chadiik/freight-packer

Dependencies are vulnerable

Opened this issue · 0 comments

Hi Chadik , an excellent tool but as of now seem it has some vulnerabilities , can you help . Is Express required in this . I am trying to install via npm , is there a user manual which can help ? Or newer version ? 2 critical severity vulnerabilities

To address all issues (including breaking changes), run:
npm audit fix --force
root@e2e-109-235:/freight-packer# npm install express --save-dev
npm WARN idealTree Removing dependencies.express in favor of devDependencies.express
npm ERR! code ERESOLVE
npm ERR! ERESOLVE could not resolve
npm ERR!
npm ERR! While resolving: webpack-dev-middleware@1.12.2
npm ERR! Found: webpack@5.83.1
npm ERR! node_modules/webpack
npm ERR! peer webpack@">=5" from babel-loader@9.1.2
npm ERR! node_modules/babel-loader
npm ERR! babel-loader@"^9.1.2" from the root project
npm ERR! peer webpack@"^5.1.0" from terser-webpack-plugin@5.3.9
npm ERR! node_modules/terser-webpack-plugin
npm ERR! terser-webpack-plugin@"^5.3.7" from webpack@5.83.1
npm ERR! 1 more (the root project)
npm ERR!
npm ERR! Could not resolve dependency:
npm ERR! peer webpack@"^1.0.0 || ^2.0.0 || ^3.0.0" from webpack-dev-middleware@1.12.2
npm ERR! node_modules/webpack-dev-middleware
npm ERR! webpack-dev-middleware@"^1.12.2" from the root project
npm ERR!
npm ERR! Conflicting peer dependency: webpack@3.12.0
npm ERR! node_modules/webpack
npm ERR! peer webpack@"^1.0.0 || ^2.0.0 || ^3.0.0" from webpack-dev-middleware@1.12.2
npm ERR! node_modules/webpack-dev-middleware
npm ERR! webpack-dev-middleware@"^1.12.2" from the root project
npm ERR!
npm ERR! Fix the upstream dependency conflict, or retry
npm ERR! this command with --force, or --legacy-peer-deps
npm ERR! to accept an incorrect (and potentially broken) dependency resolution.
npm ERR!
npm ERR! See /root/.npm/eresolve-report.txt for a full report.

npm ERR! A complete log of this run can be found in:
npm ERR! /root/.npm/_logs/2023-05-24T04_45_58_218Z-debug-0.log
root@e2e-109-235:/freight-packer#