user@midas:~/saito-lite-rust$ npm install npm warn EBADENGINE Unsupported engine { npm warn EBADENGINE package: 'glob@11.0.0', npm warn EBADENGINE required: { node: '20 || >=22' }, npm warn EBADENGINE current: { node: 'v18.20.4', npm: '10.7.0' } npm warn EBADENGINE } npm warn EBADENGINE Unsupported engine { npm warn EBADENGINE package: 'minimatch@10.0.1', npm warn EBADENGINE required: { node: '20 || >=22' }, npm warn EBADENGINE current: { node: 'v18.20.4', npm: '10.7.0' } npm warn EBADENGINE } npm warn EBADENGINE Unsupported engine { npm warn EBADENGINE package: 'jackspeak@4.0.2', npm warn EBADENGINE required: { node: '20 || >=22' }, npm warn EBADENGINE current: { node: 'v18.20.4', npm: '10.7.0' } npm warn EBADENGINE } npm warn EBADENGINE Unsupported engine { npm warn EBADENGINE package: 'path-scurry@2.0.0', npm warn EBADENGINE required: { node: '20 || >=22' }, npm warn EBADENGINE current: { node: 'v18.20.4', npm: '10.7.0' } npm warn EBADENGINE } npm warn EBADENGINE Unsupported engine { npm warn EBADENGINE package: 'lru-cache@11.0.1', npm warn EBADENGINE required: { node: '20 || >=22' }, npm warn EBADENGINE current: { node: 'v18.20.4', npm: '10.7.0' } npm warn EBADENGINE } npm warn deprecated inflight@1.0.6: This module is not supported, and leaks memory. Do not use it. Check out lru-cache if you want a good and tested way to coalesce async requests by a key value, which is much more comprehensive and powerful. npm warn deprecated glob@7.2.3: Glob versions prior to v9 are no longer supported npm warn deprecated glob@7.2.3: Glob versions prior to v9 are no longer supported npm warn deprecated glob@7.2.3: Glob versions prior to v9 are no longer supported npm warn deprecated glob@7.2.3: Glob versions prior to v9 are no longer supported npm warn deprecated glob@7.2.3: Glob versions prior to v9 are no longer supported npm warn deprecated glob@7.2.3: Glob versions prior to v9 are no longer supported npm warn deprecated glob@7.2.3: Glob versions prior to v9 are no longer supported npm warn deprecated glob@7.2.3: Glob versions prior to v9 are no longer supported npm warn deprecated glob@7.2.3: Glob versions prior to v9 are no longer supported npm warn deprecated glob@7.2.3: Glob versions prior to v9 are no longer supported npm warn deprecated glob@7.2.3: Glob versions prior to v9 are no longer supported npm warn deprecated glob@7.2.3: Glob versions prior to v9 are no longer supported added 1602 packages, and audited 1603 packages in 28s 146 packages are looking for funding run `npm fund` for details 42 vulnerabilities (6 low, 19 moderate, 15 high, 2 critical) To address issues that do not require attention, run: npm audit fix To address all issues possible (including breaking changes), run: npm audit fix --force Some issues need review, and may require choosing a different dependency. Run `npm audit` for details. user@midas:~/saito-lite-rust$ npm audit fix npm warn EBADENGINE Unsupported engine { npm warn EBADENGINE package: 'glob@11.0.0', npm warn EBADENGINE required: { node: '20 || >=22' }, npm warn EBADENGINE current: { node: 'v18.20.4', npm: '10.7.0' } npm warn EBADENGINE } npm warn EBADENGINE Unsupported engine { npm warn EBADENGINE package: 'minimatch@10.0.1', npm warn EBADENGINE required: { node: '20 || >=22' }, npm warn EBADENGINE current: { node: 'v18.20.4', npm: '10.7.0' } npm warn EBADENGINE } npm warn EBADENGINE Unsupported engine { npm warn EBADENGINE package: 'jackspeak@4.0.2', npm warn EBADENGINE required: { node: '20 || >=22' }, npm warn EBADENGINE current: { node: 'v18.20.4', npm: '10.7.0' } npm warn EBADENGINE } npm warn EBADENGINE Unsupported engine { npm warn EBADENGINE package: 'path-scurry@2.0.0', npm warn EBADENGINE required: { node: '20 || >=22' }, npm warn EBADENGINE current: { node: 'v18.20.4', npm: '10.7.0' } npm warn EBADENGINE } npm warn EBADENGINE Unsupported engine { npm warn EBADENGINE package: 'lru-cache@11.0.1', npm warn EBADENGINE required: { node: '20 || >=22' }, npm warn EBADENGINE current: { node: 'v18.20.4', npm: '10.7.0' } npm warn EBADENGINE } added 13 packages, removed 5 packages, changed 50 packages, and audited 1611 packages in 15s 150 packages are looking for funding run `npm fund` for details # npm audit report axios 0.8.1 - 0.27.2 Severity: moderate Axios Cross-Site Request Forgery Vulnerability - https://github.com/advisories/GHSA-wf5p-g6vw-rhxx No fix available node_modules/@elrondnetwork/erdjs-network-providers/node_modules/axios node_modules/axios @elrondnetwork/erdjs-network-providers * Depends on vulnerable