calendar icon indicating copy to clipboard operation
calendar copied to clipboard

[stable4.7] Fix npm audit

Open nextcloud-command opened this issue 1 year ago • 1 comments

Audit report

This audit fix resolves 19 of the total 29 vulnerabilities found in your project.

Updated dependencies

  • @nextcloud/axios
  • @nextcloud/dialogs
  • @nextcloud/files
  • @nextcloud/l10n
  • @nextcloud/moment
  • @nextcloud/vue
  • @vue/component-compiler-utils
  • @vue/test-utils
  • axios
  • body-parser
  • cookie
  • dompurify
  • express
  • node-gettext
  • path-to-regexp
  • postcss
  • send
  • serve-static
  • vue-loader

Fixed vulnerabilities

@nextcloud/axios #

  • Caused by vulnerable dependency:
    • axios
  • Affected versions: <=2.3.0
  • Package usage:
    • node_modules/@nextcloud/vue-dashboard/node_modules/@nextcloud/axios

@nextcloud/dialogs #

  • Caused by vulnerable dependency:
    • @nextcloud/files
    • @nextcloud/l10n
    • @nextcloud/vue
  • Affected versions: >=2.0.0
  • Package usage:
    • node_modules/@nextcloud/dialogs
    • node_modules/@nextcloud/vue-dashboard/node_modules/@nextcloud/dialogs

@nextcloud/files #

  • Caused by vulnerable dependency:
    • @nextcloud/l10n
  • Affected versions: >=1.1.0
  • Package usage:
    • node_modules/@nextcloud/files

@nextcloud/l10n #

  • Caused by vulnerable dependency:
    • node-gettext
  • Affected versions: >=1.1.0
  • Package usage:
    • node_modules/@nextcloud/l10n
    • node_modules/@nextcloud/vue-dashboard/node_modules/@nextcloud/l10n

@nextcloud/moment #

  • Caused by vulnerable dependency:
    • @nextcloud/l10n
    • node-gettext
  • Affected versions: >=1.1.1
  • Package usage:
    • node_modules/@nextcloud/moment

@nextcloud/vue #

  • Caused by vulnerable dependency:
    • @nextcloud/axios
    • @nextcloud/dialogs
    • @nextcloud/l10n
    • node-polyfill-webpack-plugin
  • Affected versions: *
  • Package usage:
    • node_modules/@nextcloud/dialogs/node_modules/@nextcloud/vue
    • node_modules/@nextcloud/vue
    • node_modules/@nextcloud/vue-dashboard/node_modules/@nextcloud/vue

@vue/component-compiler-utils #

  • Caused by vulnerable dependency:
    • postcss
  • Affected versions: *
  • Package usage:
    • node_modules/@vue/component-compiler-utils

@vue/test-utils #

  • Caused by vulnerable dependency:
    • vue-template-compiler
  • Affected versions: <=1.3.6
  • Package usage:
    • node_modules/@vue/test-utils

axios #

body-parser #

cookie #

dompurify #

express #

node-gettext #

path-to-regexp #

postcss #

send #

serve-static #

vue-loader #

  • Caused by vulnerable dependency:
    • @vue/component-compiler-utils
  • Affected versions: 15.0.0-beta.1 - 15.11.1
  • Package usage:
    • node_modules/vue-loader

nextcloud-command avatar Sep 15 '24 03:09 nextcloud-command

Codecov Report

All modified and coverable lines are covered by tests :white_check_mark:

Project coverage is 15.51%. Comparing base (7b2cca9) to head (ac5b80f). Report is 121 commits behind head on stable4.7.

Additional details and impacted files
@@            Coverage Diff             @@
##           stable4.7    #6346   +/-   ##
==========================================
  Coverage      15.51%   15.51%           
==========================================
  Files            206      206           
  Lines           9257     9257           
  Branches        1931     1931           
==========================================
  Hits            1436     1436           
  Misses          7821     7821           
Flag Coverage Δ
javascript 15.51% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

:umbrella: View full report in Codecov by Sentry.
:loudspeaker: Have feedback on the report? Share it here.

:rocket: New features to boost your workflow:
  • :snowflake: Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • :package: JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

codecov[bot] avatar Sep 22 '24 04:09 codecov[bot]

EOL

st3iny avatar Jun 04 '25 08:06 st3iny