# Npm audit fails

**URL:** <https://discourse.nodered.org/t/npm-audit-fails/50525>\
**Category:** General\
**Created:** [2 September 2021 04:18 UTC](https://discourse.nodered.org/t/npm-audit-fails/50525 "2021-09-02T04:18:18Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![augjoh](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/augjoh/32/26464_2.png) [@augjoh](https://discourse.nodered.org/u/augjoh)\
**Post date:** [2 September 2021 04:18 UTC](https://discourse.nodered.org/t/npm-audit-fails/50525/1 "2021-09-02T04:18:18Z")

</div>

When running `npm audit` with the latest node-red version (2.0.5) it cannot fix all issues:

```auto
> npm audit fix
[...]
up to date in 4.834s

76 packages are looking for funding
  run `npm fund` for details

fixed 0 of 3 vulnerabilities in 772 scanned packages
  3 vulnerabilities required manual review and could not be updated
>> npm audit
                                                                                
                       === npm audit security report ===                        
                                                                                
┌──────────────────────────────────────────────────────────────────────────────┐
│ Manual Review │
│ Some vulnerabilities require your attention to resolve │
│ │
│ Visit https://go.npm.me/audit-guide for additional guidance │
└──────────────────────────────────────────────────────────────────────────────┘
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ High │ Arbitrary File Creation/Overwrite via insufficient symlink │
│ │ protection due to directory cache poisoning using symbolic │
│ │ links │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ tar │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in │ >=4.4.16 <5.0.0 || >=5.0.8 <6.0.0 || >=6.1.7 │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ node-red │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ node-red > @node-red/runtime > @node-red/registry > tar │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ https://npmjs.com/advisories/1779 │
└───────────────┴──────────────────────────────────────────────────────────────┘
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ High │ Arbitrary File Creation/Overwrite via insufficient symlink │
│ │ protection due to directory cache poisoning using symbolic │
│ │ links │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ tar │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in │ >=4.4.18 <5.0.0 || >=5.0.10 <6.0.0 || >=6.1.9 │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ node-red │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ node-red > @node-red/runtime > @node-red/registry > tar │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ https://npmjs.com/advisories/1780 │
└───────────────┴──────────────────────────────────────────────────────────────┘
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ High │ Arbitrary File Creation/Overwrite on Windows via │
│ │ insufficient relative path sanitization │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ tar │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in │ >=4.4.18 <5.0.0 || >=5.0.10 <6.0.0 || >=6.1.9 │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ node-red │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ node-red > @node-red/runtime > @node-red/registry > tar │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ https://npmjs.com/advisories/1781 │
└───────────────┴──────────────────────────────────────────────────────────────┘
found 3 high severity vulnerabilities in 772 scanned packages
  3 vulnerabilities require manual review. See the full report for details.

```

How can I fix these high severity vulnerabilities?

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [2 September 2021 06:46 UTC](https://discourse.nodered.org/t/npm-audit-fails/50525/2 "2021-09-02T06:46:33Z")

</div>

We will be publishing new 1.x and 2.x releases today that address this.

---

<div class="post-metadata">

**Author:** ![augjoh](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/augjoh/32/26464_2.png) [@augjoh](https://discourse.nodered.org/u/augjoh)\
**Post date:** [4 September 2021 03:51 UTC](https://discourse.nodered.org/t/npm-audit-fails/50525/3 "2021-09-04T03:51:35Z")

</div>

Thanks for pushing an update so quickly. Can `npm audit` fix the upcoming security issues now?

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [4 September 2021 07:32 UTC](https://discourse.nodered.org/t/npm-audit-fails/50525/4 "2021-09-04T07:32:40Z")

</div>

No. You will need to install the new version of Node-RED in the usual manner.

---

<div class="post-metadata">

**Author:** ![augjoh](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/augjoh/32/26464_2.png) [@augjoh](https://discourse.nodered.org/u/augjoh)\
**Post date:** [5 September 2021 05:03 UTC](https://discourse.nodered.org/t/npm-audit-fails/50525/5 "2021-09-05T05:03:26Z")

</div>

It would be a great feature, if the user can update security related issues themselves. Why wait for a release of Node-RED, when a minor version of a dependency have to be updated, only?

---

<div class="post-metadata">

**Author:** ![dceejay](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/dceejay/32/38_2.png) [@dceejay](https://discourse.nodered.org/u/dceejay)\
**Post date:** [5 September 2021 06:18 UTC](https://discourse.nodered.org/t/npm-audit-fails/50525/6 "2021-09-05T06:18:44Z")

</div>

Yes, the user is free to manually fix things if they wish, but as the screenshot you posted shows , npm can't fix them automatically, and there is no way of telling if forcing the update will break something else, as usually the dependency is buried within some other dependency.

---

<div class="post-metadata">

**Author:** ![augjoh](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/augjoh/32/26464_2.png) [@augjoh](https://discourse.nodered.org/u/augjoh)\
**Post date:** [5 September 2021 09:27 UTC](https://discourse.nodered.org/t/npm-audit-fails/50525/7 "2021-09-05T09:27:03Z")

</div>

As long as Node-RED pins all versions and don't allow `npm` to update dependent packages "Compatible with version" (See [semver](https://github.com/npm/node-semver#versions)), the user won't be able to do so, I guess.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [6 September 2021 20:38 UTC](https://discourse.nodered.org/t/npm-audit-fails/50525/8 "2021-09-06T20:38:12Z")

</div>

I think that experience shows that forcing audit updates will often break things in a way that is pretty well impossible to debug.

