logreader icon indicating copy to clipboard operation
logreader copied to clipboard

[stable30] Fix npm audit

Open nextcloud-command opened this issue 8 months ago • 0 comments

Audit report

This audit fix resolves 14 of the total 21 vulnerabilities found in your project.

Updated dependencies

  • @nextcloud/dialogs
  • @nextcloud/vite-config
  • @vitejs/plugin-vue2
  • @vitest/coverage-istanbul
  • @vitest/mocker
  • @vue/test-utils
  • esbuild
  • happy-dom
  • rollup-plugin-esbuild-minify
  • vite
  • vite-node
  • vitest
  • vue-resize
  • vue-template-compiler

Fixed vulnerabilities

@nextcloud/dialogs #

  • Caused by vulnerable dependency:
    • @nextcloud/vue
    • vue
    • vue-frag
  • Affected versions: >=4.2.0-beta.1
  • Package usage:
    • node_modules/@nextcloud/dialogs

@nextcloud/vite-config #

  • Caused by vulnerable dependency:
    • @vitejs/plugin-vue2
  • Affected versions: <=1.5.3
  • Package usage:
    • node_modules/@nextcloud/vite-config

@vitejs/plugin-vue2 #

  • Caused by vulnerable dependency:
    • vue
  • Affected versions: *
  • Package usage:
    • node_modules/@vitejs/plugin-vue2

@vitest/coverage-istanbul #

  • Caused by vulnerable dependency:
    • vitest
  • Affected versions: <=2.2.0-beta.2
  • Package usage:
    • node_modules/@vitest/coverage-istanbul

@vitest/mocker #

  • Caused by vulnerable dependency:
    • vite
  • Affected versions: <=3.0.0-beta.4
  • Package usage:
    • node_modules/@vitest/mocker

@vue/test-utils #

  • Caused by vulnerable dependency:
    • vue
    • vue-template-compiler
  • Affected versions: <=1.3.6
  • Package usage:
    • node_modules/@vue/test-utils

esbuild #

  • esbuild enables any website to send any requests to the development server and read the response
  • Severity: moderate (CVSS 5.3)
  • Reference: https://github.com/advisories/GHSA-67mh-4wv8-2f99
  • Affected versions: <=0.24.2
  • Package usage:
    • node_modules/esbuild
    • node_modules/vite/node_modules/esbuild

happy-dom #

rollup-plugin-esbuild-minify #

  • Caused by vulnerable dependency:
    • esbuild
  • Affected versions: <=1.2.0
  • Package usage:
    • node_modules/rollup-plugin-esbuild-minify

vite #

  • Caused by vulnerable dependency:
    • esbuild
  • Affected versions: 0.11.0 - 6.1.5
  • Package usage:
    • node_modules/vite

vite-node #

  • Caused by vulnerable dependency:
    • vite
  • Affected versions: <=2.2.0-beta.2
  • Package usage:
    • node_modules/vite-node

vitest #

  • Caused by vulnerable dependency:
    • @vitest/mocker
    • vite
    • vite-node
  • Affected versions: 0.0.1 - 0.0.12 || 0.0.29 - 0.0.122 || 0.3.3 - 3.0.0-beta.4
  • Package usage:
    • node_modules/vitest

vue-resize #

  • Caused by vulnerable dependency:
    • vue
  • Affected versions: 0.4.0 - 1.0.1
  • Package usage:
    • node_modules/vue-resize

vue-template-compiler #

nextcloud-command avatar Apr 27 '25 03:04 nextcloud-command