When I update laravel-mix and npm-audit I found this warnings:

Having the same issue
โโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ High โ Denial of Service โ
โโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ Package โ http-proxy โ
โโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ Patched in โ No patch available โ
โโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ Dependency of โ laravel-mix [dev] โ
โโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ Path โ laravel-mix > webpack-dev-server > http-proxy-middleware > โ
โ โ http-proxy โ
โโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ More info โ https://npmjs.com/advisories/1486 โ
โโโโโโโโโโโโโโโโโดโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ Low โ Prototype Pollution โ
โโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ Package โ yargs-parser โ
โโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ Patched in โ >=13.1.2 <14.0.0 || >=15.0.1 <16.0.0 || >=18.1.2 โ
โโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ Dependency of โ laravel-mix [dev] โ
โโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ Path โ laravel-mix > yargs > yargs-parser โ
โโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ More info โ https://npmjs.com/advisories/1500 โ
โโโโโโโโโโโโโโโโโดโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
I have the same issue about NPM Vulnerability from NPM Audit
=== npm audit security report ===
Low Prototype Pollution
Package minimist
Dependency of laravel-mix
Path laravel-mix > webpack-cli > @webpack-cli/init >
@webpack-cli/generators > webpack > terser-webpack-plugin >
cacache > mkdirp > minimist
More info https://npmjs.com/advisories/1179
Manual Review
Some vulnerabilities require your attention to resolve
Visit https://go.npm.me/audit-guide for additional guidance
Low Prototype Pollution
Package minimist
Patched in >=0.2.1 <1.0.0 || >=1.2.3
Dependency of laravel-mix
Path laravel-mix > webpack-cli > @webpack-cli/init >
@webpack-cli/generators > glob-all > yargs > minimist
More info https://npmjs.com/advisories/1179
Low Prototype Pollution
Package minimist
Patched in >=0.2.1 <1.0.0 || >=1.2.3
Dependency of laravel-mix
Path laravel-mix > webpack-cli > @webpack-cli/init >
@webpack-cli/generators > mkdirp > minimist
More info https://npmjs.com/advisories/1179
High Denial of Service
Package http-proxy
Patched in No patch available
Dependency of laravel-mix
Path laravel-mix > webpack-cli > @webpack-cli/init >
@webpack-cli/generators > webpack-dev-server >
http-proxy-middleware > http-proxy
More info https://npmjs.com/advisories/1486
High Denial of Service
Package http-proxy
Patched in No patch available
Dependency of laravel-mix
Path laravel-mix > webpack-dev-server > http-proxy-middleware >
http-proxy
More info https://npmjs.com/advisories/1486
Low Prototype Pollution
Package yargs-parser
Patched in >=13.1.2 <14.0.0 || >=15.0.1 <16.0.0 || >=18.1.2
Dependency of laravel-mix
Path laravel-mix > webpack-cli > @webpack-cli/init >
@webpack-cli/generators > webpack-dev-server > yargs >
yargs-parser
More info https://npmjs.com/advisories/1500
Facing the same issue, any update on the fix?
same here
Path โ laravel-mix > yargs > yargs-parser
found 1 low severity vulnerability
while of course any "vulnerability" should be fixed, in my experience so far most of the things flagged by npm audit arent really relevant when you are just using webpack.
eg the original high severity issue that this issue was raised for, if you actually look at the message it is saying there is a dependency of webpack dev server that makes it vulnerable to denial of service attacks. unless you are running webpack dev server in production then that is no issue.
if you were running a node server in production and it was using that sane dependency then it would be more important to fix
Naturally same issue here. Even if I install separate yargs@19 laravel-mix does not use it. :/
It would be great if somebody would update the dependencies of the package.
I wouldn't mind if I was building projects for myself with deprecated or vulnerable packages, but a client is always right and if it said he doesn't want vulnerable packages, devs have to obey.
This has been fixed with the release of 5.0.5 which updates yargs to v15 :)
Most helpful comment
This has been fixed with the release of
5.0.5which updatesyargsto v15 :)