Resolve Yarn Dependency to Different Package

Viewed 151

I believe what I'm asking is impossible, but I'm not terribly familiar with JavaScript and Yarn nor their possibilities so I'm asking as a longshot.

But with my project, I'm getting errors with xmldom versions below 0.7.0:

┌───────────────┬──────────────────────────────────────────────────────────────┐
│ moderate      │ Misinterpretation of malicious XML input                     │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package       │ xmldom                                                       │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in    │ >=0.7.0                                                      │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ expo-linking                                                 │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path          │ expo-linking > expo-constants > @expo/config >               │
│               │ @expo/config-plugins > @expo/plist > xmldom                  │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info     │ https://www.npmjs.com/advisories/1769                        │
└───────────────┴──────────────────────────────────────────────────────────────┘

I realize that I can resolve dependencies to higher versions using resolutions in my package.json. However, part of the problem with this dependency is that xmldom is now published as @xmldom/xmldom.

So, beyond just resolving a dependency to a different version, is it at all possible to resolve it to a different package?

0 Answers
Related