升级class-validator至0.14.0遭遇@nestjs/mapped-types依赖冲突
解决class-validator@0.14.0与@nestjs/mapped-types@1.2.0的依赖冲突问题
问题背景
class-validator@0.13.2存在高危漏洞,升级至0.14.0后执行npm install触发ERESOLVE依赖解析错误,核心冲突为@nestjs/mapped-types@1.2.0的peer依赖仅支持class-validator@^0.11.1 || ^0.12.0 || ^0.13.0,更新其他依赖无法解决该冲突,回退版本则会保留高危漏洞。
错误详情
PS C:\Users\rabur\OneDrive\Desktop\life-back\application> npm install npm ERR! code ERESOLVE npm ERR! ERESOLVE could not resolve npm ERR! npm ERR! While resolving: @nestjs/mapped-types@1.2.0 npm ERR! Found: class-validator@0.14.0 npm ERR! node_modules/class-validator npm ERR! class-validator@"^0.14.0" from the root project npm ERR! peerOptional class-validator@"*" from @nestjs/common@9.2.1 npm ERR! node_modules/@nestjs/common npm ERR! @nestjs/common@"^9.0.0" from the root project npm ERR! peer @nestjs/common@"^7.0.0 || ^8.0.0 || ^9.0.0" from @nestjs/config@2.2.0 npm ERR! node_modules/@nestjs/config npm ERR! @nestjs/config@"^2.2.0" from the root project npm ERR! 7 more (@nestjs/core, @nestjs/jwt, @nestjs/mapped-types, ...) npm ERR! npm ERR! Could not resolve dependency: npm ERR! peerOptional class-validator@"^0.11.1 || ^0.12.0 || ^0.13.0" from @nestjs/mapped-types@1.2.0 npm ERR! node_modules/@nestjs/mapped-types npm ERR! @nestjs/mapped-types@"^1.2.0" from the root project npm ERR! npm ERR! Conflicting peer dependency: class-validator@0.13.2 npm ERR! node_modules/class-validator npm ERR! peerOptional class-validator@"^0.11.1 || ^0.12.0 || ^0.13.0" from @nestjs/mapped-types@1.2.0 npm ERR! node_modules/@nestjs/mapped-types npm ERR! @nestjs/mapped-types@"^1.2.0" from the root project npm ERR! npm ERR! Fix the upstream dependency conflict, or retry npm ERR! this command with --force, or --legacy-peer-deps npm ERR! to accept an incorrect (and potentially broken) dependency resolution. npm ERR! npm ERR! See C:\Users\rabur\AppData\Local\npm-cache\eresolve-report.txt for a full report. npm ERR! A complete log of this run can be found in: npm ERR! C:\Users\rabur\AppData\Local\npm-cache\_logs\2023-01-16T20_28_35_415Z-debug-0.log
当前package.json内容
{ "name": "application", "version": "0.0.1", "description": "", "author": "", "private": true, "license": "UNLICENSED", "scripts": { "prebuild": "rimraf dist", "build": "nest build", "format": "prettier --write \"src/**/*.ts\" \"test/**/*.ts\"", "start": "nest start", "start:dev": "nest start --watch", "start:debug": "nest start --debug --watch", "start:prod": "node dist/main", "lint": "eslint \"{src,apps,libs,test}/**/*.ts\" --fix", "test": "jest", "test:watch": "jest --watch", "test:cov": "jest --coverage", "test:debug": "node --inspect-brk -r tsconfig-paths/register -r ts-node/register node_modules/.bin/jest --runInBand", "test:e2e": "jest --config ./test/jest-e2e.json" }, "dependencies": { "@nestjs/common": "^9.0.0", "@nestjs/config": "^2.2.0", "@nestjs/core": "^9.0.0", "@nestjs/jwt": "^10.0.1", "@nestjs/mapped-types": "^1.2.0", "@nestjs/mongoose": "^9.2.1", "@nestjs/passport": "^9.0.0", "@nestjs/platform-express": "^9.0.0", "bcrypt": "^5.1.0", "class-transformer": "^0.5.1", "class-validator": "^0.14.0", "cookie-parser": "^1.4.6", "helmet": "^6.0.1", "mongoose": "^6.7.5", "passport": "^0.6.0", "passport-jwt": "^4.0.0", "reflect-metadata": "^0.1.13", "rimraf": "^4.0.7", "rxjs": "^7.2.0", "stripe": "^11.6.0" }, "devDependencies": { "@nestjs/cli": "^9.0.0", "@nestjs/schematics": "^9.0.0", "@nestjs/testing": "^9.0.0", "@types/bcrypt": "^5.0.0", "@types/cookie-parser": "^1.4.3", "@types/express": "^4.17.13", "@types/jest": "29.2.5", "@types/node": "^18.11.18", "@types/passport-jwt": "^3.0.7", "@types/supertest": "^2.0.11", "@typescript-eslint/eslint-plugin": "^5.0.0", "@typescript-eslint/parser": "^5.0.0", "eslint": "^8.0.1", "eslint-config-prettier": "^8.3.0", "eslint-plugin-prettier": "^4.0.0", "jest": "29.3.1", "prettier": "^2.3.2", "source-map-support": "^0.5.20", "supertest": "^6.1.3", "ts-jest": "29.0.5", "ts-loader": "^9.2.3", "ts-node": "^10.0.0", "tsconfig-paths": "4.1.2", "typescript": "^4.7.4" }, "jest": { "moduleFileExtensions": [ "js", "json", "ts" ], "rootDir": "src", "testRegex": ".*\\.spec\\.ts$", "transform": { "^.+\\.(t|j)s$": "ts-jest" }, "collectCoverageFrom": [ "**/*.(t|j)s" ], "coverageDirectory": "../coverage", "testEnvironment": "node" } }
解决方案
方案1:升级@nestjs/mapped-types到兼容版本
@nestjs/mapped-types从2.0.0版本开始,peer依赖已更新为支持class-validator@0.14.x。执行以下命令升级:
npm install @nestjs/mapped-types@latest
升级后重新执行npm install即可解决冲突,这是最推荐的长期解决方案。
方案2:使用--legacy-peer-deps临时绕过冲突
若暂时无法升级@nestjs/mapped-types,可使用npm的旧版peer依赖解析逻辑绕过冲突:
npm install --legacy-peer-deps
注意:此方案仅适合临时过渡,可能存在潜在兼容性风险,后续仍建议升级依赖。
方案3:通过overrides强制指定依赖版本(npm 8.3+支持)
在package.json中添加overrides字段,强制@nestjs/mapped-types使用class-validator@0.14.0:
{ "overrides": { "@nestjs/mapped-types": { "class-validator": "^0.14.0" } } }
添加后执行npm install即可完成安装,安装后需测试项目代码运行是否正常,确保无兼容性问题。
内容的提问来源于stack exchange,提问作者JEAN PABLO CALDERON RAMIREZ
相关产品推荐
相关产品推荐

