Skip to content

Conversation

@nextcloud-command
Copy link
Contributor

@nextcloud-command nextcloud-command commented Sep 7, 2025

Audit report

This audit fix resolves 2 of the total 16 vulnerabilities found in your project.

Updated dependencies

Fixed vulnerabilities

@nextcloud/webpack-vue-config #

axios #

  • Axios is vulnerable to DoS attack through lack of data size check
  • Severity: high (CVSS 7.5)
  • Reference: GHSA-4hjh-wcwx-xvwj
  • Affected versions: <1.12.0
  • Package usage:
    • node_modules/axios

@nextcloud-command nextcloud-command added 3. to review dependencies Pull requests that update a dependency file labels Sep 7, 2025
Copy link
Member

@danxuliu danxuliu left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Tested and works 👍

@nextcloud-command nextcloud-command force-pushed the automated/noid/stable30-fix-npm-audit branch from ca55654 to 9880d91 Compare September 14, 2025 03:16
Copy link
Member

@danxuliu danxuliu left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Tested and works 👍

@danxuliu danxuliu merged commit dde483d into stable30 Sep 14, 2025
34 checks passed
@danxuliu danxuliu deleted the automated/noid/stable30-fix-npm-audit branch September 14, 2025 09:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3. to review dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants