phpvms icon indicating copy to clipboard operation
phpvms copied to clipboard

Bump npm dependencies

Open arthurpar06 opened this issue 2 months ago • 0 comments

This PR aims to address numerous vulnerabilities within npm packages. Previously, we encountered over 17 vulnerabilities, posing a significant security risk. Our goal is to ensure that phpvms is as secure as possible. With this PR, I have managed to reduce the number of vulnerabilities to just 3, all of which are on the admin side and stem from packages that are no longer maintained or require significant upgrades.

I opted not to prioritize upgrading these packages at this time, as we are planning to transition to filament soon. Additionally, it's worth noting that theoretically, an admin should not attempt to compromise their own website.

Importantly, this PR also resolves significants CVEs in the frontend, particularly in axios, which is crucial for enhancing security measures.

arthurpar06 avatar Apr 05 '24 10:04 arthurpar06