f***@163.com
f***@163.com
  • 发布:2025-09-05 14:37
  • 更新:2025-09-05 14:51
  • 阅读:32

jsrsasign7.2.2安全问题

分类:uni-app

依赖如下
"@dcloudio/uni-app": "^2.0.2-4070620250821001",
"@dcloudio/uni-app-plus": "^2.0.2-4070620250821001",
"@dcloudio/uni-h5": "^2.0.2-4070620250821001",
"@dcloudio/uni-i18n": "^2.0.2-4070620250821001",
"@dcloudio/uni-mp-360": "^2.0.2-4070620250821001",
"@dcloudio/uni-mp-alipay": "^2.0.2-4070620250821001",
"@dcloudio/uni-mp-baidu": "^2.0.2-4070620250821001",
"@dcloudio/uni-mp-harmony": "^2.0.2-4070620250821001",
"@dcloudio/uni-mp-jd": "^2.0.2-4070620250821001",
"@dcloudio/uni-mp-kuaishou": "^2.0.2-4070620250821001",
"@dcloudio/uni-mp-lark": "^2.0.2-4070620250821001",
"@dcloudio/uni-mp-qq": "^2.0.2-4070620250821001",
"@dcloudio/uni-mp-toutiao": "^2.0.2-4070620250821001",
"@dcloudio/uni-mp-vue": "^2.0.2-4070620250821001",
"@dcloudio/uni-mp-weixin": "^2.0.2-4070620250821001",
"@dcloudio/uni-mp-xhs": "^2.0.2-4070620250821001",
"@dcloudio/uni-quickapp-native": "^2.0.2-4070620250821001",
"@dcloudio/uni-quickapp-webview": "^2.0.2-4070620250821001",
"@dcloudio/uni-stacktracey": "^2.0.2-4070620250821001",
"@dcloudio/uni-stat": "^2.0.2-4070620250821001"

@dcloudio/uni-quickapp-native库的子依赖jsrsasign7.2.2,被甲方公司安全检测出有漏洞问题,请问该如何修复呢。

安全公司推荐版本为jsrsasign:11.0.0

2025-09-05 14:37 负责人:无 分享
已邀请:
DCloud_UNI_JBB

DCloud_UNI_JBB

你开发快应用吗?不开发的话可以考虑移除 quickapp 相关的依赖

要回复问题请先登录注册