Skip to content

[stable31] Fix npm audit#1411

Open
nextcloud-command wants to merge 1 commit intostable31from
automated/noid/stable31-fix-npm-audit
Open

[stable31] Fix npm audit#1411
nextcloud-command wants to merge 1 commit intostable31from
automated/noid/stable31-fix-npm-audit

Conversation

@nextcloud-command
Copy link
Copy Markdown
Contributor

@nextcloud-command nextcloud-command commented Apr 5, 2026

Audit report

This audit fix resolves 2 of the total 34 vulnerabilities found in your project.

Updated dependencies

Fixed vulnerabilities

@nextcloud/webpack-vue-config #

axios #

  • Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF
  • Severity: moderate (CVSS 4.8)
  • Reference: GHSA-3p68-rc4w-qgx5
  • Affected versions: 1.0.0 - 1.14.0
  • Package usage:
    • node_modules/axios

@nextcloud-command nextcloud-command added 3. to review dependencies Pull requests that update a dependency file labels Apr 5, 2026
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable31-fix-npm-audit branch from d31cfd7 to 41488c5 Compare April 12, 2026 04:02
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable31-fix-npm-audit branch from 41488c5 to 2be7af8 Compare April 19, 2026 04:18
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable31-fix-npm-audit branch from 2be7af8 to 267829e Compare April 26, 2026 04:20
Signed-off-by: GitHub <noreply@github.com>
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable31-fix-npm-audit branch from 267829e to 1c08007 Compare May 3, 2026 04:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3. to review dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant