FG
🛠️ Developer ToolsMicrosoft

[BUG] npm audit fix doesn't work

Freshover 3 years ago
Mar 14, 20260 views
Confidence Score79%
79%

Problem

Is there an existing issue for this? - [X] I have searched the existing issues Current Behavior In my project, when running `npm audit`, one of the reported vulnerable packages is listed with the message “fix available via `npm audit fix`”, but running `npm audit fix` doesn’t lead to any updated packages and the exact same output as from the earlier run of `npm audit` is logged. This occurs on https://github.com/kleinfreund/vue-accessible-color-picker/commit/35bec0e751abad872de79657053cb8de07321faa. Which dependency from my package.json file is actually the vulnerable one I cannot tell with the new output of `npm audit` in npm 7. This is what the output looks like: [code block] Expected Behavior When seeing a message with the clear instruction “fix available via `npm audit fix`”, I expect this to be truthful and `npm audit fix` to always produce a changed package-lock.json file. Steps To Reproduce 1. Run `git clone https://github.com/kleinfreund/vue-accessible-color-picker.git` 2. Run `git checkout 35bec0e751abad872de79657053cb8de07321faa` to checkout the commit on the project’s `main` branch at the time of writing this. 3. Run `npm install` 4. Run `npm audit`. ~Observe how currently this includes an entry with the message “fix available via `npm audit fix`”.~ For this particular advisory, this is no longer the case, unfortunately. 5. Run `npm audit fix` Environment - OS: Ubuntu 20.04 - Node: v14.17.1 - npm: 7.19.0

Unverified for your environment

Select your OS to check compatibility.

1 Fix

Canonical Fix
High Confidence Fix
78% confidence100% success rate6 verificationsLast verified Mar 14, 2026

Solution: [BUG] npm audit fix doesn't work

Low Risk

Same issue here in my project (https://github.com/trickfilm400/vantage-node), Troubleshooting steps tried: - deleting package-lock.json - deleting node_modules/ folder this did not helped in any way Environment: - Windows 10 - npm 7.19.0 - node v14.17.0 Screenshot of console output for more information if needed

78

Trust Score

6 verifications

100% success
  1. 1

    Same issue here in my project (https://github.com/trickfilm400/vantage-node),

    Troubleshooting steps tried: - deleting package-lock.json - deleting node_modules/ folder

  2. 2

    Environment:

    - Windows 10 - npm 7.19.0 - node v14.17.0

  3. 3

    Screenshot of console output for more information if needed

    Screenshot of console output for more information if needed

Validation

Resolved in npm/cli GitHub issue #3472. Community reactions: 15 upvotes.

Verification Summary

Worked: 6
Partial: 1
Last verified Mar 14, 2026

Sign in to verify this fix

Environment

Submitted by

AC

Alex Chen

2450 rep

Tags

npmpackage-managernodejsrelease-8.xbugpriority-2