我刚刚跑了npm audit fix
,然后检查了 package-lock.json 中的更改。
之前npm audit fix
:
"ssri": {
"version": "6.0.1",
"resolved": "https://registry.npmjs.org/ssri/-/ssri-6.0.1.tgz",
"integrity": "sha512-3Wge10hNcT1Kur4PDFwEieXSCMCJs/7WvSACcrMYrNp+b8kDL1/0wJch5Ni2WrtwEa2IO8OsVfeKIciKCDx/QA==",
"requires": {
"figgy-pudding": "^3.5.1"
}
},
之后npm audit fix
:
"ssri": {
"version": "6.0.1",
"resolved": "",
"requires": {
"figgy-pudding": "^3.5.1"
}
},
这有什么意义?这甚至不会降低安全性吗?