You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Angular 14执行npm install遇ERESOLVE依赖冲突求助

Angular 14 依赖冲突与安全漏洞解决方案

当前环境

  • Angular 14.2.6
  • Node 16.17.0
  • Npm 8.15.0

ng version 输出信息

_                      _                 ____ _     ___
    / \   _ __   __ _ _   _| | __ _ _ __     / ___| |   |_ _|
   / △ \ | '_ \ / _` | | | | |/ _` | '__|   | |   | |    | |
  / ___ \| | | | (_| | |_| | | (_| | |      | |___| |___ | |
 /_/   \_\_| |_|\__, |\__,_|_|\__,_|_|       \____|_____|___|
                |___/
    

Angular CLI: 14.2.6
Node: 16.17.0
Package Manager: npm 8.15.0
OS: win32 x64

Angular: 14.2.6
... animations, cli, common, compiler, compiler-cli, core, forms
... platform-browser, platform-browser-dynamic, router

Package                            Version
------------------------------------------------------------
@angular-devkit/architect          0.1402.6
@angular-devkit/build-angular      14.2.6
@angular-devkit/core               14.2.6
@angular-devkit/schematics         14.2.6
@angular/cdk                       14.2.5
@angular/flex-layout               14.0.0-beta.41
@angular/material                  14.2.5
@angular/material-moment-adapter   14.2.5
@schematics/angular                14.2.6
rxjs                               7.5.7
typescript                         4.8.4

执行npm install时的ERESOLVE错误

$ npm install
npm ERR! code ERESOLVE
npm ERR! ERESOLVE could not resolve
npm ERR!
npm ERR! While resolving: angular-user-idle@3.0.0
npm ERR! Found: @angular/common@14.2.6
npm ERR! node_modules/@angular/common
npm ERR!   @angular/common@"~14.2.6" from the root project
npm ERR!   peer @angular/common@"^14.0.0 || ^15.0.0" from @angular/cdk@14.2.5    
npm ERR!   node_modules/@angular/cdk
npm ERR!     @angular/cdk@"^14.2.5" from the root project
npm ERR!     peer @angular/cdk@"^14.0.0" from @angular/flex-layout@14.0.0-beta.41
npm ERR!     node_modules/@angular/flex-layout
npm ERR!       @angular/flex-layout@"^14.0.0-beta.41" from the root project      
npm ERR!     1 more (@angular/material)
npm ERR!   6 more (@angular/flex-layout, @angular/forms, ...)
npm ERR!
npm ERR! Could not resolve dependency:
npm ERR! peer @angular/common@"^13.3.0" from angular-user-idle@3.0.0
npm ERR! node_modules/angular-user-idle
npm ERR!   angular-user-idle@"^3.0.0" from the root project
npm ERR!
npm ERR! Conflicting peer dependency: @angular/common@13.3.11
npm ERR! node_modules/@angular/common
npm ERR!   peer @angular/common@"^13.3.0" from angular-user-idle@3.0.0
npm ERR!   node_modules/angular-user-idle
npm ERR!     angular-user-idle@"^3.0.0" from the root project
npm ERR!
npm ERR! Fix the upstream dependency conflict, or retry
npm ERR! this command with --force, or --legacy-peer-deps
npm ERR! to accept an incorrect (and potentially broken) dependency resolution.

已尝试操作与诉求

  • 拒绝使用npm install --force或--legacy-peer-deps,避免依赖解析异常
  • 拒绝降级npm/Node版本
  • 已在package.json中添加overrides配置:
{
  ...
  ,
  "overrides": {
    "angular-user-idle": {
      "@angular/common": "$@angular/common", 
      "@angular/core": "$@angular/core"
    }
  },
  ...
}

npm audit fix后的问题

执行npm audit fix后得到审计报告:

# npm audit report

angular  *
Severity: moderate
angular vulnerable to regular expression denial of service (ReDoS)
Angular (deprecated package) Cross-site Scripting
fix available via `npm audit fix`
node_modules/angular

后续在package-lock.json中发现多处对AngularJS(angular包)的引用,需解决该安全漏洞及依赖问题。


解决方案

1. 修复angular-user-idle的依赖冲突

angular-user-idle@3.0.0仅兼容Angular 13,与当前Angular 14版本冲突,优先升级该包:

  • 安装适配Angular 14的angular-user-idle版本(如4.x系列):
    npm install angular-user-idle@4.0.0
    
    可先查看其官方版本说明确认兼容性,或直接安装最新兼容版本:
    npm install angular-user-idle@latest
    
  • 若无法找到兼容版本,可保留overrides配置,但需严格测试angular-user-idle的功能是否正常运行,避免出现运行时错误。

2. 处理AngularJS的安全漏洞

审计中的angular包是已废弃的AngularJS,非当前使用的Angular(@angular/*),需定位并修复:

  • 执行以下命令找到引入AngularJS的上游依赖:
    npm ls angular
    
  • 若上游依赖有更新版本,升级至不再依赖AngularJS的版本;
  • 若无法升级上游依赖,可通过overrides强制升级AngularJS到最新安全版本:
    "overrides": {
      "angular": "^1.8.3"
    }
    
    注意:若业务未使用该依赖的功能,可尝试移除相关上游依赖,但需先验证项目功能不受影响。

3. 验证修复效果

  • 执行npm install确认无依赖错误;
  • 启动项目,测试所有功能正常;
  • 再次执行npm audit确认漏洞已修复。

内容的提问来源于stack exchange,提问作者d.b

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.16 09:35:20