Skip to content

npm audit would lead to downgrade to another vulnerable version #1628

Description

@lexibelseibert

CLI Version

8.13.0

Node.js Version

v26.7.0

Operating System

Linux

Description

I ran npm audit and it suggests downgrading to an older version.

Steps to Reproduce

  1. From a project containing the mentioned hs version, run npm audit
  2. Review the suggestions

Expected Behavior

I expected a list of packages to upgrade.

Screenshots

No response

Debug Output

No response

Additional Context

Instead, I get a bunch of packages that say this:

Will install @hubspot/cli@7.0.2, which is a breaking change.

I'm not sure but this might be related to #1554 as well. Feel free to close if it's a duplicate, but then please advise how to proceed. We can't afford to keep high and critical vulnerabilities in our code.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions