从npm cli v8.3.0(2021-12-09)开始,这个问题可以使用package.json的overrides字段来解决。正如StriplingWarrior的回答所描述的那样
例如,该项目有typescript 4.6.2版本作为直接开发依赖,而awesome-typescript-loader使用旧版本2.7的typescript。下面是如何告诉npm使用awesome-typescript-loader的typescript 4.6.2版本:
{
"name": "myproject",
"version": "0.0.0",
"scripts": ...
"dependencies": ...
"devDependencies": {
"typescript": "~4.6.2",
"awesome-typescript-loader": "^5.2.1",
...
},
"overrides": {
"awesome-typescript-loader": {
"typescript": "$typescript"
}
}
}
如果你不使用typescript作为直接的开发依赖项,那么你必须在overrides部分写4.6.2而不是$typescript:
{
"name": "myproject",
"version": "0.0.0",
"scripts": ...
"dependencies": ...
"devDependencies": {
"awesome-typescript-loader": "^5.2.1",
...
},
"overrides": {
"awesome-typescript-loader": {
"typescript": "~4.6.2"
}
}
}
使用最新版本的依赖项:
{
"name": "myproject",
"version": "0.0.0",
"scripts": ...
"dependencies": ...
"devDependencies": {
"awesome-typescript-loader": "^5.2.1",
...
},
"overrides": {
"awesome-typescript-loader": {
"typescript": "latest"
}
}
}
同样的重写可以用于依赖和devDependencies。
如果你正在使用npm版本>5但<8.3.0:编辑你的包锁。Json:从“要求”部分删除库,并将其添加到“依赖项”下。
例如,您希望deglob包使用glob包3.2.11版本而不是当前版本。你打开包裹锁。Json,参见:
"deglob": {
"version": "2.1.0",
"resolved": "https://registry.npmjs.org/deglob/-/deglob-2.1.0.tgz",
"integrity": "sha1-TUSr4W7zLHebSXK9FBqAMlApoUo=",
"requires": {
"find-root": "1.1.0",
"glob": "7.1.2",
"ignore": "3.3.5",
"pkg-config": "1.1.1",
"run-parallel": "1.1.6",
"uniq": "1.0.1"
}
},
删除"glob": "7.1.2",从"requires"中删除"glob": "7.1.2",添加"dependencies",版本合适:
"deglob": {
"version": "2.1.0",
"resolved": "https://registry.npmjs.org/deglob/-/deglob-2.1.0.tgz",
"integrity": "sha1-TUSr4W7zLHebSXK9FBqAMlApoUo=",
"requires": {
"find-root": "1.1.0",
"ignore": "3.3.5",
"pkg-config": "1.1.1",
"run-parallel": "1.1.6",
"uniq": "1.0.1"
},
"dependencies": {
"glob": {
"version": "3.2.11"
}
}
},
现在删除你的node_modules文件夹,运行npm ci(或npm install旧版本的node/npm),它会将缺失的部分添加到“依赖项”部分。