richdocuments icon indicating copy to clipboard operation
richdocuments copied to clipboard

[stable31] Fix npm audit

Open nextcloud-command opened this issue 7 months ago • 0 comments

Audit report

This audit fix resolves 10 of the total 17 vulnerabilities found in your project.

Updated dependencies

  • @nextcloud/dialogs
  • @nextcloud/webpack-vue-config
  • @vue/component-compiler-utils
  • brace-expansion
  • postcss
  • tar-fs
  • vue-loader
  • vue-resize
  • vue-template-compiler
  • webpack-dev-server

Fixed vulnerabilities

@nextcloud/dialogs #

  • Caused by vulnerable dependency:
    • @nextcloud/vue
    • vue
    • vue-frag
  • Affected versions: 4.2.0-beta.1 - 6.3.1
  • Package usage:
    • node_modules/@nextcloud/dialogs

@nextcloud/webpack-vue-config #

  • Caused by vulnerable dependency:
    • vue
    • vue-loader
    • vue-template-compiler
  • Affected versions: <=6.2.0
  • Package usage:
    • node_modules/@nextcloud/webpack-vue-config

@vue/component-compiler-utils #

  • Caused by vulnerable dependency:
    • postcss
  • Affected versions: *
  • Package usage:
    • node_modules/@vue/component-compiler-utils

brace-expansion #

  • brace-expansion Regular Expression Denial of Service vulnerability
  • Severity: low (CVSS 3.1)
  • Reference: https://github.com/advisories/GHSA-v6h2-p8h4-qcjw
  • Affected versions: 1.0.0 - 1.1.11 || 2.0.0 - 2.0.1
  • Package usage:
    • node_modules/@typescript-eslint/typescript-estree/node_modules/brace-expansion
    • node_modules/brace-expansion
    • node_modules/detective-typescript/node_modules/brace-expansion
    • node_modules/webdav/node_modules/brace-expansion

postcss #

tar-fs #

vue-loader #

  • Caused by vulnerable dependency:
    • @vue/component-compiler-utils
  • Affected versions: 15.0.0-beta.1 - 15.11.1
  • Package usage:
    • node_modules/vue-loader

vue-resize #

  • Caused by vulnerable dependency:
    • vue
  • Affected versions: 0.4.0 - 1.0.1
  • Package usage:
    • node_modules/vue-resize

vue-template-compiler #

webpack-dev-server #

  • webpack-dev-server users' source code may be stolen when they access a malicious web site with non-Chromium based browser
  • Severity: moderate (CVSS 6.5)
  • Reference: https://github.com/advisories/GHSA-9jgg-88mc-972h
  • Affected versions: <=5.2.0
  • Package usage:
    • node_modules/webpack-dev-server

nextcloud-command avatar May 18 '25 03:05 nextcloud-command