You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Ubuntu环境下React集成Tailwind安装报错求助

React项目安装Tailwind CSS/PostCSS/Autoprefixer时的警告与漏洞修复方案

问题场景

在Ubuntu系统中执行npm i tailwind postcss autoprefixer时,出现以下警告与漏洞提示:

npm i tailwind postcss autoprefixer
npm WARN EBADENGINE Unsupported engine {
npm WARN EBADENGINE   package: 'amqplib@0.5.2',
npm WARN EBADENGINE   required: { node: '>=0.8 <=9' },
npm WARN EBADENGINE   current: { node: 'v18.16.1', npm: '9.8.0' }
npm WARN EBADENGINE }
npm WARN deprecated uuid@3.3.2: Please upgrade  to version 7 or higher.  Older versions may use Math.random() in certain circumstances, which is known to be problematic.  See https://v8.dev/blog/math-random for details.
npm WARN deprecated core-js@2.6.12: core-js@<3.23.3 is no longer maintained and not recommended for usage due to the number of issues. Because of the V8 engine whims, feature detection in old core-js versions could cause a slowdown up to 100x even if nothing is polyfilled. Some versions have web compatibility issues. Please, upgrade your dependencies to the actual version of core-js.

added 153 packages, and audited 395 packages in 14s

88 packages are looking for funding
  run `npm fund` for details

14 vulnerabilities (6 moderate, 7 high, 1 critical)

To address issues that do not require attention, run:
  npm audit fix

To address all issues possible (including breaking changes), run:
  npm audit fix --force

Some issues need review, and may require choosing
a different dependency.


Run `npm audit` for details

警告修复方案

1. EBADENGINE版本不兼容警告

  • 原因:amqplib@0.5.2仅支持Node.js 0.8-9版本,与当前使用的Node.js 18.16.1不匹配
  • 解决:
    • 若amqplib是你直接依赖的包,执行npm install amqplib@latest安装兼容Node.js 18的最新版本
    • 若amqplib是间接依赖,在项目根目录的package.json中添加以下配置强制覆盖版本:
      "overrides": {
        "amqplib": "^0.10.3"
      }
      
    之后重新执行npm install生效

2. 废弃包警告

  • uuid@3.3.2:执行npm install uuid@latest升级到7.x及以上版本
  • core-js@2.6.12:执行npm install core-js@latest升级到3.23.3及以上版本

漏洞修复方案

  1. 先执行非破坏性修复:

    npm audit fix
    

    该命令会修复无需变更依赖版本的漏洞,不会破坏现有项目

  2. 若仍有漏洞未修复,尝试强制修复(可能涉及依赖版本升级,存在破坏性变更风险,建议先备份代码):

    npm audit fix --force
    
  3. 若上述命令无法解决所有问题,运行以下命令查看漏洞详情,手动替换存在风险的依赖包:

    npm audit
    

内容的提问来源于stack exchange,提问作者Abdo Mouak

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.16 21:20:25