---

<div class="post-metadata">

**Author:** ![augjoh](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/augjoh/32/26464_2.png) [@augjoh](https://discourse.nodered.org/u/augjoh)\
**Post date:** [18 September 2021 07:16 UTC](https://discourse.nodered.org/t/npm-audit-fails/50525/9 "2021-09-18T07:16:17Z")

</div>

I agree, that the packages should be locked somehow. But banning the user to update compatible versions does not contradict with it, from my perspective. Updating may break something, but running a version with known security flows is already broken.

---

<div class="post-metadata">

**Author:** ![dceejay](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/dceejay/32/38_2.png) [@dceejay](https://discourse.nodered.org/u/dceejay)\
**Post date:** [18 September 2021 07:39 UTC](https://discourse.nodered.org/t/npm-audit-fails/50525/10 "2021-09-18T07:39:57Z")

</div>

Luckily its all open source so you can update whatever you want as often as you want.

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [18 September 2021 09:08 UTC](https://discourse.nodered.org/t/npm-audit-fails/50525/11 "2021-09-18T09:08:39Z")

</div>

I think (though not certain) that npm audit fix may update to versions that are not consistent with the settings in package.json. It treats your instruction to fix it as permission to override package.json. That is why it may break things.

---

<div class="post-metadata">

**Author:** ![augjoh](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/augjoh/32/26464_2.png) [@augjoh](https://discourse.nodered.org/u/augjoh)\
**Post date:** [19 September 2021 04:35 UTC](https://discourse.nodered.org/t/npm-audit-fails/50525/12 "2021-09-19T04:35:53Z")

</div>

But it needs a deeper knowledge, if `package.json` does not allow updates.

---

<div class="post-metadata">

**Author:** ![dceejay](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/dceejay/32/38_2.png) [@dceejay](https://discourse.nodered.org/u/dceejay)\
**Post date:** [19 September 2021 07:08 UTC](https://discourse.nodered.org/t/npm-audit-fails/50525/13 "2021-09-19T07:08:43Z")

</div>

As does fixing the code when you randomly update packages to latest.

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [19 September 2021 07:45 UTC](https://discourse.nodered.org/t/npm-audit-fails/50525/14 "2021-09-19T07:45:36Z")

</div>

> [@augjoh](#):
>
> needs a deeper knowledge, if `package.json` does not allow updates

Can you explain what you mean by that?

---

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [19 September 2021 08:27 UTC](https://discourse.nodered.org/t/npm-audit-fails/50525/15 "2021-09-19T08:27:46Z")

</div>

I think what the op is saying node-red ships with exact semantic versions specified in the package deps and therefore doesn't permit any patch or minor updates without an audit fix or modifying package.json

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [19 September 2021 08:45 UTC](https://discourse.nodered.org/t/npm-audit-fails/50525/16 "2021-09-19T08:45:26Z")

</div>

Ah, yes, if talking specifically about node-red rather than other modules.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [19 September 2021 16:50 UTC](https://discourse.nodered.org/t/npm-audit-fails/50525/17 "2021-09-19T16:50:56Z")

</div>

Having played with Node.js for many years now, I can safely say that I would never allow the npm audit to "fix" anything. At least unless I really knew the thing it was fixing and what packages were relying on it.

No matter how hard you try maintain good semantic versioning, it is always prone to mistakes and often to interpretation as well.

I rely on GitHub extensions to tell me if any of my dependencies have problems and need updating and I grab the latest version of dependencies when I do a new version of my own nodes. Anything else is going to bite you in the nether regions at some inopportune moment and should be avoided.

---

<div class="post-metadata">

**Author:** ![augjoh](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/augjoh/32/26464_2.png) [@augjoh](https://discourse.nodered.org/u/augjoh)\
**Post date:** [2 October 2021 05:25 UTC](https://discourse.nodered.org/t/npm-audit-fails/50525/18 "2021-10-02T05:25:09Z")

</div>

I agree fully, running `npm audit fix` can break your software/nodes, especially when running unattended and automatically. On the other hand, if have to review every detected problem, your users will have a bad time, when your on vacation or tangled in other stuff.

If you update your dependencies (not matter how), you'll have to test the changes. After updating your dependencies, you could test your software with Github Actions (or antoher CI/CD tool) automatically. If your tests pass, your nodes are working. So from my point of view, an automated update process requires an automated testing step. If you have that, `npm audit fix` is a piece of cake.

Users of node-red need to test their flows, after updating node-red anyway. They could rely on the locked set set of modules (via `package-lock.json`) **and** have the ability to use `npm audit fix`. I see no reason why this feature is hold back from them.

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [2 October 2021 06:23 UTC](https://discourse.nodered.org/t/npm-audit-fails/50525/19 "2021-10-02T06:23:14Z")

</div>

Remember that node red makes use of many modules that are not under the control of the node red team. If one of those is updated and five minutes later a user runs audit fix then they would get that update before anyone has time to run any tests.

---

<div class="post-metadata">

**Author:** ![augjoh](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/augjoh/32/26464_2.png) [@augjoh](https://discourse.nodered.org/u/augjoh)\
**Post date:** [8 October 2021 14:06 UTC](https://discourse.nodered.org/t/npm-audit-fails/50525/20 "2021-10-08T14:06:04Z")

</div>

How to fix the following stuff?

```auto
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ High │ Incorrect Comparison in axios │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ axios │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in │ >=0.21.2 │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ node-red │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ node-red > node-red-admin > axios │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-cph5-m8f7-6c5x │
└───────────────┴──────────────────────────────────────────────────────────────┘

```

[Next page](https://discourse.nodered.org/t/npm-audit-fails/50525.md?page=2)
