Skip to content

Conversation

@nextcloud-command
Copy link
Contributor

@nextcloud-command nextcloud-command commented May 4, 2025

Audit report

This audit fix resolves 8 of the total 15 vulnerabilities found in your project.

Updated dependencies

Fixed vulnerabilities

@nextcloud/dialogs #

  • Caused by vulnerable dependency:
  • Affected versions: 4.2.0-beta.1 - 6.3.0
  • Package usage:
    • node_modules/@nextcloud/dialogs

@nextcloud/vite-config #

  • Caused by vulnerable dependency:
  • Affected versions: <=1.5.6
  • Package usage:
    • node_modules/@nextcloud/vite-config

@vitejs/plugin-vue2 #

  • Caused by vulnerable dependency:
  • Affected versions: *
  • Package usage:
    • node_modules/@vitejs/plugin-vue2

esbuild #

  • esbuild enables any website to send any requests to the development server and read the response
  • Severity: moderate (CVSS 5.3)
  • Reference: GHSA-67mh-4wv8-2f99
  • Affected versions: <=0.24.2
  • Package usage:
    • node_modules/vite/node_modules/esbuild

undici #

  • undici Denial of Service attack via bad certificate data
  • Severity: low (CVSS 3.1)
  • Reference: GHSA-cxrh-j4jr-qwg3
  • Affected versions: <5.29.0
  • Package usage:
    • node_modules/undici

vite #

  • Vite's server.fs.deny bypassed with /. for files under project root
  • Severity: moderate
  • Reference: GHSA-859w-5945-r5v3
  • Affected versions: 0.11.0 - 6.1.6
  • Package usage:
    • node_modules/vite

vue-async-computed #

  • Caused by vulnerable dependency:
  • Affected versions: 2.0.0-rc.1 - 4.0.0-mixin.0
  • Package usage:
    • node_modules/vue-async-computed

vue-resize #

  • Caused by vulnerable dependency:
  • Affected versions: 0.4.0 - 1.0.1
  • Package usage:
    • node_modules/vue-resize

@nextcloud-command nextcloud-command added 3. to review Waiting for reviews dependencies Pull requests that update a dependency file labels May 4, 2025
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable30-fix-npm-audit branch from 12d755d to 4cd3b36 Compare May 11, 2025 03:42
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable30-fix-npm-audit branch from 4cd3b36 to e86a0db Compare May 18, 2025 03:45
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable30-fix-npm-audit branch from e86a0db to d5fd6eb Compare June 1, 2025 04:00
@skjnldsv skjnldsv merged commit db9b377 into stable30 Jun 1, 2025
36 of 38 checks passed
@skjnldsv skjnldsv deleted the automated/noid/stable30-fix-npm-audit branch June 1, 2025 11:13
@nextcloud-bot nextcloud-bot mentioned this pull request Jun 4, 2025
11 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3. to review Waiting for reviews dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants