Skip to content

[stable31] Fix npm audit#3123

Open
nextcloud-command wants to merge 1 commit intostable31from
automated/noid/stable31-fix-npm-audit
Open

[stable31] Fix npm audit#3123
nextcloud-command wants to merge 1 commit intostable31from
automated/noid/stable31-fix-npm-audit

Conversation

@nextcloud-command
Copy link
Contributor

Audit report

This audit fix resolves 2 of the total 43 vulnerabilities found in your project.

Updated dependencies

Fixed vulnerabilities

dompurify #

  • DOMPurify contains a Cross-site Scripting vulnerability
  • Severity: moderate (CVSS 6.1)
  • Reference: GHSA-v2wj-7wpq-c8vv
  • Affected versions: 3.1.3 - 3.3.1
  • Package usage:
    • node_modules/dompurify

vite #

  • Vite middleware may serve files starting with the same name with the public directory
  • Severity: low
  • Reference: GHSA-g4jq-h2w9-997c
  • Affected versions: 7.1.0 - 7.1.10
  • Package usage:
    • node_modules/vite

Signed-off-by: GitHub <noreply@github.com>
@nextcloud-command nextcloud-command added 3. to review Waiting for reviews dependencies Pull requests that update a dependency file labels Mar 22, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3. to review Waiting for reviews dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant