Skip to content

react-scripts showing false critical vulnerabilities is ANNOYING  #3930

@jap99

Description

@jap99

Is there an existing issue for this?

  • I have searched the existing issues

Current Behavior

'npm audit' results in 10's, 100's of vulnerabilities, many / most being listed as critical.

Even though these false positive vulnerabilities are simply false positives, they're not only extremely annoying, but they will make it too difficult to identify anytime there is a real attack against the build toolchain because it will be hidden / buried in w/ all the false positives.

Please fix this ASAP.

Expected Behavior

Stop showing false positives; start with react-scripts.

Steps To Reproduce

Open multiple different react projects.
Each react project should have different versions of react, node, & other popular npm packages.
Do 'npm audit' & you'll see the issues.

Thank you.

Environment

No response

Metadata

Metadata

Assignees

No one assigned

    Labels

    Bugthing that needs fixingNeeds Triageneeds review for next stepsRelease 8.xwork is associated with a specific npm 8 release

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions