activity icon indicating copy to clipboard operation
activity copied to clipboard

[stable29] Fix npm audit

Open nextcloud-command opened this issue 1 year ago • 3 comments

Audit report

This audit fix resolves 21 of the total 30 vulnerabilities found in your project.

Updated dependencies

  • @nextcloud/dialogs
  • @nextcloud/files
  • @nextcloud/moment
  • @nextcloud/typings
  • @nextcloud/vite-config
  • @testing-library/vue
  • @vitejs/plugin-vue2
  • @vue/language-core
  • @vue/test-utils
  • axios
  • braces
  • dompurify
  • elliptic
  • micromatch
  • rollup
  • vite
  • vite-plugin-dts
  • vue-resize
  • vue-template-compiler
  • vue-tsc
  • vuex

Fixed vulnerabilities

@nextcloud/dialogs #

  • Caused by vulnerable dependency:
    • @nextcloud/files
    • @nextcloud/l10n
    • @nextcloud/vue
    • vue
    • vue-frag
  • Affected versions: >=2.0.0
  • Package usage:
    • node_modules/@nextcloud/dialogs

@nextcloud/files #

  • Caused by vulnerable dependency:
    • @nextcloud/l10n
  • Affected versions: >=1.1.0
  • Package usage:
    • node_modules/@nextcloud/files

@nextcloud/moment #

  • Caused by vulnerable dependency:
    • @nextcloud/l10n
    • node-gettext
  • Affected versions: >=1.1.1
  • Package usage:
    • node_modules/@nextcloud/moment

@nextcloud/typings #

  • Caused by vulnerable dependency:
    • vue
  • Affected versions: 1.7.0 - 1.8.0
  • Package usage:
    • node_modules/@nextcloud/typings

@nextcloud/vite-config #

  • Caused by vulnerable dependency:
    • @vitejs/plugin-vue2
    • vite-plugin-dts
  • Affected versions: *
  • Package usage:
    • node_modules/@nextcloud/vite-config

@testing-library/vue #

  • Caused by vulnerable dependency:
    • @vue/test-utils
    • vue
    • vue-template-compiler
  • Affected versions: <=5.9.0
  • Package usage:
    • node_modules/@testing-library/vue

@vitejs/plugin-vue2 #

  • Caused by vulnerable dependency:
    • vue
  • Affected versions: *
  • Package usage:
    • node_modules/@vitejs/plugin-vue2

@vue/language-core #

  • Caused by vulnerable dependency:
    • vue-template-compiler
  • Affected versions: <=2.0.28
  • Package usage:
    • node_modules/@vue/language-core

@vue/test-utils #

  • Caused by vulnerable dependency:
    • vue
    • vue-template-compiler
  • Affected versions: <=1.3.6
  • Package usage:
    • node_modules/@vue/test-utils

axios #

braces #

dompurify #

elliptic #

micromatch #

rollup #

vite #

vite-plugin-dts #

  • Caused by vulnerable dependency:
    • @vue/language-core
    • vue-tsc
  • Affected versions: 3.0.0-beta.1 - 4.0.0-beta.2
  • Package usage:
    • node_modules/vite-plugin-dts

vue-resize #

  • Caused by vulnerable dependency:
    • vue
  • Affected versions: 0.4.0 - 1.0.1
  • Package usage:
    • node_modules/vue-resize

vue-template-compiler #

vue-tsc #

  • Caused by vulnerable dependency:
    • @vue/language-core
  • Affected versions: 1.7.0-alpha.0 - 2.0.28
  • Package usage:
    • node_modules/vue-tsc

vuex #

  • Caused by vulnerable dependency:
    • vue
  • Affected versions: 3.1.3 - 3.6.2
  • Package usage:
    • node_modules/vuex

nextcloud-command avatar Jun 16 '24 03:06 nextcloud-command

Activity    Run #2495

Run Properties:  status check failed Failed #2495  •  git commit cf75d9c379: [stable29] Fix npm audit
Project Activity
Branch Review automated/noid/stable29-fix-npm-audit
Run status status check failed Failed #2495
Run duration 03m 56s
Commit git commit cf75d9c379: [stable29] Fix npm audit
Committer Nextcloud Command Bot
View all properties for this run ↗︎

Test results
Tests that failed  Failures 3
Tests that were flaky  Flaky 0
Tests that did not run due to a developer annotating a test with .skip  Pending 0
Tests that did not run due to a failure in a mocha hook  Skipped 0
Tests that passed  Passing 7
View all changes introduced in this branch ↗︎

Tests for review

Failed  cypress/e2e/sidebar.cy.ts • 3 failed tests • Run E2E

View Output

Test Artifacts
Check activity listing in the sidebar > Has share activity Test Replay Screenshots
Check activity listing in the sidebar > Has rename activity Test Replay Screenshots
Check activity listing in the sidebar > Has tag activity Test Replay Screenshots

cypress[bot] avatar Jun 16 '24 04:06 cypress[bot]

/compile /

AndyScherzinger avatar Jul 10 '24 20:07 AndyScherzinger

/compile /

AndyScherzinger avatar Oct 06 '24 19:10 AndyScherzinger

/compile amend /

artonge avatar Mar 06 '25 09:03 artonge

/compile /

miaulalala avatar Mar 17 '25 11:03 miaulalala

/compile amend /

miaulalala avatar Mar 17 '25 11:03 miaulalala

Codecov Report

All modified and coverable lines are covered by tests :white_check_mark:

Project coverage is 41.87%. Comparing base (0a07d0a) to head (3a002dc). Report is 4 commits behind head on stable29.

Additional details and impacted files
@@            Coverage Diff            @@
##           stable29    #1710   +/-   ##
=========================================
  Coverage     41.87%   41.87%           
=========================================
  Files            43       43           
  Lines          3847     3847           
  Branches        110      110           
=========================================
  Hits           1611     1611           
  Misses         2210     2210           
  Partials         26       26           

:umbrella: View full report in Codecov by Sentry.
:loudspeaker: Have feedback on the report? Share it here.

:rocket: New features to boost your workflow:
  • :snowflake: Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • :package: JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

codecov[bot] avatar Mar 23 '25 03:03 codecov[bot]

/compile amend/

miaulalala avatar Mar 24 '25 11:03 miaulalala

/compile amend /

miaulalala avatar Mar 24 '25 14:03 miaulalala

/compile amend /

miaulalala avatar Apr 14 '25 10:04 miaulalala

Local cypress run is green, merging.

artonge avatar Apr 14 '25 16:04 artonge