You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

bcrypt传递依赖内存泄漏警告:生产环境风险及依赖覆盖咨询

背景信息

安装bcrypt后,我收到了若干关于废弃包的警告,其中第一条尤为令人担忧:

$ npm install bcrypt
npm WARN deprecated inflight@1.0.6: This module is not supported, and leaks memory. 
  Do not use it. Check out lru-cache if you want a good and tested way to coalesce 
  async requests by a key value, which is much more comprehensive and powerful.
npm WARN deprecated npmlog@5.0.1: This package is no longer supported.
npm WARN deprecated rimraf@3.0.2: Rimraf versions prior to v4 are no longer supported
npm WARN deprecated glob@7.2.3: Glob versions prior to v9 are no longer supported
npm WARN deprecated are-we-there-yet@2.0.0: This package is no longer supported.
npm WARN deprecated gauge@3.0.2: This package is no longer supported.

$ npm ls inflight
└─┬ bcrypt@5.1.1
  └─┬ @mapbox/node-pre-gyp@1.0.11
    └─┬ rimraf@3.0.2
      └─┬ glob@7.2.3
        └── inflight@1.0.6

这条关于潜在内存泄漏的警告让我担心bcrypt在生产环境的长期运行应用中是否安全。

npm建议的修复方案是使用lru-cache替代inflight,这需要通过更新package.json来覆盖rimraf的版本,配置如下:

{
...
  "overrides": {
    "rimraf": "^4.0.0"
  }
...
}

但我对此有所顾虑。另外,bcrypt@5.1.1和@mapbox/node-pre-gyp@1.0.11已是各自的最新版本,无法对其进行升级。

我的问题

  1. 如果直接在生产环境中使用bcrypt,这些废弃依赖会带来显著风险吗?
  2. 如果存在风险,我是否应该按照上述方式覆盖依赖版本?

希望能得到您的指导!

补充背景信息

  • Node.js版本:v20.13.0
  • npm版本:10.5.2
  • 操作系统:Windows 10 Pro(64位)

内容的提问来源于stack exchange,提问作者Himantha Marasinghe

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.23 05:52:36