Накатил чистый проект с помощью
npx sv create
сразу ловлю
cookie <0.7.0
cookie accepts cookie name, path, and domain with out of bounds characters - https://github.com/advisories/GHSA-pxg6-pf52-xh8x
fix available via npm audit fix --force
Will install @sveltejs/kit@0.0.30, which is a breaking change
node_modules/cookie
@sveltejs/kit >=1.0.0-next.0
Depends on vulnerable versions of @sveltejs/vite-plugin-svelte
Depends on vulnerable versions of cookie
Depends on vulnerable versions of vite
node_modules/@sveltejs/kit
@sveltejs/adapter-auto >=1.0.0-next.0
Depends on vulnerable versions of @sveltejs/kit
node_modules/@sveltejs/adapter-auto
@sveltejs/adapter-node >=1.0.0-next.0
Depends on vulnerable versions of @sveltejs/kit
node_modules/@sveltejs/adapter-node
esbuild <=0.24.2
Severity: moderate
esbuild enables any website to send any requests to the development server and read the response - https://github.com/advisories/GHSA-67mh-4wv8-2f99
No fix available
node_modules/esbuild
vite >=0.11.0
Depends on vulnerable versions of esbuild
node_modules/vite
@sveltejs/vite-plugin-svelte *
Depends on vulnerable versions of @sveltejs/vite-plugin-svelte-inspector
Depends on vulnerable versions of vite
Depends on vulnerable versions of vitefu
node_modules/@sveltejs/vite-plugin-svelte
@sveltejs/vite-plugin-svelte-inspector *
Depends on vulnerable versions of @sveltejs/vite-plugin-svelte
Depends on vulnerable versions of vite
node_modules/@sveltejs/vite-plugin-svelte-inspector
vitefu *
Depends on vulnerable versions of vite
node_modules/vitefu
9 vulnerabilities (3 low, 6 moderate)
как сделать 0 vulnerabilities ? Пробовал обновить все пакеты - не спасло ситуацию