bcrypt传递依赖内存泄漏警告:生产环境风险及依赖覆盖咨询
背景信息
安装bcrypt后,我收到了若干关于废弃包的警告,其中第一条尤为令人担忧:
$ npm install bcrypt npm WARN deprecated inflight@1.0.6: This module is not supported, and leaks memory. Do not use it. Check out lru-cache if you want a good and tested way to coalesce async requests by a key value, which is much more comprehensive and powerful. npm WARN deprecated npmlog@5.0.1: This package is no longer supported. npm WARN deprecated rimraf@3.0.2: Rimraf versions prior to v4 are no longer supported npm WARN deprecated glob@7.2.3: Glob versions prior to v9 are no longer supported npm WARN deprecated are-we-there-yet@2.0.0: This package is no longer supported. npm WARN deprecated gauge@3.0.2: This package is no longer supported. $ npm ls inflight └─┬ bcrypt@5.1.1 └─┬ @mapbox/node-pre-gyp@1.0.11 └─┬ rimraf@3.0.2 └─┬ glob@7.2.3 └── inflight@1.0.6
这条关于潜在内存泄漏的警告让我担心bcrypt在生产环境的长期运行应用中是否安全。
npm建议的修复方案是使用lru-cache替代inflight,这需要通过更新package.json来覆盖rimraf的版本,配置如下:
{ ... "overrides": { "rimraf": "^4.0.0" } ... }
但我对此有所顾虑。另外,bcrypt@5.1.1和@mapbox/node-pre-gyp@1.0.11已是各自的最新版本,无法对其进行升级。
我的问题
- 如果直接在生产环境中使用
bcrypt,这些废弃依赖会带来显著风险吗? - 如果存在风险,我是否应该按照上述方式覆盖依赖版本?
希望能得到您的指导!
补充背景信息
- Node.js版本:v20.13.0
- npm版本:10.5.2
- 操作系统:Windows 10 Pro(64位)
内容的提问来源于stack exchange,提问作者Himantha Marasinghe
相关产品推荐
相关产品推荐

