Skip to content

[stable32] Fix npm audit#1412

Open
nextcloud-command wants to merge 1 commit intostable32from
automated/noid/stable32-fix-npm-audit
Open

[stable32] Fix npm audit#1412
nextcloud-command wants to merge 1 commit intostable32from
automated/noid/stable32-fix-npm-audit

Conversation

@nextcloud-command
Copy link
Copy Markdown
Contributor

@nextcloud-command nextcloud-command commented Apr 5, 2026

Audit report

This audit fix resolves 1 of the total 30 vulnerabilities found in your project.

Updated dependencies

Fixed vulnerabilities

axios #

  • Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF
  • Severity: moderate (CVSS 4.8)
  • Reference: GHSA-3p68-rc4w-qgx5
  • Affected versions: 1.0.0 - 1.14.0
  • Package usage:
    • node_modules/axios

@nextcloud-command nextcloud-command added 3. to review dependencies Pull requests that update a dependency file labels Apr 5, 2026
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable32-fix-npm-audit branch from 3d2fc53 to 0c28b86 Compare April 12, 2026 04:03
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable32-fix-npm-audit branch from 0c28b86 to 632b469 Compare April 19, 2026 04:16
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable32-fix-npm-audit branch from 632b469 to e81bddc Compare April 26, 2026 04:20
Signed-off-by: GitHub <noreply@github.com>
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable32-fix-npm-audit branch from e81bddc to ecad602 Compare May 3, 2026 04:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3. to review dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant