npm 6.0.1执行npm audit建议后无变化,npm update fsevents命令失效求助
npm update fsevents --depth 4 Isn't Fixing Your Vulnerabilities in npm 6.0.1 Hey there! It’s frustrating when a command that used to work suddenly doesn’t resolve your npm audit vulnerabilities—let’s walk through the most likely reasons this is happening with your fsevents update, and what you can do about it.
Outdated npm version is holding you back
npm 6.0.1 is a pretty old release (from 2018), and early 6.x versions had significant bugs in hownpm auditandnpm updatehandle dependency trees and vulnerability resolution. Later patches to npm 6 (like 6.14.18, the final 6.x release) fixed many issues with depth-based updates and audit accuracy. Your older npm might not be correctly traversing the dependency tree to level 4, or might fail to apply updates even when it finds them.The vulnerabilities are outside the specified depth
The--depth 4flag only updates dependencies up to 4 levels deep in your tree. If the 65 fsevents-related vulnerabilities are coming from packages nested deeper than level 4, this command won’t touch them. Runnpm ls fseventsto print all instances of fsevents in your dependency tree—this will show you exactly where each version is located and how deep it is.Strict version constraints block updates
Some of your direct or indirect dependencies might have hard version locks on fsevents (e.g., requiring^1.2.3instead of a version that includes the patch). npm won’t override these constraints by default, so even if you run the update command, it can’t upgrade fsevents in those cases. Check the output ofnpm ls fseventsfor any version pins that prevent upgrading to a patched release.Audit report might be misattributing vulnerabilities
Sometimesnpm auditflags vulnerabilities that aren’t actually in fsevents itself, but in a different package that depends on fsevents. Or the audit database might be out of date, flagging a vulnerability that’s already been patched in your installed version. Look up the specific CVE IDs from your audit report in fsevents’ GitHub release notes or issue tracker to confirm if your current version is actually vulnerable.Stale lock file or node_modules are causing issues
Yourpackage-lock.jsonmight be outdated, sonpm updateis respecting old locked versions instead of pulling in the latest patched releases. Try deleting yournode_modulesfolder andpackage-lock.jsonfile, then runnpm installto rebuild your dependency tree from scratch. After that, re-runnpm auditand try the update command again.
Quick next steps to try:
- First, upgrade npm to the latest 6.x version with
npm install -g npm@6—this will fix many of the core bugs in your current version. - Run
npm ls fseventsto map out all instances of the package in your tree. - If you still see vulnerabilities, try
npm audit fix(note: this might make breaking changes to your dependencies, so test thoroughly).
内容的提问来源于stack exchange,提问作者eKelvin

