-
Notifications
You must be signed in to change notification settings - Fork 3.3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[BUG] npm audit not finding vulnerabilities #3338
Comments
are you still seeing this issue? can you try updating npm with i just tested by installing my |
@nlf thanks for the response. My issue is not specific on issue 1745 but more general than this. I always have sync issues between my local builds and CI. Every time one sees an issue several days before the other one. In this case, the CI reported 1745 but for several days my local machine didn't report it. Now, after a week, my local npm finds 1745. But there are some cases that my local machine finds issues before our CI - in general, different machines see different audits. It takes several days until both machines report the same issues. Do you use some cache or something? How can I see immediately same results in different machines without waiting few days until they sync? |
@hrazmsft yes, audit does in fact has a cache layer in order to improve performance to what otherwise can be a very costly operation. You can dig more into the internals of the I'm going to leave this issue open as it does seem to warrant a little more digging from our part. Would appreciate any extra info that can be provided, is it still happening with current versions of the npm cli ( |
@ruyadorno thank you! Is there any way to skip the cache locally? For example if the CI finds a vulnerability I want to see and fix it with |
Is there an existing issue for this?
Current Behavior
I have CI pipeline that checks regularly for security issues in the npm packages. For example, it reports about https://www.npmjs.com/advisories/1745.
I do have the infected package in my local machine:

Although in the local machine it doesn't see any high severity vulnerabilities:

And not finding the 1745 issue at all...
Expected Behavior
All security issues (especially high severity vulnerabilities) should appear immediately!
Steps To Reproduce
npm audit
Environment
The text was updated successfully, but these errors were encountered: