You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

安装firebase-tools陷入漏洞修复循环,求助解决方法

安装firebase-tools时npm audit漏洞无法修复的原因

漏洞报告详情

# npm audit report

express  <=4.17.2 || 5.0.0-alpha.1 - 5.0.0-alpha.8
Severity: high
qs vulnerable to Prototype Pollution - GHSA-hrpp-h998-j3pp
Depends on vulnerable versions of qs
fix available via `npm audit fix`
node_modules/firebase-tools/node_modules/express

got  <11.8.5
Severity: moderate
Got allows a redirect to a UNIX socket - GHSA-pfrx-2q88-qq97
fix available via `npm audit fix --force`
Will install firebase-tools@1.2.0, which is a breaking change
node_modules/firebase-tools/node_modules/got
  package-json  <=6.5.0
  Depends on vulnerable versions of got
  node_modules/firebase-tools/node_modules/package-json
    latest-version  0.2.0 - 5.1.0
    Depends on vulnerable versions of package-json
    node_modules/firebase-tools/node_modules/latest-version
      update-notifier  0.2.0 - 5.1.0
      Depends on vulnerable versions of latest-version
      node_modules/firebase-tools/node_modules/superstatic/node_modules/update-notifier
      node_modules/firebase-tools/node_modules/update-notifier
        firebase-tools  >=2.0.0
        Depends on vulnerable versions of update-notifier
        node_modules/firebase-tools
        superstatic  >=0.12.11
        Depends on vulnerable versions of update-notifier
        node_modules/firebase-tools/node_modules/superstatic

minimatch  <3.0.5
Severity: high
minimatch ReDoS vulnerability - GHSA-f8q6-p94x-37v3
fix available via `npm audit fix`
node_modules/firebase-tools/node_modules/minimatch

qs  6.5.0 - 6.5.2 || 6.7.0 - 6.7.2
Severity: high
qs vulnerable to Prototype Pollution - GHSA-hrpp-h998-j3pp
qs vulnerable to Prototype Pollution - GHSA-hrpp-h998-j3pp
fix available via `npm audit fix`
node_modules/firebase-tools/node_modules/qs
node_modules/firebase-tools/node_modules/request/node_modules/qs
  body-parser  1.19.0
  Depends on vulnerable versions of qs
  node_modules/firebase-tools/node_modules/body-parser
  express  <=4.17.2 || 5.0.0-alpha.1 - 5.0.0-alpha.8
  Depends on vulnerable versions of qs
  node_modules/firebase-tools/node_modules/express

10 vulnerabilities (6 moderate, 4 high)

无法修复的核心原因

  • 这些漏洞均来自firebase-tools内部的嵌套依赖包,而非你的项目直接依赖。npm默认修复逻辑仅能处理项目直接依赖,或在不破坏上层依赖版本约束的前提下修复嵌套依赖,但firebase-tools的package.json对express、got、minimatch等依赖的版本范围有严格限制,npm无法自动升级这些嵌套依赖而不破坏firebase-tools的功能。
  • npm audit fix --force的本质是通过降级firebase-tools到1.2.0(极其老旧版本)适配旧依赖,并非真正修复漏洞,还会引入兼容性风险。
  • 手动安装qs@latest仅会将qs作为项目直接依赖,firebase-tools内部仍使用自身嵌套的漏洞版本,无法覆盖。
  • 删除node_modules和package-lock.json重新安装时,npm会严格按照firebase-tools的依赖约束拉取指定版本的嵌套包,漏洞自然会再次出现。

临时解决方案

若需强制修复这些漏洞,可使用npm 8.3+支持的overrides功能,在项目package.json中强制指定firebase-tools嵌套依赖的安全版本:

"overrides": {
  "firebase-tools": {
    "qs": "^6.11.0",
    "express": "^4.18.2",
    "minimatch": "^3.1.2",
    "got": "^11.8.5"
  }
}

添加后执行npm install即可。注意:此操作可能引发firebase-tools的兼容性问题,需测试验证功能是否正常。

内容的提问来源于stack exchange,提问作者JamesG

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.09 14:40:35