Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

The default Vue template has 19 high severity vulnerabilities and cannot build or serve #2504

Open
pmorch opened this issue May 4, 2023 · 0 comments

Comments

@pmorch
Copy link

pmorch commented May 4, 2023

Description of Bug

Creating a new Vue project from the dashboard creates an outdated Vue project. Instead I expect to see a new project that installs without vulnerabilities and both builds and serves.

Details

$ npm install
npm WARN EBADENGINE Unsupported engine {
npm WARN EBADENGINE   package: '@achrinza/node-ipc@9.2.2',
npm WARN EBADENGINE   required: { node: '8 || 10 || 12 || 14 || 16 || 17' },
npm WARN EBADENGINE   current: { node: 'v18.13.0', npm: '9.2.0' }
npm WARN EBADENGINE }
npm WARN deprecated stable@0.1.8: Modern JS already guarantees Array#sort() is a stable sort, so this library is deprecated. See the compatibility table on MDN: https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/Array/sort#browser_compatibility
npm WARN deprecated source-map-url@0.4.1: See https://github.com/lydell/source-map-url#deprecated
npm WARN deprecated @hapi/topo@3.1.6: This version has been deprecated and is no longer supported or maintained
npm WARN deprecated @hapi/bourne@1.3.2: This version has been deprecated and is no longer supported or maintained
npm WARN deprecated urix@0.1.0: Please see https://github.com/lydell/urix#deprecated
npm WARN deprecated har-validator@5.1.5: this library is no longer supported
npm WARN deprecated eslint-loader@2.2.1: This loader has been deprecated. Please use eslint-webpack-plugin
npm WARN deprecated resolve-url@0.2.1: https://github.com/lydell/resolve-url#deprecated
npm WARN deprecated source-map-resolve@0.5.3: See https://github.com/lydell/source-map-resolve#deprecated
npm WARN deprecated sourcemap-codec@1.4.8: Please use @jridgewell/sourcemap-codec instead
npm WARN deprecated chokidar@2.1.8: Chokidar 2 does not receive security updates since 2019. Upgrade to chokidar 3 with 15x fewer dependencies
npm WARN deprecated chokidar@2.1.8: Chokidar 2 does not receive security updates since 2019. Upgrade to chokidar 3 with 15x fewer dependencies
npm WARN deprecated querystring@0.2.0: The querystring API is considered Legacy. new code should use the URLSearchParams API instead.
npm WARN deprecated html-webpack-plugin@3.2.0: 3.x is no longer supported
npm WARN deprecated babel-eslint@10.1.0: babel-eslint is now @babel/eslint-parser. This package will no longer receive updates.
npm WARN deprecated @hapi/address@2.1.4: Moved to 'npm install @sideway/address'
npm WARN deprecated uuid@3.4.0: Please upgrade  to version 7 or higher.  Older versions may use Math.random() in certain circumstances, which is known to be problematic.  See https://v8.dev/blog/math-random for details.
npm WARN deprecated request@2.88.2: request has been deprecated, see https://github.com/request/request/issues/3142
npm WARN deprecated @hapi/hoek@8.5.1: This version has been deprecated and is no longer supported or maintained
npm WARN deprecated @hapi/joi@15.1.1: Switch to 'npm install joi'
npm WARN deprecated svgo@1.3.2: This SVGO version is no longer supported. Upgrade to v2.x.x.

added 1388 packages, and audited 1389 packages in 1m

118 packages are looking for funding
  run `npm fund` for details

30 vulnerabilities (1 low, 5 moderate, 19 high, 5 critical)

