Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

2 low severity vulnerabilities

未关闭
#583 2 条评论 8 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

评估

难度
4/5
预计耗时
3-5 天
新手友好度
28/100
Issue 类型
缺陷
描述清晰度
基本清楚
活跃度
停滞
领域
security, tooling

调研方向

首先使用 npm install,然后使用 npm audit 重现报告,接着通过 patch-package 跟踪间接依赖 tmp。检查是否有可用的安全版本或有文档记录的解决方法;在不破坏 patch-package 的情况下解决依赖警告即表示完成。

由索引模型根据 Issue 内容生成。

描述

Problem Description

Running npm audit reports vulnerabilities in the tmp dependency, which is indirectly required by patch-package.

Audit Log

# npm audit report

tmp  <=0.2.3
tmp allows arbitrary temporary file / directory write via symbolic link `dir` parameter - https://github.com/advisories/GHSA-52f5-9888-hmc6
No fix available
node_modules/tmp
  patch-package  *
  Depends on vulnerable versions of tmp
  node_modules/patch-package

2 low severity vulnerabilities

Impact

  • patch-package depends on a vulnerable version of tmp.
  • No fix is currently available.
  • This raises security warnings when installing dependencies.

Steps to Reproduce

  1. Install dependencies with npm install
  2. Run npm audit
  3. See the reported vulnerability in tmp

Expected Behavior

  • patch-package should update the tmp dependency to a secure version or provide a workaround.

Environment

  • Node.js: 20
主要语言
TypeScript
星标
11.2k
派生
325
PR 合并指标
30 天内没有已合并 PR

环境准备

我们还没有检查这个项目的环境配置文件。先看它的 README,通用步骤见我们的新手贡献指南。

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

ds300/patch-package 的其他 Issue

查看 ds300/patch-package 的全部 Issue

相似的 Issue

更多 TypeScript Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。