versions of axios node_modules/@elrondnetwork/erdjs-network-providers body-parser <1.20.3 Severity: high body-parser vulnerable to denial of service when url encoding is enabled - https://github.com/advisories/GHSA-qwcr-r2fm-qrc7 No fix available node_modules/express/node_modules/body-parser express <=4.21.0 || 5.0.0-alpha.1 - 5.0.0 Depends on vulnerable versions of body-parser Depends on vulnerable versions of cookie Depends on vulnerable versions of path-to-regexp Depends on vulnerable versions of send Depends on vulnerable versions of serve-static node_modules/express saito-js * Depends on vulnerable versions of express node_modules/saito-js cookie <0.7.0 cookie accepts cookie name, path, and domain with out of bounds characters - https://github.com/advisories/GHSA-pxg6-pf52-xh8x fix available via `npm audit fix --force` Will install socket.io@4.8.1, which is a breaking change node_modules/cookie node_modules/engine.io/node_modules/cookie engine.io 1.8.0 - 6.6.1 Depends on vulnerable versions of cookie Depends on vulnerable versions of debug node_modules/engine.io socket.io 2.2.0 - 3.0.4 Depends on vulnerable versions of debug Depends on vulnerable versions of engine.io Depends on vulnerable versions of socket.io-parser node_modules/socket.io debug 4.0.0 - 4.3.0 Regular Expression Denial of Service in debug - https://github.com/advisories/GHSA-gxpj-cx7g-858c fix available via `npm audit fix --force` Will install socket.io@4.8.1, which is a breaking change node_modules/engine.io/node_modules/debug node_modules/socket.io-parser/node_modules/debug node_modules/socket.io/node_modules/debug socket.io-parser 3.4.0 - 4.0.2 Depends on vulnerable versions of debug node_modules/socket.io-parser ip * Severity: high ip SSRF improper categorization in isPublic - https://github.com/advisories/GHSA-2p57-rm9w-gvfp fix available via `npm audit fix --force` Will install stun@1.1.0, which is a breaking change node_modules/ip node_modules/stun/node_modules/ip socks 1.0.0 - 2.7.1 Depends on vulnerable versions of ip node_modules/socks stun <=0.0.3 || >=1.2.0 Depends on vulnerable versions of ip node_modules/stun log4js <6.4.0 Severity: moderate Incorrect Default Permissions in log4js - https://github.com/advisories/GHSA-82v2-mx6x-wq7q No fix available node_modules/log4js node-turn * Depends on vulnerable versions of log4js node_modules/node-turn path-to-regexp <0.1.10 Severity: high path-to-regexp outputs backtracking regular expressions - https://github.com/advisories/GHSA-9wv6-86v2-598j No fix available node_modules/path-to-regexp phin <3.7.1 Severity: moderate phin may include sensitive headers in subsequent requests after redirect - https://github.com/advisories/GHSA-x565-32qp-m3vf fix available via `npm audit fix --force` Will install jimp@1.6.0, which is a breaking change node_modules/phin @jimp/core <=0.21.4--canary.1163.d07ed6254d130e2995d24101e93427ec091016e6.0 Depends on vulnerable versions of phin node_modules/@jimp/core @jimp/custom <=0.21.4--canary.1163.d07ed6254d130e2995d24101e93427ec091016e6.0 Depends on vulnerable versions of @jimp/core node_modules/@jimp/custom jimp 0.3.6-alpha.5 - 0.21.4--canary.1163.d07ed6254d130e2995d24101e93427ec091016e6.0 Depends on vulnerable versions of @jimp/custom node_modules/jimp protobufjs 6.10.0 - 6.11.3 Severity: critical protobufjs Prototype Pollution vulnerability - https://github.com/advisories/GHSA-h755-8qp9-cq85 fix available via `npm audit fix --force` Will install @elrondnetwork/erdjs@5.0.1, which is a breaking change node_modules/protobufjs @elrondnetwork/erdjs >=6.0.0 Depends on vulnerable versions of protobufjs node_modules/@elrondnetwork/erdjs send <0.19.0 Severity: moderate send vulnerable to template injection that can lead to XSS - https://github.com/advisories/GHSA-m6fv-jmcg-4jfg No fix available node_modules/send serve-static <=1.16.0 Depends on vulnerable versions of send node_modules/serve-static taffydb * Severity: high TaffyDB can allow access to any data items in the DB - https://github.com/advisories/GHSA-mxhp-79qh-mcx6 fix available via `npm audit fix --force` Will install jsdoc@4.0.4, which is a breaking change node_modules/taffydb jsdoc 3.2.0-dev - 3.6.11 Depends on vulnerable versions of taffydb node_modules/jsdoc 26 vulnerabilities (5 low, 11 moderate, 8 high, 2 critical) To address issues that do not require attention, run: npm audit fix To address all issues possible (including breaking changes), run: npm audit fix --force Some issues need review, and may require choosing a different dependency.