To address issues that do not require attention, run:
  npm audit fix

To address all issues (including breaking changes), run:
  npm audit fix --force

Run `npm audit` for details.
$ npm run build 

> sb-vue@0.1.0 build
> vue-cli-service build


⠹  Building for production...Error: error:0308010C:digital envelope routines::unsupported
    at new Hash (node:internal/crypto/hash:71:19)
    at Object.createHash (node:crypto:133:10)
    at module.exports (/home/pmorch/Downloads/ost/node_modules/webpack/lib/util/createHash.js:135:53)
    at NormalModule._initBuildHash (/home/pmorch/Downloads/ost/node_modules/webpack/lib/NormalModule.js:417:16)
    at handleParseError (/home/pmorch/Downloads/ost/node_modules/webpack/lib/NormalModule.js:471:10)
    at /home/pmorch/Downloads/ost/node_modules/webpack/lib/NormalModule.js:503:5
    at /home/pmorch/Downloads/ost/node_modules/webpack/lib/NormalModule.js:358:12
    at /home/pmorch/Downloads/ost/node_modules/loader-runner/lib/LoaderRunner.js:373:3
    at iterateNormalLoaders (/home/pmorch/Downloads/ost/node_modules/loader-runner/lib/LoaderRunner.js:214:10)
    at iterateNormalLoaders (/home/pmorch/Downloads/ost/node_modules/loader-runner/lib/LoaderRunner.js:221:10)
    at /home/pmorch/Downloads/ost/node_modules/loader-runner/lib/LoaderRunner.js:236:3
    at runSyncOrAsync (/home/pmorch/Downloads/ost/node_modules/loader-runner/lib/LoaderRunner.js:130:11)
    at iterateNormalLoaders (/home/pmorch/Downloads/ost/node_modules/loader-runner/lib/LoaderRunner.js:232:2)
    at Array.<anonymous> (/home/pmorch/Downloads/ost/node_modules/loader-runner/lib/LoaderRunner.js:205:4)
    at Storage.finished (/home/pmorch/Downloads/ost/node_modules/enhanced-resolve/lib/CachedInputFileSystem.js:55:16)
    at /home/pmorch/Downloads/ost/node_modules/enhanced-resolve/lib/CachedInputFileSystem.js:91:9
⠦  Building for production.../home/pmorch/Downloads/ost/node_modules/loader-runner/lib/LoaderRunner.js:114
			throw e;
			^

Error: error:0308010C:digital envelope routines::unsupported
    at new Hash (node:internal/crypto/hash:71:19)
    at Object.createHash (node:crypto:133:10)
    at module.exports (/home/pmorch/Downloads/ost/node_modules/webpack/lib/util/createHash.js:135:53)
    at NormalModule._initBuildHash (/home/pmorch/Downloads/ost/node_modules/webpack/lib/NormalModule.js:417:16)
    at /home/pmorch/Downloads/ost/node_modules/webpack/lib/NormalModule.js:452:10
    at /home/pmorch/Downloads/ost/node_modules/webpack/lib/NormalModule.js:323:13
    at /home/pmorch/Downloads/ost/node_modules/loader-runner/lib/LoaderRunner.js:367:11
    at /home/pmorch/Downloads/ost/node_modules/loader-runner/lib/LoaderRunner.js:182:20
    at context.callback (/home/pmorch/Downloads/ost/node_modules/loader-runner/lib/LoaderRunner.js:111:13)
    at Object.callback (/home/pmorch/Downloads/ost/node_modules/thread-loader/dist/index.js:46:7)
    at done (/home/pmorch/Downloads/ost/node_modules/neo-async/async.js:8069:18)
    at callback (/home/pmorch/Downloads/ost/node_modules/thread-loader/dist/WorkerPool.js:178:19)
    at /home/pmorch/Downloads/ost/node_modules/thread-loader/dist/WorkerPool.js:204:15
    at mapSeries (/home/pmorch/Downloads/ost/node_modules/neo-async/async.js:3625:14)
    at PoolWorker.onWorkerMessage (/home/pmorch/Downloads/ost/node_modules/thread-loader/dist/WorkerPool.js:170:35)
    at /home/pmorch/Downloads/ost/node_modules/thread-loader/dist/WorkerPool.js:152:14 {
  opensslErrorStack: [ 'error:03000086:digital envelope routines::initialization error' ],
  library: 'digital envelope routines',
  reason: 'unsupported',
  code: 'ERR_OSSL_EVP_UNSUPPORTED'
}

Node.js v18.13.0
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant