原标题:I can t install pm install react-bootstrap bootstrap in Ubuntu. I m getting a lot of errors in the terminal

I m new to the npm world and I apologize for the question. I would like to use Bootstrap with React (React-Bootstrap). I m having trouble installing npm install react-bootstrap bootstrap in Ubuntu. After starting the npx command create-react-app react-bootstrap-app, i enter the folder and start the npm:

install react-bootstrap bootstrap --save command

After running npm install react-bootstrap bootstrap --save, i get these:

After running npm install react-bootstrap bootstrap --save, i get these:

added 19 packages, and audited 1574 packages in 9s

256 packages are looking for funding
  run `npm fund` for details

8 vulnerabilities (2 moderate, 6 high)

To address all issues (including breaking changes), run:
  npm audit fix --force

Run `npm audit` for details.

After running npm audit --force, i get these errors and many npm WARN deprecated:

npm WARN using --force Recommended protections disabled.
npm WARN audit Updating react-scripts to 3.0.1, which is a SemVer major change.

added 761 packages, removed 565 packages, changed 374 packages, and audited 1770 packages in 2m

115 packages are looking for funding
  run `npm fund` for details

# npm audit report

ansi-html  <0.0.8
Severity: high
Uncontrolled Resource Consumption in ansi-html - https://github.com/advisories/GHSA-whgm-jr23-g3j9
fix available via `npm audit fix --force`
Will install [email protected], which is a breaking change
  webpack-dev-server  2.0.0-beta - 4.7.2
  Depends on vulnerable versions of ansi-html
  Depends on vulnerable versions of chokidar
  Depends on vulnerable versions of selfsigned
  Depends on vulnerable versions of sockjs
  Depends on vulnerable versions of yargs
    react-scripts  >=0.1.0
    Depends on vulnerable versions of @svgr/webpack
    Depends on vulnerable versions of @typescript-eslint/eslint-plugin
    Depends on vulnerable versions of @typescript-eslint/parser
    Depends on vulnerable versions of css-loader
    Depends on vulnerable versions of eslint-config-react-app
    Depends on vulnerable versions of jest
    Depends on vulnerable versions of jest-environment-jsdom-fourteen
    Depends on vulnerable versions of optimize-css-assets-webpack-plugin
    Depends on vulnerable versions of postcss-flexbugs-fixes
    Depends on vulnerable versions of postcss-loader
    Depends on vulnerable versions of postcss-normalize
    Depends on vulnerable versions of postcss-preset-env
    Depends on vulnerable versions of postcss-safe-parser
    Depends on vulnerable versions of react-dev-utils
    Depends on vulnerable versions of semver
    Depends on vulnerable versions of terser-webpack-plugin
    Depends on vulnerable versions of webpack-dev-server

browserslist  4.0.0 - 4.16.4
Severity: moderate
Regular Expression Denial of Service in browserslist - https://github.com/advisories/GHSA-w8qv-6jwh-64r5
fix available via `npm audit fix --force`
Will install [email protected], which is a breaking change
  react-dev-utils  0.4.0 - 12.0.0-next.60
  Depends on vulnerable versions of browserslist
  Depends on vulnerable versions of fork-ts-checker-webpack-plugin
  Depends on vulnerable versions of globby
  Depends on vulnerable versions of immer
  Depends on vulnerable versions of loader-utils
  Depends on vulnerable versions of recursive-readdir
  Depends on vulnerable versions of shell-quote

glob-parent  <5.1.2
Severity: high
glob-parent vulnerable to Regular Expression Denial of Service in enclosure regex - https://github.com/advisories/GHSA-ww39-953v-wcq6
fix available via `npm audit fix --force`
Will install [email protected], which is a breaking change
  chokidar  1.0.0-rc1 - 2.1.8
  Depends on vulnerable versions of glob-parent
    fork-ts-checker-webpack-plugin  <=3.1.0
    Depends on vulnerable versions of chokidar
    watchpack-chokidar2  *
    Depends on vulnerable versions of chokidar
      watchpack  1.7.2 - 1.7.5
      Depends on vulnerable versions of watchpack-chokidar2
  fast-glob  <=2.2.7
  Depends on vulnerable versions of glob-parent
    globby  8.0.0 - 9.2.0
    Depends on vulnerable versions of fast-glob

The problem comes from create-react-app (namely react-scripts), instead of the command of npm install react-bootstrap bootstrap --save.

@Phil s comments has its Value, creact-app is a framework that helps You set up a web application in a severalpoints, but it deprecated around 3 years before (source: create-react-appthub Gi).

请通过<代码>npm 审计查询详细情况,其中应显示以下信息:

# npm audit report

nth-check  <2.0.1
Severity: high
Inefficient Regular Expression Complexity in nth-check - https://github.com/advisories/GHSA-rp65-9cf3-cjxr
fix available via `npm audit fix --force`
Will install [email protected], which is a breaking change
  css-select  <=3.1.0
  Depends on vulnerable versions of nth-check
    svgo  1.0.0 - 1.3.2
    Depends on vulnerable versions of css-select
      @svgr/plugin-svgo  <=5.5.0
      Depends on vulnerable versions of svgo
        @svgr/webpack  4.0.0 - 5.5.0
        Depends on vulnerable versions of @svgr/plugin-svgo
          react-scripts  >=2.1.4
          Depends on vulnerable versions of @svgr/webpack
          Depends on vulnerable versions of resolve-url-loader

postcss  <8.4.31
Severity: moderate
PostCSS line return parsing error - https://github.com/advisories/GHSA-7fh5-64p2-3v2j
fix available via `npm audit fix --force`
Will install [email protected], which is a breaking change
  resolve-url-loader  0.0.1-experiment-postcss || 3.0.0-alpha.1 - 4.0.0
  Depends on vulnerable versions of postcss

8 vulnerabilities (2 moderate, 6 high)

To address all issues (including breaking changes), run:
  npm audit fix --force

首先,它建议你使用<条码>npm审计 固定,这意味着微量更新(例如<条码>1.0.x<条码/代码>至<条码>。 这个问题可以解决。

但在上述情况下,建议使用<条码>npm 审计准则-force,其中仅指主要最新情况(例如<条码>1.x.x至<条码>2.x.)。 可以解决这个问题(但通常会中断申请)。

通常vulnerabilities are not unforgivable——除非你从事需要重大安全关切的项目。


