Skip to content

Conversation

@nextcloud-command
Copy link
Contributor

@nextcloud-command nextcloud-command commented Apr 6, 2025

Audit report

This audit fix resolves 9 of the total 16 vulnerabilities found in your project.

Updated dependencies

Fixed vulnerabilities

@nextcloud/dialogs #

  • Caused by vulnerable dependency:
  • Affected versions: 4.2.0-beta.1 - 6.3.0
  • Package usage:
    • node_modules/@nextcloud/dialogs

@nextcloud/vite-config #

  • Caused by vulnerable dependency:
  • Affected versions: <=1.5.6
  • Package usage:
    • node_modules/@nextcloud/vite-config

@vitejs/plugin-vue2 #

  • Caused by vulnerable dependency:
  • Affected versions: *
  • Package usage:
    • node_modules/@vitejs/plugin-vue2

esbuild #

  • esbuild enables any website to send any requests to the development server and read the response
  • Severity: moderate (CVSS 5.3)
  • Reference: GHSA-67mh-4wv8-2f99
  • Affected versions: <=0.24.2
  • Package usage:
    • node_modules/esbuild
    • node_modules/vite/node_modules/esbuild

rollup-plugin-esbuild-minify #

  • Caused by vulnerable dependency:
  • Affected versions: <=1.2.0
  • Package usage:
    • node_modules/rollup-plugin-esbuild-minify

undici #

  • undici Denial of Service attack via bad certificate data
  • Severity: low (CVSS 3.1)
  • Reference: GHSA-cxrh-j4jr-qwg3
  • Affected versions: <5.29.0
  • Package usage:
    • node_modules/undici

vite #

  • Vite's server.fs.deny bypassed with /. for files under project root
  • Severity: moderate
  • Reference: GHSA-859w-5945-r5v3
  • Affected versions: 0.11.0 - 6.1.6
  • Package usage:
    • node_modules/vite

vue-async-computed #

  • Caused by vulnerable dependency:
  • Affected versions: 2.0.0-rc.1 - 4.0.0-mixin.0
  • Package usage:
    • node_modules/vue-async-computed

vue-resize #

  • Caused by vulnerable dependency:
  • Affected versions: 0.4.0 - 1.0.1
  • Package usage:
    • node_modules/vue-resize

@nextcloud-command nextcloud-command added 3. to review Waiting for reviews dependencies Pull requests that update a dependency file labels Apr 6, 2025
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable31-fix-npm-audit branch 2 times, most recently from e75b865 to 4892e42 Compare April 20, 2025 03:33
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable31-fix-npm-audit branch 2 times, most recently from 5938eee to 40a4b08 Compare May 4, 2025 03:38
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable31-fix-npm-audit branch from 40a4b08 to d49ebdd Compare May 11, 2025 03:42
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable31-fix-npm-audit branch from d49ebdd to f19c3b9 Compare May 18, 2025 03:45
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable31-fix-npm-audit branch from f19c3b9 to 44dc46d Compare June 1, 2025 04:00
@skjnldsv skjnldsv merged commit 9043026 into stable31 Jun 1, 2025
38 of 41 checks passed
@skjnldsv skjnldsv deleted the automated/noid/stable31-fix-npm-audit branch June 1, 2025 11:12
@nextcloud-bot nextcloud-bot mentioned this pull request Jun 4, 2025
10 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3. to review Waiting for reviews dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants