Some of them. npm audit checks every package your project uses against a database of known vulnerabilities, and an old project can easily show dozens. Many are in development tools that never reach your users. The ones in code that runs on your server or in visitors' browsers matter most. Run npm audit fix for the safe updates, test, then deal with the rest one at a time. Don't run npm audit fix --force without testing: it can jump packages to new major versions that break the app.
What's the problem
You install the project and npm prints "found 47 vulnerabilities (12 moderate, 30 high, 5 critical)". It sounds alarming, and you can't tell whether it means the app is unsafe to launch or just old.
Why it happens
- Your app is mostly other people's code. A typical JavaScript project pulls in hundreds of packages, each of which pulls in more. A vulnerability anywhere in that tree is reported.
- Projects sit, vulnerabilities get found. Every month a project goes without updates, more of its packages get published advisories. OWASP lists software supply chain failures third in its Top 10.
- Severity isn't the same as risk to you. A "critical" flaw in a tool that only runs on a developer's machine during the build isn't the same as one in the code that handles your users' logins.
- Some fixes need breaking changes. When the fix requires a new major version of something your project depends on directly,
npm audit fixwon't apply it without--force.
How to fix it
- Run
npm audit fix(without--force). It applies updates that stay within the version ranges your project allows. - Test the app, especially logins, payments and the main flows.
- See what's left that actually ships:
npm audit --omit=devleaves out development-only packages. - For each remaining issue, read the advisory. Does your app use the affected feature? Is there a patched version? Update those packages deliberately, one at a time, testing between each.
- Use
--forceonly on a branch, with tests, and expect to fix what breaks. - Keep it from piling up again: update dependencies regularly, rather than once every few years.
When to call Preventionlabs
If a few updates clear the serious ones, you're in good shape. Call us when the fixes cascade: one major upgrade forces another, the build breaks, and the project is stuck years behind. A resurrection delivers an app that builds and starts on maintained dependencies, and dependency vulnerabilities are on the MVP-level protection checklist.
Submit your project for a free assessmentFree assessment. $10,000 AUD flat to get it live, only if we take it on and you go ahead.
Sources
- npm: npm auditofficial docs
The audit command submits a description of the dependencies configured in your project to your default registry and asks for a report of known vulnerabilities.
- npm: npm auditofficial docs
Note that some vulnerabilities cannot be fixed automatically and will require manual intervention or review.
- npm: npm auditofficial docs
If the chain of metavulnerabilities extends all the way to the root project, and it cannot be updated without changing its dependency ranges, then npm audit fix will require the --force option to apply the remediation.
- OWASP: OWASP Top 10:2025security standards body
A03:2025 - Software Supply Chain Failures