how to update package-lock.json file in laravel?

Viewed 1214

The security part of GateLab gives me a message to update the ‍‍package-lock.json file. The text of the message is as follows :

‍Known security vulnerabilities detected

Dependency object-path Version < 0.11.5 Upgrade to ~> 0.11.5 Defined in package-lock.json Vulnerabilities CVE-2020-15256 High severity

Dependency elliptic Version < 6.5.4 Upgrade to ~> 6.5.4 Defined in package-lock.json Vulnerabilities CVE-2020-28498 Moderate severity

Dependency is-svg Version

= 2.1.0 < 4.2.2 Upgrade to ~> 4.2.2

Defined in package-lock.json Vulnerabilities CVE-2021-28092 Moderate severity

Dependency ssri Version

= 5.2.2 < 8.0.1 Upgrade to ~> 8.0.1

Defined in package-lock.json Vulnerabilities CVE-2021-27290 Moderate severity

but packages will not be updated when I update npm with npm update

3 Answers

Although this is not Laravel related as has been mentioned, you can use a packaged called npm-check-updates to check for updates to your package.json

It is installed like this

npm install -g npm-check-updates

And you can use it by running

ncu

1

Run npm outdated to check all the outdated packages. You will see the wanted version in the results.

Run npm update to update to the wanted version.

2

If that doesn't work, try to install them manually.

npm install object-path@~0.11.5

3 CAUTION

You can also update all dependencies to the latest versions by

npx npm-check-updates -u

YOU MAY ENCOUNTER COMPATIBILITY PROBLEM AFTER BLINDLY UPDATING, YOUR PROJECT MAY EXPLODE.

Related