Skip to content

[stable34] Fix npm audit#1362

Merged
skjnldsv merged 1 commit into
stable34from
automated/noid/stable34-fix-npm-audit
Jun 30, 2026
Merged

[stable34] Fix npm audit#1362
skjnldsv merged 1 commit into
stable34from
automated/noid/stable34-fix-npm-audit

Conversation

@nextcloud-command

@nextcloud-command nextcloud-command commented May 24, 2026

Copy link
Copy Markdown
Contributor

Audit report

This audit fix resolves 2 of the total 18 vulnerabilities found in your project.

Updated dependencies

Fixed vulnerabilities

dompurify #

  • DOMPurify: IN_PLACE mode trusts attacker-controlled nodeName on live non-form nodes, allowing script retention and XSS via attacker-supplied DOM objects
  • Severity: low
  • Reference: GHSA-x4vx-rjvf-j5p4
  • Affected versions: <=3.4.10
  • Package usage:
    • node_modules/dompurify

vite #

  • launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows
  • Severity: moderate
  • Reference: GHSA-v6wh-96g9-6wx3
  • Affected versions: 7.0.0 - 7.3.3
  • Package usage:
    • node_modules/vite

@nextcloud-command nextcloud-command added 3. to review dependencies Pull requests that update a dependency file labels May 24, 2026
@nextcloud-command
nextcloud-command force-pushed the automated/noid/stable34-fix-npm-audit branch from d681ec8 to 41b47e0 Compare May 31, 2026 04:18
@nextcloud-command
nextcloud-command force-pushed the automated/noid/stable34-fix-npm-audit branch 2 times, most recently from 54ddfbb to 639f199 Compare June 14, 2026 04:17
@nextcloud-command
nextcloud-command force-pushed the automated/noid/stable34-fix-npm-audit branch from 639f199 to 276f6e2 Compare June 21, 2026 04:20
Signed-off-by: GitHub <noreply@github.com>
@nextcloud-command
nextcloud-command force-pushed the automated/noid/stable34-fix-npm-audit branch from 276f6e2 to 5f6afa1 Compare June 28, 2026 04:18
@skjnldsv
skjnldsv merged commit 34031ef into stable34 Jun 30, 2026
35 checks passed
@skjnldsv
skjnldsv deleted the automated/noid/stable34-fix-npm-audit branch June 30, 2026 07:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3. to review dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants