You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

yarn audit检测到@storybook/react依赖链中immer存在原型污染漏洞的技术问询

Fixing Immer Prototype Pollution Vulnerability in Storybook Dependencies

Hey there! Let's sort out that Immer prototype pollution vulnerability popping up in your React project's Storybook dependencies. Here are actionable ways to resolve it:

1. Force an updated Immer version with Yarn Resolutions

Since the vulnerability is fixed in Immer v9.0.6+, you can directly force all nested dependencies to use this version using Yarn's resolutions feature:

  • Add a resolutions field to your package.json file:
{
  "dependencies": {
    "@storybook/addon-actions": "6.3.12",
    "@storybook/addon-knobs": "6.3.1",
    "@storybook/addon-links": "6.3.1",
    "@storybook/addons": "6.3.1",
    "@storybook/react": "6.3.12"
  },
  "resolutions": {
    "immer": "^9.0.6"
  }
}
  • Reinstall your dependencies to apply the change:
yarn install
  • Verify the fix by checking the installed Immer version:
yarn list immer

This should show all instances of Immer in your dependency tree using v9.0.6 or higher.

2. Upgrade Storybook to a Newer Version

Your current Storybook version (6.3.x) relies on an older react-dev-utils that pulls in the vulnerable Immer version. Upgrading Storybook to a more recent release may resolve this automatically, as newer versions often update their nested dependencies:

  • Upgrade all your Storybook packages to the latest stable version (note: v7.x has breaking changes, so if you want to avoid major overhauls, target 6.5.x):
yarn upgrade @storybook/react@6.5.x @storybook/addon-actions@6.5.x @storybook/addon-knobs@6.5.x @storybook/addon-links@6.5.x @storybook/addons@6.5.x
  • Important: If you upgrade to Storybook v7.x, @storybook/addon-knobs is deprecated. You'll need to replace it with @storybook/addon-controls:
yarn remove @storybook/addon-knobs
yarn add @storybook/addon-controls --dev

Then update your Storybook config files to replace any knobs references with controls.

3. Confirm the Vulnerability is Resolved

After applying either fix, run the audit command again to make sure the issue is gone:

yarn audit

If you still see the vulnerability, use yarn why immer to trace remaining paths where an older Immer version is being pulled in, and adjust your resolutions or upgrades accordingly.

内容的提问来源于stack exchange,提问作者Petros Kalafatidis

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.30 20:04:06