Skip to content

Conversation

@nextcloud-command
Copy link
Contributor

Audit report

This audit fix resolves 7 of the total 11 vulnerabilities found in your project.

Updated dependencies

Fixed vulnerabilities

browserify-sign #

  • Caused by vulnerable dependency:
  • Affected versions: >=4.0.0
  • Package usage:
    • node_modules/browserify-sign

create-ecdh #

  • Caused by vulnerable dependency:
  • Affected versions: >=4.0.0
  • Package usage:
    • node_modules/create-ecdh

crypto-browserify #

  • Caused by vulnerable dependency:
  • Affected versions: >=3.11.0
  • Package usage:
    • node_modules/crypto-browserify

elliptic #

  • Elliptic allows BER-encoded signatures
  • Severity: low (CVSS 5.3)
  • Reference: GHSA-49q7-c7j4-3p7m
  • Affected versions: >=2.0.0
  • Package usage:
    • node_modules/elliptic

node-stdlib-browser #

  • Caused by vulnerable dependency:
  • Affected versions: *
  • Package usage:
    • node_modules/node-stdlib-browser

vite-plugin-node-polyfills #

  • Caused by vulnerable dependency:
  • Affected versions: >=0.3.0
  • Package usage:
    • node_modules/vite-plugin-node-polyfills

vue-tsc #

  • Caused by vulnerable dependency:
  • Affected versions: 1.7.0-alpha.0 - 2.0.28
  • Package usage:
    • node_modules/vue-tsc

@nextcloud-command nextcloud-command added 3. to review Waiting for reviews dependencies Pull requests that update a dependency file labels Aug 7, 2024
@susnux susnux merged commit c2b18e2 into master Aug 7, 2024
@susnux susnux deleted the automated/noid/master-fix-npm-audit branch August 7, 2024 16:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3. to review Waiting for reviews dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants