romenigld

romenigld

Hello Guys,
I’m reading the ebook Programming Phoenix 1.4 and in the subchapter “Phoenix LiveView” of the chapter “What’s Next?” I cloned the Phoenix LiveView Example.
So I made the steps for run and when I run the npm install. I have a warning for fix the npm audit.

So I try to fix like recommend the steps and with --force.
But it complains for 1 vulnerability.

 $ npm audit

                       === npm audit security report ===

┌──────────────────────────────────────────────────────────────────────────────┐
│                                Manual Review                                 │
│            Some vulnerabilities require your attention to resolve            │
│                                                                              │
│         Visit https://go.npm.me/audit-guide for additional guidance          │
└──────────────────────────────────────────────────────────────────────────────┘
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ High          │ Arbitrary File Overwrite                                     │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package       │ tar                                                          │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in    │ >=2.2.2 <3.0.0 || >=4.4.2                                    │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ webpack [dev]                                                │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path          │ webpack > watchpack > chokidar > fsevents > node-pre-gyp >   │
│               │ tar                                                          │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info     │ https://npmjs.com/advisories/803                             │
└───────────────┴──────────────────────────────────────────────────────────────┘
found 1 high severity vulnerability in 6579 scanned packages
  1 vulnerability requires manual review. See the full report for details.

I don’t know what do. I need help!?

Showing Posts 1 to 10

egze

egze

Don‘t know how to fix it, Sorry.

But also I wouldn‘t worry about it too much. For production app you won‘t be running node, webpack or this tar package. The scripts will be compiled to 1 JS file and served statically.

romenigld

romenigld OP

So I ignore and continue?
thank’s for reply @egze.

egze

egze

Yepp. I would ignore it.

romenigld

romenigld OP

:love_you_gesture::crossed_fingers:

kokolegorille

kokolegorille

There is package that helps You update npm package…

https://github.com/tjunnone/npm-check-updates

You might use it to solve this issue.

romenigld

romenigld OP

Nice package @kokolegorille. Thank you for reply!
This NCU work’s, and do it automatically.
Here is what happened when I tried.

$ ncu
Checking /Users/romenigld/workspace/phoenix/Programming Phoenix 1.4/phoenix_live_view_example/assets/package.json
[====================] 12/12 100%

 babel-core           ^6.26.0  →  ^6.26.3
 babel-loader          ^7.1.5  →   ^8.0.6
 babel-preset-env      ^1.6.1  →   ^1.7.0
 copy-webpack-plugin   ^4.6.0  →   ^5.0.5
 style-loader         ^0.20.2  →   ^1.0.1
 webpack                4.0.0  →   4.41.2

Run ncu -u to upgrade package.json

$ ncu -u
Upgrading /Users/romenigld/workspace/phoenix/Programming Phoenix 1.4/phoenix_live_view_example/assets/package.json
[====================] 12/12 100%

 babel-core           ^6.26.0  →  ^6.26.3
 babel-loader          ^7.1.5  →   ^8.0.6
 babel-preset-env      ^1.6.1  →   ^1.7.0
 copy-webpack-plugin   ^4.6.0  →   ^5.0.5
 style-loader         ^0.20.2  →   ^1.0.1
 webpack                4.0.0  →   4.41.2

Run npm install to install new versions.

$  npm install

> fsevents@1.2.9 install /Users/romenigld/workspace/phoenix/Programming Phoenix 1.4/phoenix_live_view_example/assets/node_modules/fsevents
> node install

node-pre-gyp WARN Using needle for node-pre-gyp https download
[fsevents] Success: "/Users/romenigld/workspace/phoenix/Programming Phoenix 1.4/phoenix_live_view_example/assets/node_modules/fsevents/lib/binding/Release/node-v64-darwin-x64/fse.node" is installed via remote
npm WARN babel-loader@8.0.6 requires a peer of @babel/core@^7.0.0 but none is installed. You must install peer dependencies yourself.
npm WARN assets No description

added 69 packages from 72 contributors, removed 7 packages, updated 93 packages, moved 2 packages and audited 7759 packages in 13.996s
found 0 vulnerabilities

egze

egze

Seems that you still have a problem with @babel/core?

romenigld

romenigld OP

Yes I just see this WARN now, I just saw the 0 vulnerabilities.
How can I install to the core 7?
thank’s for reply!

egze

egze

Set the version in package.json and npm update.

romenigld

romenigld OP

I tried to do like you told me. But I made a mistake, so rather than put npm update.
I put to run run npm instal and I get this error:

 npm install
npm ERR! code ETARGET
npm ERR! notarget No matching version found for babel-core@^7.0.0.
npm ERR! notarget In most cases you or one of your dependencies are requesting
npm ERR! notarget a package version that doesn't exist.

npm ERR! A complete log of this run can be found in:
npm ERR!     /Users/romenigld/.npm/_logs/2019-12-06T11_50_08_131Z-debug.log

So I was seeking for update this and what I do was:

$ npm install --save-dev @babel/core @babel/preset-env
npm WARN assets No description

+ @babel/preset-env@7.7.4
+ @babel/core@7.7.4
added 115 packages from 35 contributors and audited 8924 packages in 11.732s
found 0 vulnerabilities

$ npm install
npm WARN assets No description

audited 8924 packages in 5.238s
found 0 vulnerabilities

Anyway, thank you for help me @egze.

Where Next? Top

Trending in Questions Top

katta
I having some trouble figuring out if I have set myself too strict of standards for my production server. Currently I can handle 75% of r...
New
brecabral
Documentation While reading the Scoped Routes section, I noticed that the documentation currently refers to a problem without explainin...
New
achenet
Hello, I’m trying to build a basic Phoenix web-app, and I’d like to use Tailwind. However, when I launch mix phx.server, I get an error...
New
kpanic
Hi everyone, I am toying with the idea of building a “match maker” for giving personal help to people that wants to start coding. I sta...
New
asweet-confluent
I recently noticed that Elixir’s Logger defaults its primary log level to :debug when no :logger, :level application configuration is pre...
New
Cxx-mlr
I’m working on a small exercise involving update_in/3, and I came up with this solution: data = %{ name: "Periodic Table", category:...
New
ChrisAmelia
I’ve got trouble wrapping my head around the order in which functions are called in this snippet (from Phoenix’s authentication): toke...
New

Other Trending Topics Top

GenericJam
Edit: 2026 May 15 - This post is archived. Mob is alive!! Main docs: mob v0.7.11 — Documentation A bit of explanation for the slightly c...
New
JesseHerrick
Hey, I’m Jesse and I’m the main contributor behind Dexter, a full-featured, lightning-fast Elixir LSP optimized for large codebases. It s...
New
mudasobwa
I am happy to introduce the very α version of the new programming language compiled to BEAM. Welcome Cure. It has literally three kille...
New
garrison
Hobbes is a low-level distributed database for the Elixir programming language. Hobbes provides a simple, safe, and scalable storage lay...
New
mhanberg
Hi everyone! The first release candidate for the Expert language server project is now available! We’ve published a press release detai...
New
budgie
A little off-topic, but I feel like people here have a good head on their shoulders. I used to be quite good at making software. Was luc...
New

We're in Beta

About us Mission Statement

Options

Thread Display Mode




Thread Preview

Skip Thread Previews