Skip to content

[stable31] Fix npm audit#7779

Open
nextcloud-command wants to merge 1 commit into
stable31from
automated/noid/stable31-fix-npm-audit
Open

[stable31] Fix npm audit#7779
nextcloud-command wants to merge 1 commit into
stable31from
automated/noid/stable31-fix-npm-audit

Conversation

@nextcloud-command

@nextcloud-command nextcloud-command commented Mar 22, 2026

Copy link
Copy Markdown
Contributor

Audit report

This audit fix resolves 1 of the total 43 vulnerabilities found in your project.

Updated dependencies

Fixed vulnerabilities

dompurify #

  • DOMPurify's ADD_TAGS function form bypasses FORBID_TAGS due to short-circuit evaluation
  • Severity: moderate
  • Reference: GHSA-39q2-94rc-95cp
  • Affected versions: <=3.3.3
  • Package usage:
    • node_modules/dompurify

@luka-nextcloud luka-nextcloud force-pushed the automated/noid/stable31-fix-npm-audit branch from 9a71bb9 to a4e343a Compare March 26, 2026 13:18
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable31-fix-npm-audit branch 2 times, most recently from 2954915 to 9c4e1b4 Compare April 5, 2026 03:52
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable31-fix-npm-audit branch from 9c4e1b4 to a221d8c Compare April 12, 2026 04:03
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable31-fix-npm-audit branch from a221d8c to a207979 Compare April 19, 2026 04:17
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable31-fix-npm-audit branch 2 times, most recently from 0eb1c67 to 19a6b1b Compare May 3, 2026 04:16
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable31-fix-npm-audit branch from 19a6b1b to 462b037 Compare May 10, 2026 04:14
Signed-off-by: GitHub <noreply@github.com>
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable31-fix-npm-audit branch from 462b037 to 6858c05 Compare May 17, 2026 04:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant