yarn audit检测到@storybook/react依赖链中immer存在原型污染漏洞的技术问询
Hey there! Let's sort out that Immer prototype pollution vulnerability popping up in your React project's Storybook dependencies. Here are actionable ways to resolve it:
1. Force an updated Immer version with Yarn Resolutions
Since the vulnerability is fixed in Immer v9.0.6+, you can directly force all nested dependencies to use this version using Yarn's resolutions feature:
- Add a
resolutionsfield to yourpackage.jsonfile:
{ "dependencies": { "@storybook/addon-actions": "6.3.12", "@storybook/addon-knobs": "6.3.1", "@storybook/addon-links": "6.3.1", "@storybook/addons": "6.3.1", "@storybook/react": "6.3.12" }, "resolutions": { "immer": "^9.0.6" } }
- Reinstall your dependencies to apply the change:
yarn install
- Verify the fix by checking the installed Immer version:
yarn list immer
This should show all instances of Immer in your dependency tree using v9.0.6 or higher.
2. Upgrade Storybook to a Newer Version
Your current Storybook version (6.3.x) relies on an older react-dev-utils that pulls in the vulnerable Immer version. Upgrading Storybook to a more recent release may resolve this automatically, as newer versions often update their nested dependencies:
- Upgrade all your Storybook packages to the latest stable version (note: v7.x has breaking changes, so if you want to avoid major overhauls, target 6.5.x):
yarn upgrade @storybook/react@6.5.x @storybook/addon-actions@6.5.x @storybook/addon-knobs@6.5.x @storybook/addon-links@6.5.x @storybook/addons@6.5.x
- Important: If you upgrade to Storybook v7.x,
@storybook/addon-knobsis deprecated. You'll need to replace it with@storybook/addon-controls:
yarn remove @storybook/addon-knobs yarn add @storybook/addon-controls --dev
Then update your Storybook config files to replace any knobs references with controls.
3. Confirm the Vulnerability is Resolved
After applying either fix, run the audit command again to make sure the issue is gone:
yarn audit
If you still see the vulnerability, use yarn why immer to trace remaining paths where an older Immer version is being pulled in, and adjust your resolutions or upgrades accordingly.
内容的提问来源于stack exchange,提问作者Petros Kalafatidis

