You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

React Native Expo项目npm依赖漏洞无法修复,修复命令执行后问题循环

React Native Expo 依赖漏洞循环修复失败问题

我花了数小时尝试修复React Native Expo项目中的依赖漏洞,试过所有常规方法均无效:

  • 执行npm update
  • 执行npm audit fix --force
  • 执行npm update dep@latest
  • 修改漏洞依赖版本后执行npm i
  • 删除package-lock.json后重新安装

操作后不仅漏洞未解决,还出现了循环问题:每次执行修复命令,漏洞状态会在两个不同的问题间来回切换。

初始npm audit报告

# npm audit report

qs  6.7.0 - 6.7.2
Severity: high
qs vulnerable to Prototype Pollution
fix available via `npm audit fix --force`
Will install expo@44.0.6, which is a breaking change
node_modules/qs
  body-parser  1.19.0
  Depends on vulnerable versions of qs
  node_modules/body-parser
    @expo/dev-server  *
    Depends on vulnerable versions of body-parser
    node_modules/@expo/dev-server
      @expo/cli  >=0.1.0
      Depends on vulnerable versions of @expo/dev-server
      node_modules/expo/node_modules/@expo/cli
        expo  >=45.0.0-beta.1
        Depends on vulnerable versions of @expo/cli
        node_modules/expo

5 high severity vulnerabilities

To address all issues (including breaking changes), run:
  npm audit fix --force

执行npm audit fix --force后的npm audit报告

# npm audit report

node-fetch  <=2.6.6
Severity: high
The `size` option isn't honored after following a redirect in node-fetch
node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
fix available via `npm audit fix --force`
Will install expo@47.0.8, which is a breaking change
node_modules/isomorphic-fetch/node_modules/node-fetch
  isomorphic-fetch  2.0.0 - 2.2.1
  Depends on vulnerable versions of node-fetch
  node_modules/isomorphic-fetch
    fbjs  0.7.0 - 1.0.0
    Depends on vulnerable versions of isomorphic-fetch
    node_modules/fbemitter/node_modules/fbjs
      fbemitter  2.0.3 - 3.0.0-alpha.1
      Depends on vulnerable versions of fbjs
      node_modules/fbemitter
        expo  14.0.0 - 44.0.6
        Depends on vulnerable versions of fbemitter
        node_modules/expo

5 vulnerabilities (4 low, 1 high)

To address all issues (including breaking changes), run:
  npm audit fix --force

解决方案建议

  1. 升级到最新稳定版Expo
    问题根源是旧版Expo依赖的子包存在未修复漏洞,npm audit fix --force仅在不同旧版Expo间切换,无法解决根本问题。直接执行官方升级命令:

    npx expo upgrade
    

    该命令会自动处理Expo及相关依赖的版本兼容,升级后大部分漏洞会被修复。

  2. 用overrides强制替换漏洞子依赖
    若暂时无法升级Expo,可在package.json中添加overrides字段,强制使用安全版本替换子依赖:

    "overrides": {
      "qs": "^6.11.0",
      "node-fetch": "^2.6.7"
    }
    

    添加后执行npm install,npm会全局替换依赖树中的对应包版本。

  3. 清理缓存后重装依赖
    缓存异常可能导致依赖安装混乱,执行以下命令彻底清理后重装:

    npm cache clean --force
    rm -rf node_modules package-lock.json
    npm install
    
  4. 统一Expo CLI版本
    确保全局与项目内的Expo CLI版本一致,避免版本冲突:

    npm install -g @expo/cli
    npm install @expo/cli --save-dev
    

内容的提问来源于stack exchange,提问作者Mark

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.07 19:01:13