files_automatedtagging
files_automatedtagging copied to clipboard
[stable31] Fix npm audit
Audit report
This audit fix resolves 13 of the total 20 vulnerabilities found in your project.
Updated dependencies
- @babel/helpers
- @babel/runtime
- @nextcloud/l10n
- @nextcloud/webpack-vue-config
- @vue/component-compiler-utils
- axios
- dompurify
- elliptic
- node-gettext
- postcss
- vue-loader
- vue-resize
- vue-template-compiler
Fixed vulnerabilities
@babel/helpers #
- Babel has inefficient RexExp complexity in generated code with .replace when transpiling named capturing groups
- Severity: moderate (CVSS 6.2)
- Reference: https://github.com/advisories/GHSA-968p-4wvh-cqc8
- Affected versions: <7.26.10
- Package usage:
node_modules/@babel/helpers
@babel/runtime #
- Babel has inefficient RexExp complexity in generated code with .replace when transpiling named capturing groups
- Severity: moderate (CVSS 6.2)
- Reference: https://github.com/advisories/GHSA-968p-4wvh-cqc8
- Affected versions: <7.26.10
- Package usage:
node_modules/@babel/runtime
@nextcloud/l10n #
- Caused by vulnerable dependency:
- node-gettext
- Affected versions: 1.1.0 - 3.1.0
- Package usage:
node_modules/@nextcloud/l10n
@nextcloud/webpack-vue-config #
- Caused by vulnerable dependency:
- vue
- vue-loader
- vue-template-compiler
- Affected versions: *
- Package usage:
node_modules/@nextcloud/webpack-vue-config
@vue/component-compiler-utils #
- Caused by vulnerable dependency:
- postcss
- Affected versions: *
- Package usage:
node_modules/@vue/component-compiler-utils
axios #
- axios Requests Vulnerable To Possible SSRF and Credential Leakage via Absolute URL
- Severity: high
- Reference: https://github.com/advisories/GHSA-jr5f-v2jv-69x6
- Affected versions: <1.8.2
- Package usage:
node_modules/axios
dompurify #
- DOMPurify allows Cross-site Scripting (XSS)
- Severity: moderate (CVSS 4.5)
- Reference: https://github.com/advisories/GHSA-vhxf-7vqr-mrjg
- Affected versions: <3.2.4
- Package usage:
node_modules/dompurify
elliptic #
- Elliptic's private key extraction in ECDSA upon signing a malformed input (e.g. a string)
- Severity: critical 🚨
- Reference: https://github.com/advisories/GHSA-vjh7-7g9h-fjfh
- Affected versions: <=6.6.0
- Package usage:
node_modules/elliptic
node-gettext #
- node-gettext vulnerable to Prototype Pollution
- Severity: high (CVSS 5.9)
- Reference: https://github.com/advisories/GHSA-g974-hxvm-x689
- Affected versions: *
- Package usage:
node_modules/node-gettext
postcss #
- PostCSS line return parsing error
- Severity: moderate (CVSS 5.3)
- Reference: https://github.com/advisories/GHSA-7fh5-64p2-3v2j
- Affected versions: <8.4.31
- Package usage:
node_modules/@vue/component-compiler-utils/node_modules/postcss
vue-loader #
- Caused by vulnerable dependency:
- @vue/component-compiler-utils
- Affected versions: 15.0.0-beta.1 - 15.11.1
- Package usage:
node_modules/vue-loader
vue-resize #
- Caused by vulnerable dependency:
- vue
- Affected versions: 0.4.0 - 1.0.1
- Package usage:
node_modules/vue-resize
vue-template-compiler #
- vue-template-compiler vulnerable to client-side Cross-Site Scripting (XSS)
- Severity: moderate (CVSS 4.2)
- Reference: https://github.com/advisories/GHSA-g3ch-rx76-35fx
- Affected versions: >=2.0.0
- Package usage:
node_modules/vue-template-compiler