How to resolve vulnerabilities detected by yarn audit? #9667
-
|
I develop a SPA with quasar 1.15.20, @quasar/app 2.2.10 (sorry, no CLI - SPA mode topic available). I did I would like to get rid of these vulnerabilities. I installed yarn-audit-fix, but it could not fix them: Do you have any advice? Or am I overreacting about these vulnerabilities? |
Beta Was this translation helpful? Give feedback.
Replies: 3 comments 3 replies
-
Beta Was this translation helpful? Give feedback.
-
These are audit results from one of my Quasar apps (1.15.13): |
Beta Was this translation helpful? Give feedback.
-
|
The only way for the audit to not report anything is to upgrade to Quasar v2. But, regardless of above, there is literally zero impact over the production code outputted (your /dist). These are packages used only on the devserver itself. |
Beta Was this translation helpful? Give feedback.
The only way for the audit to not report anything is to upgrade to Quasar v2.
There's a lot of packages that cannot be upgraded for Qv1 because of Webpack 4. Upgrading to Webpack 5 for Qv1 would mean the mother of all breaking changes.
But, regardless of above, there is literally zero impact over the production code outputted (your /dist). These are packages used only on the devserver itself.