Skip to content

Conversation

@nextcloud-command
Copy link
Collaborator

@nextcloud-command nextcloud-command commented Jan 5, 2025

Audit report

This audit fix resolves 18 of the total 31 vulnerabilities found in your project.

Updated dependencies

Fixed vulnerabilities

@babel/runtime #

  • Babel has inefficient RexExp complexity in generated code with .replace when transpiling named capturing groups
  • Severity: moderate (CVSS 6.2)
  • Reference: GHSA-968p-4wvh-cqc8
  • Affected versions: <7.26.10
  • Package usage:
    • node_modules/@babel/runtime

@nextcloud/dialogs #

  • Caused by vulnerable dependency:
  • Affected versions: >=4.2.0-beta.1
  • Package usage:
    • node_modules/@nextcloud/dialogs

@nextcloud/l10n #

  • Caused by vulnerable dependency:
  • Affected versions: 1.1.0 - 3.1.0
  • Package usage:
    • node_modules/@nextcloud/l10n
    • node_modules/@nextcloud/moment/node_modules/@nextcloud/l10n

@nextcloud/moment #

  • Caused by vulnerable dependency:
  • Affected versions: >=1.1.1
  • Package usage:
    • node_modules/@nextcloud/moment

@vue/component-compiler-utils #

  • Caused by vulnerable dependency:
  • Affected versions: *
  • Package usage:
    • node_modules/@vue/component-compiler-utils

@vue/test-utils #

  • Caused by vulnerable dependency:
  • Affected versions: <=1.3.6
  • Package usage:
    • node_modules/@vue/test-utils

axios #

  • axios Requests Vulnerable To Possible SSRF and Credential Leakage via Absolute URL
  • Severity: high
  • Reference: GHSA-jr5f-v2jv-69x6
  • Affected versions: <1.8.2
  • Package usage:
    • node_modules/axios

dompurify #

  • DOMPurify allows Cross-site Scripting (XSS)
  • Severity: moderate (CVSS 4.5)
  • Reference: GHSA-vhxf-7vqr-mrjg
  • Affected versions: <3.2.4
  • Package usage:
    • node_modules/dompurify
    • node_modules/mermaid/node_modules/dompurify

elliptic #

  • Elliptic's private key extraction in ECDSA upon signing a malformed input (e.g. a string)
  • Severity: critical 🚨
  • Reference: GHSA-vjh7-7g9h-fjfh
  • Affected versions: <=6.6.0
  • Package usage:
    • node_modules/elliptic

katex #

  • KaTeX \htmlData does not validate attribute names
  • Severity: moderate (CVSS 6.3)
  • Reference: GHSA-cg87-wmx4-v546
  • Affected versions: 0.12.0 - 0.16.20
  • Package usage:
    • node_modules/katex

mermaid #

  • Caused by vulnerable dependency:
  • Affected versions: 8.11.1 - 10.3.0 || 10.9.2 - 10.9.3 || 11.3.0 - 11.4.0
  • Package usage:
    • node_modules/mermaid

node-gettext #

  • node-gettext vulnerable to Prototype Pollution
  • Severity: high (CVSS 5.9)
  • Reference: GHSA-g974-hxvm-x689
  • Affected versions: *
  • Package usage:
    • node_modules/node-gettext

postcss #

  • PostCSS line return parsing error
  • Severity: moderate (CVSS 5.3)
  • Reference: GHSA-7fh5-64p2-3v2j
  • Affected versions: <8.4.31
  • Package usage:
    • node_modules/@vue/component-compiler-utils/node_modules/postcss

undici #

  • Use of Insufficiently Random Values in undici
  • Severity: moderate (CVSS 6.8)
  • Reference: GHSA-c76h-2ccp-4975
  • Affected versions: 4.5.0 - 5.28.4
  • Package usage:
    • node_modules/undici

vite #

  • Caused by vulnerable dependency:
  • Affected versions: 0.11.0 - 6.1.2
  • Package usage:
    • node_modules/vite

vue-resize #

  • Caused by vulnerable dependency:
  • Affected versions: 0.4.0 - 1.0.1
  • Package usage:
    • node_modules/vue-resize

vue-template-compiler #

  • vue-template-compiler vulnerable to client-side Cross-Site Scripting (XSS)
  • Severity: moderate (CVSS 4.2)
  • Reference: GHSA-g3ch-rx76-35fx
  • Affected versions: >=2.0.0
  • Package usage:
    • node_modules/vue-template-compiler

vuex #

  • Caused by vulnerable dependency:
  • Affected versions: 3.1.3 - 3.6.2
  • Package usage:
    • node_modules/vuex

@nextcloud-command nextcloud-command added 3. to review dependencies Pull requests that update a dependency file labels Jan 5, 2025
@codecov
Copy link

codecov bot commented Jan 5, 2025

Codecov Report

All modified and coverable lines are covered by tests ✅

Project coverage is 53.68%. Comparing base (2136b88) to head (c7442ee).
Report is 5 commits behind head on stable30.

Additional details and impacted files
@@            Coverage Diff            @@
##           stable30    #6837   +/-   ##
=========================================
  Coverage     53.68%   53.68%           
=========================================
  Files           116      116           
  Lines          2578     2578           
  Branches        525      527    +2     
=========================================
  Hits           1384     1384           
  Misses         1066     1066           
  Partials        128      128           

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@nextcloud-command nextcloud-command force-pushed the automated/noid/stable30-fix-npm-audit branch 2 times, most recently from 670d9ab to 9690697 Compare January 19, 2025 03:17
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable30-fix-npm-audit branch 2 times, most recently from a9606db to f057ee3 Compare February 2, 2025 03:19
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable30-fix-npm-audit branch from f057ee3 to 106b745 Compare February 9, 2025 03:19
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable30-fix-npm-audit branch from 106b745 to 2ec9e88 Compare February 16, 2025 03:28
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable30-fix-npm-audit branch from 2ec9e88 to 1249f00 Compare February 23, 2025 03:30
@max-nextcloud max-nextcloud force-pushed the automated/noid/stable30-fix-npm-audit branch 2 times, most recently from d769c2b to b32dcac Compare February 27, 2025 14:28
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable30-fix-npm-audit branch 2 times, most recently from 6d559ab to fd03f38 Compare March 9, 2025 03:00
@juliusknorr juliusknorr force-pushed the automated/noid/stable30-fix-npm-audit branch from fd03f38 to fea0376 Compare March 13, 2025 20:53
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable30-fix-npm-audit branch from fea0376 to c51aa16 Compare March 16, 2025 03:26
@juliusknorr juliusknorr force-pushed the automated/noid/stable30-fix-npm-audit branch from c51aa16 to f3e9fd2 Compare March 21, 2025 12:08
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable30-fix-npm-audit branch from f3e9fd2 to a364f6b Compare March 23, 2025 03:25
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable30-fix-npm-audit branch from a364f6b to b128e93 Compare March 30, 2025 03:34
@mejo- mejo- force-pushed the automated/noid/stable30-fix-npm-audit branch from b128e93 to c7442ee Compare April 2, 2025 12:40
@mejo- mejo- merged commit fc6618b into stable30 Apr 2, 2025
62 of 63 checks passed
@mejo- mejo- deleted the automated/noid/stable30-fix-npm-audit branch April 2, 2025 12:49
@Altahrim Altahrim mentioned this pull request Apr 3, 2025
5 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3. to review dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants