Skip to content

[main] Fix npm audit#4783

Merged
elzody merged 1 commit into
mainfrom
automated/noid/main-fix-npm-audit
Jul 21, 2025
Merged

[main] Fix npm audit#4783
elzody merged 1 commit into
mainfrom
automated/noid/main-fix-npm-audit

Conversation

@nextcloud-command
Copy link
Copy Markdown
Contributor

@nextcloud-command nextcloud-command commented May 18, 2025

Audit report

This audit fix resolves 10 of the total 17 vulnerabilities found in your project.

Updated dependencies

Fixed vulnerabilities

@nextcloud/dialogs #

  • Caused by vulnerable dependency:
  • Affected versions: 4.2.0-beta.1 - 6.3.1
  • Package usage:
    • node_modules/@nextcloud/dialogs

@nextcloud/webpack-vue-config #

@vue/component-compiler-utils #

  • Caused by vulnerable dependency:
  • Affected versions: *
  • Package usage:
    • node_modules/@vue/component-compiler-utils

brace-expansion #

  • brace-expansion Regular Expression Denial of Service vulnerability
  • Severity: low (CVSS 3.1)
  • Reference: GHSA-v6h2-p8h4-qcjw
  • Affected versions: 1.0.0 - 1.1.11 || 2.0.0 - 2.0.1
  • Package usage:
    • node_modules/@typescript-eslint/typescript-estree/node_modules/brace-expansion
    • node_modules/brace-expansion
    • node_modules/detective-typescript/node_modules/brace-expansion
    • node_modules/webdav/node_modules/brace-expansion

compression #

  • Caused by vulnerable dependency:
  • Affected versions: 1.0.3 - 1.8.0
  • Package usage:
    • node_modules/compression

on-headers #

  • on-headers is vulnerable to http response header manipulation
  • Severity: low (CVSS 3.4)
  • Reference: GHSA-76c9-3jph-rj3q
  • Affected versions: <1.1.0
  • Package usage:
    • node_modules/on-headers

postcss #

  • PostCSS line return parsing error
  • Severity: moderate (CVSS 5.3)
  • Reference: GHSA-7fh5-64p2-3v2j
  • Affected versions: <8.4.31
  • Package usage:
    • node_modules/@vue/component-compiler-utils/node_modules/postcss

vue-loader #

  • Caused by vulnerable dependency:
  • Affected versions: 15.0.0-beta.1 - 15.11.1
  • Package usage:
    • node_modules/vue-loader

vue-resize #

  • Caused by vulnerable dependency:
  • Affected versions: 0.4.0 - 1.0.1
  • Package usage:
    • node_modules/vue-resize

vue-template-compiler #

  • vue-template-compiler vulnerable to client-side Cross-Site Scripting (XSS)
  • Severity: moderate (CVSS 4.2)
  • Reference: GHSA-g3ch-rx76-35fx
  • Affected versions: >=2.0.0
  • Package usage:
    • node_modules/vue-template-compiler

@nextcloud-command nextcloud-command added 3. to review Ready to be reviewed dependencies Pull requests that update a dependency file labels May 18, 2025
@elzody elzody force-pushed the automated/noid/main-fix-npm-audit branch 2 times, most recently from abb0428 to 850036d Compare May 22, 2025 12:57
@juliusknorr juliusknorr force-pushed the automated/noid/main-fix-npm-audit branch from 850036d to 51accb5 Compare May 23, 2025 13:08
@nextcloud-command nextcloud-command force-pushed the automated/noid/main-fix-npm-audit branch from 51accb5 to 7a6efee Compare May 25, 2025 03:54
@elzody elzody force-pushed the automated/noid/main-fix-npm-audit branch from 7a6efee to 0926171 Compare May 29, 2025 20:24
@nextcloud-command nextcloud-command force-pushed the automated/noid/main-fix-npm-audit branch 2 times, most recently from 3459db5 to c0fb93c Compare June 1, 2025 04:07
@elzody elzody force-pushed the automated/noid/main-fix-npm-audit branch from c0fb93c to ca46bd7 Compare June 4, 2025 20:00
@nextcloud-command nextcloud-command force-pushed the automated/noid/main-fix-npm-audit branch 2 times, most recently from bf8c93b to 05a07d4 Compare June 8, 2025 03:54
@nextcloud-command nextcloud-command force-pushed the automated/noid/main-fix-npm-audit branch from 05a07d4 to 550d9cf Compare June 15, 2025 03:52
@nextcloud-command nextcloud-command force-pushed the automated/noid/main-fix-npm-audit branch from 550d9cf to 1b8f73e Compare June 22, 2025 03:59
@nextcloud-command nextcloud-command force-pushed the automated/noid/main-fix-npm-audit branch 2 times, most recently from 16a9926 to d028f0c Compare July 6, 2025 03:59
@nextcloud-command nextcloud-command force-pushed the automated/noid/main-fix-npm-audit branch 2 times, most recently from 8e08a6a to a74692b Compare July 20, 2025 04:04
Signed-off-by: GitHub <noreply@github.com>
@elzody elzody force-pushed the automated/noid/main-fix-npm-audit branch from a74692b to 57af9ca Compare July 21, 2025 15:10
@elzody elzody merged commit 3f8f068 into main Jul 21, 2025
57 of 59 checks passed
@elzody elzody deleted the automated/noid/main-fix-npm-audit branch July 21, 2025 15:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3. to review Ready to be reviewed dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants