1

我刚刚跑了npm audit fix,然后检查了 package-lock.json 中的更改。

之前npm audit fix

    "ssri": {
      "version": "6.0.1",
      "resolved": "https://registry.npmjs.org/ssri/-/ssri-6.0.1.tgz",
      "integrity": "sha512-3Wge10hNcT1Kur4PDFwEieXSCMCJs/7WvSACcrMYrNp+b8kDL1/0wJch5Ni2WrtwEa2IO8OsVfeKIciKCDx/QA==",
      "requires": {
        "figgy-pudding": "^3.5.1"
      }
    },

之后npm audit fix

    "ssri": {
      "version": "6.0.1",
      "resolved": "",
      "requires": {
        "figgy-pudding": "^3.5.1"
      }
    },

这有什么意义?这甚至不会降低安全性吗?

4

0 回答 0