升级react-scripts时npm upgrade与npm audit fix遭遇漏洞及执行错误问题求助
Let's break down what's happening and walk through actionable fixes for your problem:
What's Going Wrong
When you run npm upgrade or npm upgrade react-scripts, npm shuffles your dependencies but leaves a moderate vulnerability in the nth-check package (part of the react-scripts dependency chain). Trying to force-fix with npm audit fix --force backfires: it tries to downgrade react-scripts to v2.1.3 (a huge step back that introduces more vulnerabilities) and eventually throws an ERR_INVALID_ARG_TYPE error because the forced changes break your dependency structure.
Step-by-Step Fixes
1. Clean Up Corrupted Dependencies First
First, let's reset your dependencies to avoid cached or broken files:
# Delete node_modules and lockfile rm -rf node_modules package-lock.json # For Windows users: # rd /s /q node_modules # del package-lock.json # Clear npm cache npm cache clean --force
2. Fix the nth-check Vulnerability Without Downgrading react-scripts
Instead of letting npm force a downgrade of react-scripts, we'll manually override the vulnerable nth-check version to its safe release. Add this to your package.json:
"overrides": { "nth-check": "^2.0.1" }
This tells npm to use the secure nth-check v2.0.1 (or newer) everywhere in your dependency tree, regardless of what parent packages request.
Then install dependencies again:
npm install
3. Update react-scripts to the Latest Stable Version
If you're using Create React App, the best long-term fix is to get the newest react-scripts (which already includes patched dependencies):
npm install react-scripts@latest
4. Verify the Fix
Run npm audit to confirm the vulnerabilities are resolved:
npm audit
You should no longer see the nth-check moderate vulnerability, and the dependency structure should be stable.
Why Your Previous Attempts Failed
npm audit fix --forceis a blunt tool: it prioritizes fixing vulnerabilities over maintaining a working dependency tree, which is why it tried to downgrade you to a 4-year-old version ofreact-scripts(introducing more issues than it fixed).- The
ERR_INVALID_ARG_TYPEerror was caused by broken dependency paths after the forced downgrade—your project's packages were expecting certain files or parameters that no longer existed.
内容的提问来源于stack exchange,提问作者capoaira

