Skip to content

Conversation

@Antreesy
Copy link
Collaborator

@Antreesy Antreesy commented Jul 7, 2023

Non-fixable dependencies at the moment:

semver  <7.5.2
Severity: moderate
semver vulnerable to Regular Expression Denial of Service - https://github.com/advisories/GHSA-c2qf-rxjj-qqgw
No fix available

13 moderate severity vulnerabilities

Signed-off-by: Maksim Sukharev <[email protected]>
@Antreesy Antreesy added security dependencies Pull requests that update a dependency file javascript labels Jul 7, 2023
@Antreesy Antreesy added this to the Nextcloud 25.0.9 milestone Jul 7, 2023
@Antreesy Antreesy requested a review from nickvergessen as a code owner July 7, 2023 12:21
@Antreesy Antreesy self-assigned this Jul 7, 2023
Copy link
Member

@nickvergessen nickvergessen left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Diff is too big, can't check.
But still works, so I guess it's fine.

@nickvergessen nickvergessen merged commit d47f5cb into stable25 Jul 10, 2023
@nickvergessen nickvergessen deleted the chore/stable25/audit-dependencies branch July 10, 2023 08:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants