React Native Expo项目npm依赖漏洞无法修复,修复命令执行后问题循环
React Native Expo 依赖漏洞循环修复失败问题
我花了数小时尝试修复React Native Expo项目中的依赖漏洞,试过所有常规方法均无效:
- 执行
npm update - 执行
npm audit fix --force - 执行
npm update dep@latest - 修改漏洞依赖版本后执行
npm i - 删除
package-lock.json后重新安装
操作后不仅漏洞未解决,还出现了循环问题:每次执行修复命令,漏洞状态会在两个不同的问题间来回切换。
初始npm audit报告
# npm audit report qs 6.7.0 - 6.7.2 Severity: high qs vulnerable to Prototype Pollution fix available via `npm audit fix --force` Will install expo@44.0.6, which is a breaking change node_modules/qs body-parser 1.19.0 Depends on vulnerable versions of qs node_modules/body-parser @expo/dev-server * Depends on vulnerable versions of body-parser node_modules/@expo/dev-server @expo/cli >=0.1.0 Depends on vulnerable versions of @expo/dev-server node_modules/expo/node_modules/@expo/cli expo >=45.0.0-beta.1 Depends on vulnerable versions of @expo/cli node_modules/expo 5 high severity vulnerabilities To address all issues (including breaking changes), run: npm audit fix --force
执行npm audit fix --force后的npm audit报告
# npm audit report node-fetch <=2.6.6 Severity: high The `size` option isn't honored after following a redirect in node-fetch node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor fix available via `npm audit fix --force` Will install expo@47.0.8, which is a breaking change node_modules/isomorphic-fetch/node_modules/node-fetch isomorphic-fetch 2.0.0 - 2.2.1 Depends on vulnerable versions of node-fetch node_modules/isomorphic-fetch fbjs 0.7.0 - 1.0.0 Depends on vulnerable versions of isomorphic-fetch node_modules/fbemitter/node_modules/fbjs fbemitter 2.0.3 - 3.0.0-alpha.1 Depends on vulnerable versions of fbjs node_modules/fbemitter expo 14.0.0 - 44.0.6 Depends on vulnerable versions of fbemitter node_modules/expo 5 vulnerabilities (4 low, 1 high) To address all issues (including breaking changes), run: npm audit fix --force
解决方案建议
升级到最新稳定版Expo
问题根源是旧版Expo依赖的子包存在未修复漏洞,npm audit fix --force仅在不同旧版Expo间切换,无法解决根本问题。直接执行官方升级命令:npx expo upgrade该命令会自动处理Expo及相关依赖的版本兼容,升级后大部分漏洞会被修复。
用
overrides强制替换漏洞子依赖
若暂时无法升级Expo,可在package.json中添加overrides字段,强制使用安全版本替换子依赖:"overrides": { "qs": "^6.11.0", "node-fetch": "^2.6.7" }添加后执行
npm install,npm会全局替换依赖树中的对应包版本。清理缓存后重装依赖
缓存异常可能导致依赖安装混乱,执行以下命令彻底清理后重装:npm cache clean --force rm -rf node_modules package-lock.json npm install统一Expo CLI版本
确保全局与项目内的Expo CLI版本一致,避免版本冲突:npm install -g @expo/cli npm install @expo/cli --save-dev
内容的提问来源于stack exchange,提问作者Mark
相关产品推荐
相关产品推荐

