Skip to content

[main] Fix npm audit#1597

Merged
susnux merged 1 commit intomainfrom
automated/noid/main-fix-npm-audit
Feb 28, 2025
Merged

[main] Fix npm audit#1597
susnux merged 1 commit intomainfrom
automated/noid/main-fix-npm-audit

Conversation

@nextcloud-command
Copy link
Contributor

@nextcloud-command nextcloud-command commented Feb 16, 2025

Audit report

This audit fix resolves 7 of the total 23 vulnerabilities found in your project.

Updated dependencies

Fixed vulnerabilities

@nextcloud/l10n #

  • Caused by vulnerable dependency:
  • Affected versions: 1.1.0 - 3.1.0
  • Package usage:
    • node_modules/@nextcloud/l10n

@vue/test-utils #

  • Caused by vulnerable dependency:
  • Affected versions: <=1.3.6
  • Package usage:
    • node_modules/@vue/test-utils

node-gettext #

  • node-gettext vulnerable to Prototype Pollution
  • Severity: high (CVSS 5.9)
  • Reference: GHSA-g974-hxvm-x689
  • Affected versions: *
  • Package usage:
    • node_modules/node-gettext

vite-plugin-css-injected-by-js #

  • Caused by vulnerable dependency:
  • Affected versions: *
  • Package usage:
    • node_modules/vite-plugin-css-injected-by-js

vite-plugin-node-polyfills #

  • Caused by vulnerable dependency:
  • Affected versions: >=0.3.2
  • Package usage:
    • node_modules/vite-plugin-node-polyfills

vue-resize #

  • Caused by vulnerable dependency:
  • Affected versions: 0.4.0 - 1.0.1
  • Package usage:
    • node_modules/vue-resize

vue-template-compiler #

  • vue-template-compiler vulnerable to client-side Cross-Site Scripting (XSS)
  • Severity: moderate (CVSS 4.2)
  • Reference: GHSA-g3ch-rx76-35fx
  • Affected versions: >=2.0.0
  • Package usage:
    • node_modules/vue-template-compiler

@nextcloud-command nextcloud-command added 3. to review dependencies Pull requests that update a dependency file labels Feb 16, 2025
@nextcloud-command nextcloud-command force-pushed the automated/noid/main-fix-npm-audit branch from 9676337 to e4e934f Compare February 23, 2025 03:05
Signed-off-by: Ferdinand Thiessen <opensource@fthiessen.de>
@susnux susnux force-pushed the automated/noid/main-fix-npm-audit branch from e4e934f to 87ba901 Compare February 28, 2025 10:30
@susnux susnux merged commit c1ce81f into main Feb 28, 2025
14 checks passed
@susnux susnux deleted the automated/noid/main-fix-npm-audit branch February 28, 2025 10:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3. to review dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants