calendar icon indicating copy to clipboard operation
calendar copied to clipboard

[stable5.0] Fix npm audit

Open nextcloud-command opened this issue 1 year ago β€’ 1 comments

Audit report

This audit fix resolves 20 of the total 24 vulnerabilities found in your project.

Updated dependencies

  • @nextcloud/dialogs
  • @nextcloud/files
  • @nextcloud/l10n
  • @nextcloud/moment
  • @nextcloud/vue
  • @vue/component-compiler-utils
  • axios
  • body-parser
  • cookie
  • dompurify
  • elliptic
  • express
  • micromatch
  • node-gettext
  • path-to-regexp
  • postcss
  • send
  • serve-static
  • vue-loader
  • webpack

Fixed vulnerabilities

@nextcloud/dialogs #

  • Caused by vulnerable dependency:
    • @nextcloud/files
    • @nextcloud/l10n
    • @nextcloud/vue
  • Affected versions: >=2.0.0
  • Package usage:
    • node_modules/@nextcloud/dialogs

@nextcloud/files #

  • Caused by vulnerable dependency:
    • @nextcloud/l10n
  • Affected versions: >=1.1.0
  • Package usage:
    • node_modules/@nextcloud/files

@nextcloud/l10n #

  • Caused by vulnerable dependency:
    • node-gettext
  • Affected versions: >=1.1.0
  • Package usage:
    • node_modules/@nextcloud/l10n
    • node_modules/@nextcloud/moment/node_modules/@nextcloud/l10n

@nextcloud/moment #

  • Caused by vulnerable dependency:
    • @nextcloud/l10n
    • node-gettext
  • Affected versions: >=1.1.1
  • Package usage:
    • node_modules/@nextcloud/moment

@nextcloud/vue #

  • Caused by vulnerable dependency:
    • @nextcloud/l10n
  • Affected versions: >=1.4.0
  • Package usage:
    • node_modules/@nextcloud/vue

@vue/component-compiler-utils #

  • Caused by vulnerable dependency:
    • postcss
  • Affected versions: *
  • Package usage:
    • node_modules/@vue/component-compiler-utils

axios #

body-parser #

cookie #

dompurify #

elliptic #

express #

micromatch #

node-gettext #

path-to-regexp #

postcss #

send #

serve-static #

vue-loader #

  • Caused by vulnerable dependency:
    • @vue/component-compiler-utils
  • Affected versions: 15.0.0-beta.1 - 15.11.1
  • Package usage:
    • node_modules/vue-loader

webpack #

  • Webpack's AutoPublicPathRuntimeModule has a DOM Clobbering Gadget that leads to XSS
  • Severity: moderate (CVSS 6.4)
  • Reference: https://github.com/advisories/GHSA-4vvj-4cpr-p986
  • Affected versions: 5.0.0-alpha.0 - 5.93.0
  • Package usage:
    • node_modules/webpack

nextcloud-command avatar Sep 29 '24 03:09 nextcloud-command

Codecov Report

All modified and coverable lines are covered by tests :white_check_mark:

Project coverage is 15.43%. Comparing base (5ef9b1e) to head (0eb3122). Report is 10 commits behind head on stable5.0.

Additional details and impacted files
@@              Coverage Diff              @@
##           stable5.0    #6375      +/-   ##
=============================================
+ Coverage      15.41%   15.43%   +0.01%     
=============================================
  Files            206      206              
  Lines           9451     9439      -12     
  Branches        2192     2183       -9     
=============================================
  Hits            1457     1457              
+ Misses          7676     7664      -12     
  Partials         318      318              
Flag Coverage Ξ”
javascript 15.43% <ΓΈ> (+0.01%) :arrow_up:

Flags with carried forward coverage won't be shown. Click here to find out more.

:umbrella: View full report in Codecov by Sentry.
:loudspeaker: Have feedback on the report? Share it here.

codecov[bot] avatar Sep 29 '24 04:09 codecov[bot]

The branch stable5.0 was superseded.

st3iny avatar Feb 20 '25 22:02 st3iny