Skip to content

Conversation

@nextcloud-command
Copy link
Collaborator

@nextcloud-command nextcloud-command commented Feb 16, 2025

Audit report

This audit fix resolves 12 of the total 29 vulnerabilities found in your project.

Updated dependencies

Fixed vulnerabilities

@nextcloud/dialogs #

  • Caused by vulnerable dependency:
  • Affected versions: >=4.2.0-beta.1
  • Package usage:
    • node_modules/@nextcloud/dialogs

@nextcloud/l10n #

  • Caused by vulnerable dependency:
  • Affected versions: 1.1.0 - 3.1.0
  • Package usage:
    • node_modules/@nextcloud/l10n
    • node_modules/@nextcloud/moment/node_modules/@nextcloud/l10n

@nextcloud/moment #

  • Caused by vulnerable dependency:
  • Affected versions: >=1.1.1
  • Package usage:
    • node_modules/@nextcloud/moment

@vue/test-utils #

  • Caused by vulnerable dependency:
  • Affected versions: <=1.3.6
  • Package usage:
    • node_modules/@vue/test-utils

cypress-vite #

  • Caused by vulnerable dependency:
  • Affected versions: >=1.0.2
  • Package usage:
    • node_modules/cypress-vite

node-gettext #

  • node-gettext vulnerable to Prototype Pollution
  • Severity: high (CVSS 5.9)
  • Reference: GHSA-g974-hxvm-x689
  • Affected versions: *
  • Package usage:
    • node_modules/node-gettext

tsx #

  • Caused by vulnerable dependency:
  • Affected versions: 3.13.0 - 4.19.2
  • Package usage:
    • node_modules/tsx

vite-plugin-css-injected-by-js #

  • Caused by vulnerable dependency:
  • Affected versions: *
  • Package usage:
    • node_modules/vite-plugin-css-injected-by-js

vite-plugin-node-polyfills #

  • Caused by vulnerable dependency:
  • Affected versions: >=0.3.2
  • Package usage:
    • node_modules/vite-plugin-node-polyfills

vue-resize #

  • Caused by vulnerable dependency:
  • Affected versions: 0.4.0 - 1.0.1
  • Package usage:
    • node_modules/vue-resize

vue-template-compiler #

  • vue-template-compiler vulnerable to client-side Cross-Site Scripting (XSS)
  • Severity: moderate (CVSS 4.2)
  • Reference: GHSA-g3ch-rx76-35fx
  • Affected versions: >=2.0.0
  • Package usage:
    • node_modules/vue-template-compiler

vuex #

  • Caused by vulnerable dependency:
  • Affected versions: 3.1.3 - 3.6.2
  • Package usage:
    • node_modules/vuex

@nextcloud-command nextcloud-command added 3. to review dependencies Pull requests that update a dependency file labels Feb 16, 2025
@nextcloud-command nextcloud-command force-pushed the automated/noid/main-fix-npm-audit branch from 0dee6e2 to 14b27bb Compare February 23, 2025 03:31
@codecov
Copy link

codecov bot commented Feb 27, 2025

Codecov Report

All modified and coverable lines are covered by tests ✅

Project coverage is 46.30%. Comparing base (1f75e30) to head (6586280).
Report is 5 commits behind head on main.

Additional details and impacted files
@@            Coverage Diff             @@
##             main    #6912      +/-   ##
==========================================
+ Coverage   37.82%   46.30%   +8.48%     
==========================================
  Files         750      682      -68     
  Lines       42691    34868    -7823     
  Branches     1273     1205      -68     
==========================================
  Hits        16146    16146              
+ Misses      25923    18168    -7755     
+ Partials      622      554      -68     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@juliusknorr juliusknorr merged commit 3f4c598 into main Feb 27, 2025
64 checks passed
@juliusknorr juliusknorr deleted the automated/noid/main-fix-npm-audit branch February 27, 2025 13:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3. to review dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants