Skip to content

Conversation

@nextcloud-command
Copy link
Contributor

@nextcloud-command nextcloud-command commented Aug 4, 2024

Audit report

This audit fix resolves 8 of the total 12 vulnerabilities found in your project.

Updated dependencies

Fixed vulnerabilities

browserify-sign #

  • Caused by vulnerable dependency:
  • Affected versions: >=4.0.0
  • Package usage:
    • node_modules/browserify-sign

create-ecdh #

  • Caused by vulnerable dependency:
  • Affected versions: >=4.0.0
  • Package usage:
    • node_modules/create-ecdh

crypto-browserify #

  • Caused by vulnerable dependency:
  • Affected versions: >=3.11.0
  • Package usage:
    • node_modules/crypto-browserify

elliptic #

  • Elliptic allows BER-encoded signatures
  • Severity: low (CVSS 5.3)
  • Reference: GHSA-49q7-c7j4-3p7m
  • Affected versions: >=2.0.0
  • Package usage:
    • node_modules/elliptic

fast-xml-parser #

  • fast-xml-parser vulnerable to ReDOS at currency parsing
  • Severity: high (CVSS 7.5)
  • Reference: GHSA-mpg4-rc92-vx8v
  • Affected versions: <4.4.1
  • Package usage:
    • node_modules/fast-xml-parser

node-stdlib-browser #

  • Caused by vulnerable dependency:
  • Affected versions: *
  • Package usage:
    • node_modules/node-stdlib-browser

vite-plugin-node-polyfills #

  • Caused by vulnerable dependency:
  • Affected versions: >=0.3.0
  • Package usage:
    • node_modules/vite-plugin-node-polyfills

vue-tsc #

  • Caused by vulnerable dependency:
  • Affected versions: 1.7.0-alpha.0 - 2.0.28
  • Package usage:
    • node_modules/vue-tsc

@nextcloud-command nextcloud-command added 3. to review Waiting for reviews dependencies Pull requests that update a dependency file labels Aug 4, 2024
@AndyScherzinger AndyScherzinger force-pushed the automated/noid/stable29-fix-npm-audit branch from 25c826f to 6154795 Compare August 5, 2024 22:20
@AndyScherzinger AndyScherzinger added this to the Nextcloud 29.0.5 milestone Aug 5, 2024
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable29-fix-npm-audit branch from 6154795 to 0a5b821 Compare August 7, 2024 13:54
@Altahrim Altahrim mentioned this pull request Aug 8, 2024
9 tasks
@susnux susnux force-pushed the automated/noid/stable29-fix-npm-audit branch from 0a5b821 to 4c44045 Compare August 8, 2024 15:40
@susnux susnux enabled auto-merge August 8, 2024 15:40
@susnux susnux merged commit 5931651 into stable29 Aug 8, 2024
@susnux susnux deleted the automated/noid/stable29-fix-npm-audit branch August 8, 2024 15:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3. to review Waiting for reviews dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants