contacts
contacts copied to clipboard
[main] Fix npm audit
Audit report
This audit fix resolves 15 of the total 20 vulnerabilities found in your project.
Updated dependencies
- @nextcloud/dialogs
- @nextcloud/files
- @nextcloud/l10n
- @nextcloud/moment
- @nextcloud/vue
- @vue/component-compiler-utils
- browserify-sign
- create-ecdh
- crypto-browserify
- elliptic
- node-gettext
- node-stdlib-browser
- postcss
- vite-plugin-node-polyfills
- vue-tsc
Fixed vulnerabilities
@nextcloud/dialogs #
- Caused by vulnerable dependency:
- @nextcloud/files
- @nextcloud/l10n
- @nextcloud/vue
- Affected versions: >=2.0.0
- Package usage:
node_modules/@nextcloud/dialogs
@nextcloud/files #
- Caused by vulnerable dependency:
- @nextcloud/l10n
- Affected versions: >=1.1.0
- Package usage:
node_modules/@nextcloud/files
@nextcloud/l10n #
- Caused by vulnerable dependency:
- node-gettext
- Affected versions: >=1.1.0
- Package usage:
node_modules/@nextcloud/l10nnode_modules/@nextcloud/moment/node_modules/@nextcloud/l10n
@nextcloud/moment #
- Caused by vulnerable dependency:
- @nextcloud/l10n
- node-gettext
- Affected versions: >=1.1.1
- Package usage:
node_modules/@nextcloud/moment
@nextcloud/vue #
- Caused by vulnerable dependency:
- @nextcloud/l10n
- Affected versions: >=1.4.0
- Package usage:
node_modules/@nextcloud/vue
@vue/component-compiler-utils #
- Caused by vulnerable dependency:
- postcss
- Affected versions: *
- Package usage:
node_modules/@vue/component-compiler-utils
browserify-sign #
- Caused by vulnerable dependency:
- elliptic
- Affected versions: >=2.4.0
- Package usage:
node_modules/browserify-sign
create-ecdh #
- Caused by vulnerable dependency:
- elliptic
- Affected versions: *
- Package usage:
node_modules/create-ecdh
crypto-browserify #
- Caused by vulnerable dependency:
- browserify-sign
- create-ecdh
- Affected versions: >=3.4.0
- Package usage:
node_modules/crypto-browserify
elliptic #
- Valid ECDSA signatures erroneously rejected in Elliptic
- Severity: low
- Reference: https://github.com/advisories/GHSA-fc9h-whq2-v747
- Affected versions: *
- Package usage:
node_modules/elliptic
node-gettext #
- node-gettext vulnerable to Prototype Pollution
- Severity: moderate (CVSS 5.9)
- Reference: https://github.com/advisories/GHSA-g974-hxvm-x689
- Affected versions: *
- Package usage:
node_modules/node-gettext
node-stdlib-browser #
- Caused by vulnerable dependency:
- crypto-browserify
- Affected versions: *
- Package usage:
node_modules/node-stdlib-browser
postcss #
- PostCSS line return parsing error
- Severity: moderate (CVSS 5.3)
- Reference: https://github.com/advisories/GHSA-7fh5-64p2-3v2j
- Affected versions: <8.4.31
- Package usage:
node_modules/@vue/component-compiler-utils/node_modules/postcss
vite-plugin-node-polyfills #
- Caused by vulnerable dependency:
- node-stdlib-browser
- Affected versions: >=0.3.0
- Package usage:
node_modules/vite-plugin-node-polyfills
vue-tsc #
- Caused by vulnerable dependency:
- @vue/language-core
- Affected versions: 1.7.0-alpha.0 - 2.0.28
- Package usage:
node_modules/vue-tsc