Skip to content

[stable31] Fix npm audit#1411

Merged
danxuliu merged 1 commit into
stable31from
automated/noid/stable31-fix-npm-audit
May 20, 2026
Merged

[stable31] Fix npm audit#1411
danxuliu merged 1 commit into
stable31from
automated/noid/stable31-fix-npm-audit

Conversation

@nextcloud-command

@nextcloud-command nextcloud-command commented Apr 5, 2026

Copy link
Copy Markdown
Contributor

Audit report

This audit fix resolves 2 of the total 33 vulnerabilities found in your project.

Updated dependencies

Fixed vulnerabilities

@nextcloud/webpack-vue-config #

axios #

  • Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF
  • Severity: moderate (CVSS 4.8)
  • Reference: GHSA-3p68-rc4w-qgx5
  • Affected versions: 1.0.0 - 1.15.1
  • Package usage:
    • node_modules/axios

@nextcloud-command nextcloud-command added 3. to review dependencies Pull requests that update a dependency file labels Apr 5, 2026
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable31-fix-npm-audit branch from d31cfd7 to 41488c5 Compare April 12, 2026 04:02
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable31-fix-npm-audit branch from 41488c5 to 2be7af8 Compare April 19, 2026 04:18
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable31-fix-npm-audit branch 2 times, most recently from 267829e to 1c08007 Compare May 3, 2026 04:12
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable31-fix-npm-audit branch from 1c08007 to a39d251 Compare May 10, 2026 04:16
Signed-off-by: GitHub <noreply@github.com>
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable31-fix-npm-audit branch from a39d251 to 788171e Compare May 17, 2026 04:20

@danxuliu danxuliu left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Tested and works 👍

@danxuliu danxuliu merged commit 7db5087 into stable31 May 20, 2026
36 checks passed
@danxuliu danxuliu deleted the automated/noid/stable31-fix-npm-audit branch May 20, 2026 21:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3. to review dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants