豆豆友情提示:这是一个非官方 GitHub 代理镜像,主要用于网络测试或访问加速。请勿在此进行登录、注册或处理任何敏感信息。进行这些操作请务必访问官方网站 github.com。 Raw 内容也通过此代理提供。
Skip to content

Support package.json overrides for vulnerability remediation #14736

@jiayi11

Description

@jiayi11

Is there an existing issue for this?

  • I have searched the existing issues

Feature description

We’d like the tool to use overrides in package.json for dependency vulnerability fixes, instead
of only updating package-lock.json. Right now, it only changes the lockfile. While that may fix the immediate issue, it does not clearly document the intended dependency constraint in source control. Using overrides would make the remediation explicit and persistent, especially when lockfiles are regenerated or dependencies are reinstalled.

https://docs.npmjs.com/cli/v8/configuring-npm/package-json#overrides

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    Status

    No status

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions