Skip to content

Conversation

@nextcloud-command
Copy link
Contributor

Audit report

This audit fix resolves 12 of the total 16 vulnerabilities found in your project.

Updated dependencies

Fixed vulnerabilities

@nextcloud/dialogs #

@nextcloud/files #

  • Caused by vulnerable dependency:
  • Affected versions: >=1.1.0
  • Package usage:
    • node_modules/@nextcloud/files

@nextcloud/l10n #

  • Caused by vulnerable dependency:
  • Affected versions: >=1.1.0
  • Package usage:
    • node_modules/@nextcloud/l10n

@nextcloud/vue #

  • Caused by vulnerable dependency:
  • Affected versions: >=1.4.0
  • Package usage:
    • node_modules/@nextcloud/vue

browserify-sign #

  • Caused by vulnerable dependency:
  • Affected versions: >=2.4.0
  • Package usage:
    • node_modules/browserify-sign

create-ecdh #

  • Caused by vulnerable dependency:
  • Affected versions: *
  • Package usage:
    • node_modules/create-ecdh

crypto-browserify #

  • Caused by vulnerable dependency:
  • Affected versions: >=3.4.0
  • Package usage:
    • node_modules/crypto-browserify

elliptic #

  • Valid ECDSA signatures erroneously rejected in Elliptic
  • Severity: low
  • Reference: GHSA-fc9h-whq2-v747
  • Affected versions: *
  • Package usage:
    • node_modules/elliptic

node-gettext #

  • node-gettext vulnerable to Prototype Pollution
  • Severity: moderate (CVSS 5.9)
  • Reference: GHSA-g974-hxvm-x689
  • Affected versions: *
  • Package usage:
    • node_modules/node-gettext

node-stdlib-browser #

  • Caused by vulnerable dependency:
  • Affected versions: *
  • Package usage:
    • node_modules/node-stdlib-browser

vite-plugin-node-polyfills #

  • Caused by vulnerable dependency:
  • Affected versions: >=0.3.0
  • Package usage:
    • node_modules/vite-plugin-node-polyfills

vue-tsc #

  • Caused by vulnerable dependency:
  • Affected versions: 1.7.0-alpha.0 - 2.0.28
  • Package usage:
    • node_modules/vue-tsc

@nextcloud-command nextcloud-command added 3. to review dependencies Pull requests that update a dependency file labels Oct 20, 2024
@szaimen szaimen added this to the Nextcloud 31 milestone Oct 21, 2024
@szaimen szaimen merged commit 8d7fc0d into master Oct 21, 2024
@szaimen szaimen deleted the automated/noid/master-fix-npm-audit branch October 21, 2024 07:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3. to review dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants