I got 86 vulnerabilities and 4 of them are high. And then I run npm audit to know what's wrong with my react project
High Regular Expression Denial of Service
Package normalize-url
Patched in >=4.5.1 <5.0.0 || >=5.3.1 <6.0.0 || >=6.0.1
Dependency of react-scripts
Path react-scripts > optimize-css-assets-webpack-plugin > cssnano
> cssnano-preset-default > postcss-normalize-url >
normalize-url
More info https://npmjs.com/advisories/1755
And then I visit the url and I know I should upgrade to versions 4.5.1, 5.3.1, 6.0.1 or later. I did it using npm install normalize-url@6.0.1 but I still got the same vulnerabilities. I try to check which version of normalize-url was installed by running npm ls normalize-url and I got:
+-- normalize-url@6.0.1
`-- react-scripts@4.0.3
+-- mini-css-extract-plugin@0.11.3
| `-- normalize-url@1.9.1
`-- optimize-css-assets-webpack-plugin@5.0.4
`-- cssnano@4.1.11
`-- cssnano-preset-default@4.0.8
`-- postcss-normalize-url@4.0.1
`-- normalize-url@3.3.0
I've tried to do this too https://www.npmjs.com/package/npm-force-resolutions and I still got the vulnerabilities. Does anyone know how to fix this? Thanks