Skip to content

[BUG] npm audit does not show the package from package.json that depends on the vulnerable package #7443

Description

@dandv

Is there an existing issue for this?

  • I have searched the existing issues

This issue exists in the latest npm version

  • I am using the latest npm

Current Behavior

npm audit does not output which of the packages from the package.json dependencies depends on the detected vulnerable package(s).

Expected Behavior

npm should tell me which of the packages I'm using depend(s) on the vulnerable package(s), so that I can update or replace it/them.

Steps To Reproduce

  1. git clone https://github.com/dandv/npm-audit-bug.git && cd npm-audit-bug
  2. npm install
  3. npm audit
  4. Notice the output doesn't mention which of the user's packages from package.json depends on the vulnerable package.

image

Environment

  • npm: 10.6.0
  • Node.js: 18.19.0
  • OS Name: Fedora Linux 38
  • npm config:
; "global" config from /etc/npmrc

; prefix = "/usr/local" ; overridden by user
python = "/usr/bin/python3" 

; "user" config from /home/dandv/.npmrc

prefix = "/home/dandv/.local" 

; node bin location = /usr/bin/node-18
; node version = v18.19.0
; npm local prefix = /home/dandv/prg/npm-audit-bug
; npm version = 10.6.0
; cwd = /home/dandv/prg/npm-audit-bug
; HOME = /home/dandv
; Run `npm config ls -l` to show all defaults.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Bugthing that needs fixingPriority 2secondary priority issue

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions