18

Is it possible to configure npm to skip audit of vulnerabilities for devDependencies when running command npm install?

revy
  • 3,945
  • 7
  • 40
  • 85

4 Answers4

15

You can skip auditing at all by adding the --no-audit flag.

npm install --no-audit

If you want this to apply to devDependencies only, you can run it this way:

npm install --no-audit --only=dev

If you want this to apply to production dependencies only, you can run it this way:

npm install --no-audit --only=prod
5

Since this is a first result when you try to google for a way to disable audit, let's post a more convenient solution for more general case.

You can skip auditing altogether by using npm config:

npm config set audit false

And to reduce pesky noise even more:

npm config set fund false
Joris Schellekens
  • 8,483
  • 2
  • 23
  • 54
garkin
  • 139
  • 2
  • 4
0
npm install --disableNodeJS --nodeAuditSkipDevDependencies
user2579720
  • 53
  • 2
  • 7
-1

You can simply just use the command

npm audit --prod

And to ignore a particular package use

npm audit --ignore packageName

To know more about it you can visit this link - https://github.com/npm/npm/issues/20564.

Dharman
  • 30,962
  • 25
  • 85
  • 135
Marshal
  • 16
  • 3
  • Thank you, I know about `npm audit --prod`. I was asking if there is a global npm configuration available to skip dev dependencies auditing on `npm install`. – revy Mar 05 '22 at 08:52