Skip to content

Conversation

@nextcloud-command
Copy link
Collaborator

@nextcloud-command nextcloud-command commented Aug 18, 2024

Audit report

This audit fix resolves 6 of the total 11 vulnerabilities found in your project.

Updated dependencies

Fixed vulnerabilities

@vue/component-compiler-utils #

  • Caused by vulnerable dependency:
  • Affected versions: *
  • Package usage:
    • node_modules/@vue/component-compiler-utils

@vue/test-utils #

  • Caused by vulnerable dependency:
  • Affected versions: <=1.3.6
  • Package usage:
    • node_modules/@vue/test-utils

elliptic #

  • Elliptic's EDDSA missing signature length check
  • Severity: low (CVSS 5.3)
  • Reference: GHSA-f7q4-pwc6-w24p
  • Affected versions: 2.0.0 - 6.5.6
  • Package usage:
    • node_modules/elliptic

micromatch #

  • Regular Expression Denial of Service (ReDoS) in micromatch
  • Severity: moderate
  • Reference: GHSA-952p-6rrq-rcjv
  • Affected versions: <4.0.8
  • Package usage:
    • node_modules/micromatch

postcss #

  • PostCSS line return parsing error
  • Severity: moderate (CVSS 5.3)
  • Reference: GHSA-7fh5-64p2-3v2j
  • Affected versions: <8.4.31
  • Package usage:
    • node_modules/@vue/component-compiler-utils/node_modules/postcss

vue-tsc #

  • Caused by vulnerable dependency:
  • Affected versions: 1.7.0-alpha.0 - 2.0.28
  • Package usage:
    • node_modules/vue-tsc

@nextcloud-command nextcloud-command added 3. to review dependencies Pull requests that update a dependency file labels Aug 18, 2024
@mejo- mejo- force-pushed the automated/noid/stable30-fix-npm-audit branch 2 times, most recently from 9a29615 to 282278c Compare August 23, 2024 08:29
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable30-fix-npm-audit branch from 282278c to a4312ab Compare August 25, 2024 03:04
@juliusknorr juliusknorr merged commit d5560c8 into stable30 Aug 26, 2024
@juliusknorr juliusknorr deleted the automated/noid/stable30-fix-npm-audit branch August 26, 2024 07:39
@blizzz blizzz mentioned this pull request Aug 29, 2024
24 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3. to review dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants