NPM 6 - 我应该审核修复所有软件包漏洞吗?

时间:2018-06-12 17:18:13

标签: security npm npm-install audit angular6

安装NPM 6后,我在Angular 6项目上安装的几乎所有NPM软件包都存在漏洞。

我应该每次“npm审核修复”每个包吗? 我应该重新安装NPM 5吗?其他解决方案?

这是我使用的终端sequlize代码及其漏洞:

npm i sequelize --save
npm WARN @angular/material@6.2.1 requires a peer of @angular/cdk@6.2.1 
but none is installed. You must install peer dependencies yourself.

+ sequelize@4.37.10
added 16 packages from 39 contributors and audited 22308 packages in 
10.659s
found 9 vulnerabilities (3 low, 5 moderate, 1 high)
run `npm audit fix` to fix them, or `npm audit` for details

1 个答案:

答案 0 :(得分:0)

尝试执行以下cmd:

* npm i karma@3.0.0-保存并
* npm install --save-dev protractor@5.4.0