试图安装松露时电子错误
当我尝试使用NPM安装安装松露时,g [emagy 警告说,有15个vunersisions(10个中等,4个高和1批判性)。当我运行NPM审核修复时,我会得到以下错误
电子< = 13.6.3严重性:高
上下文隔离通过电子中的泄漏的跨上下文对象 - https .com/Advision/GHSA-M93V-9QJC-3G79
沙盒渲染器可以通过 本地图 - https://github.com/github.com/advisories/ghsa-mpjm-v997--ghsa-mpjm-v997--- C4H4
IPC消息传递到电子中错误的框架 - https://github.com/advisories/ghsa-hvf8-hvf8-hvf8-hv8-h2qh-37m9m9
上下文隔离通过电子中的承诺绕过 - https://github.com/advisories/ghsa-6vrv-94jv-94jv-crrg
渲染器可以在没有的情况下获取对随机蓝牙设备的访问 电子许可 - https://github.com/advisories/ghsa-ghsa-3p22-ghq8-v749
通过
NPM审核修复程序可用修复
node_modules/electron-eval/node_modules/electron
electron-eval> = 0.9.8
取决于电子的脆弱版本 node_modules/electron-eval
安装的电子版本为19.0.3
我试图卸载电子并更改版本,但没有任何效果,我不确定为什么要安装电子谢谢
诺埃尔
When I try install truffle using npm install -g [email protected] I get a warning that there are 15 vunerabilities (10 moderate, 4 high and 1 critical). When I run npm audit fix I get the following errors
electron <=13.6.3 Severity: high
Context isolation bypass via leaked cross-context objects in Electron - https://github.com/advisories/GHSA-m93v-9qjc-3g79
Sandboxed renderers can obtain thumbnails of arbitrary files through
the nativeImage API - https://github.com/advisories/GHSA-mpjm-v997-c4h4IPC messages delivered to the wrong frame in Electron -
https://github.com/advisories/GHSA-hvf8-h2qh-37m9Context isolation bypass via Promise in Electron -
https://github.com/advisories/GHSA-6vrv-94jv-crrgRenderers can obtain access to random bluetooth device without
permission in Electron -
https://github.com/advisories/GHSA-3p22-ghq8-v749fix available via
npm audit fix
node_modules/electron-eval/node_modules/electron
electron-eval >=0.9.8
Depends on vulnerable versions of electron
node_modules/electron-eval
the version of electron installed is 19.0.3
I've tried to uninstall electron and change the version but nothing is working, I'm not sure why electron is installed, I don't think I have used it for anything
Thanks
Noelle
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
data:image/s3,"s3://crabby-images/d5906/d59060df4059a6cc364216c4d63ceec29ef7fe66" alt="扫码二维码加入Web技术交流群"
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论
评论(1)
最新版本的松露需要C ++开发工具。 -install-truffle-g“>在使用NPM安装松露在Windows 10上安装松露时会出现错误-G
我认为可能存在一些兼容性问题,我有2005年以来的VS版本,从2005年及其机器上开始。我唯一可以提出的解决方案是删除所有实例Visual Studio,然后我就可以安装Truffle版本5.4.29而无需发行。从那以后,我已经安装了VS代码,并且效果很好。
The latest version of truffle requires c++ development tools as per this SO question Getting Error on installing Truffle on windows 10 using npm install truffle -g
I think there may have been some compatibility issues, I had versions of VS from 2005 and onwards on my machine. The only solution I could come up with was to remove all instances of Visual Studio, I was then able to install truffle version 5.4.29 without issue. I have since installed VS code and it works grand.