh4h-2g58
fix available via `npm audit fix --force`
Will install react-simple-maps@1.0.0, which is a breaking change
node_modules/d3-transition/node_modules/d3-color
node_modules/react-simple-maps/node_modules/d3-color
  d3-interpolate  0.1.3 - 2.0.1
  Depends on vulnerable versions of d3-color
  node_modules/d3-transition/node_modules/d3-interpolate
  node_modules/react-simple-maps/node_modules/d3-interpolate
    d3-transition  0.0.7 - 2.0.0
    Depends on vulnerable versions of d3-color
    Depends on vulnerable versions of d3-interpolate
    node_modules/d3-transition
    d3-zoom  0.0.2 - 2.0.0
    Depends on vulnerable versions of d3-interpolate
    Depends on vulnerable versions of d3-transition
    node_modules/react-simple-maps/node_modules/d3-zoom
      react-simple-maps  2.0.0 - 3.0.0
      Depends on vulnerable versions of d3-zoom
      node_modules/react-simple-maps

遇到的问题

尝试用overrides、直接安装子依赖等方法修复漏洞后,运行应用时出现ES模块错误:

Uncaught Error: require() of ES Module

解决方案

  • 用npm overrides指定兼容的修复版本
    选择既修复ReDoS漏洞、又同时支持CommonJS和ES模块的版本,避免纯ES模块导致的require()错误。在package.json中添加以下配置:

    "overrides": {
      "react-simple-maps": {
        "d3-zoom": "2.0.1",
        "d3-color": "3.1.0",
        "d3-interpolate": "2.0.2",
        "d3-transition": "2.0.1"
      },
      "d3-transition": {
        "d3-color": "3.1.0",
        "d3-interpolate": "2.0.2"
      }
    }
    

    执行npm install完成依赖更新,这些版本既修复了漏洞,又能兼容项目的模块加载方式。

  • 调整项目模块系统配置
    如果使用Webpack,在配置文件中设置resolve.mainFields: ['main', 'module'],优先加载依赖的CommonJS入口;如果是Vite项目,在vite.config.js中添加optimizeDeps.include包含相关d3包,或根据需要设置ssr.noExternal处理模块兼容。

  • 降级到react-simple-maps的兼容小版本
    查看react-simple-maps的更新日志,找到2.x分支中已更新依赖到安全版本的小版本(如2.3.0),直接安装该版本:

    npm install react-simple-maps@2.3.0
    

    该版本已内置安全的d3依赖,无需手动覆盖子依赖。

  • Yarn用户使用resolutions替代
    若项目用Yarn,在package.json中添加:

    "resolutions": {
      "d3-color": "3.1.0",
      "d3-interpolate": "2.0.2",
      "d3-transition": "2.0.1",
      "d3-zoom": "2.0.1"
    }
    

    执行yarn install完成依赖修复。

内容的提问来源于stack exchange,提问作者Tanuj0610

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.16 02:05:13