server icon indicating copy to clipboard operation
server copied to clipboard

[master] Fix npm audit

Open nextcloud-command opened this issue 1 year ago • 0 comments

Audit report

This audit fix resolves 11 of the total 16 vulnerabilities found in your project.

Updated dependencies

  • @jimp/core
  • @jimp/custom
  • engine.io
  • load-bmfont
  • node-vibrant
  • phin
  • puppeteer
  • puppeteer-core
  • select2
  • socket.io-adapter
  • ws

Fixed vulnerabilities

@jimp/core #

  • Caused by vulnerable dependency:
    • phin
  • Affected versions: <=0.21.4--canary.1163.d07ed6254d130e2995d24101e93427ec091016e6.0
  • Package usage:
    • node_modules/@jimp/core

@jimp/custom #

  • Caused by vulnerable dependency:
    • @jimp/core
  • Affected versions: <=0.21.4--canary.1163.d07ed6254d130e2995d24101e93427ec091016e6.0
  • Package usage:
    • node_modules/@jimp/custom

engine.io #

  • Caused by vulnerable dependency:
    • ws
  • Affected versions: 0.7.8 - 0.7.9 || 6.0.0 - 6.5.4
  • Package usage:
    • node_modules/engine.io

load-bmfont #

  • Caused by vulnerable dependency:
    • phin
  • Affected versions: >=1.4.0
  • Package usage:
    • node_modules/load-bmfont

node-vibrant #

  • Caused by vulnerable dependency:
    • @jimp/custom
  • Affected versions: 3.1.5 - 3.1.6
  • Package usage:
    • node_modules/node-vibrant

phin #

puppeteer #

  • Caused by vulnerable dependency:
    • puppeteer-core
  • Affected versions: 18.2.0 - 22.11.1
  • Package usage:
    • node_modules/puppeteer

puppeteer-core #

  • Caused by vulnerable dependency:
    • ws
  • Affected versions: 11.0.0 - 22.11.1
  • Package usage:
    • node_modules/puppeteer-core

select2 #

socket.io-adapter #

  • Caused by vulnerable dependency:
    • ws
  • Affected versions: 2.5.2 - 2.5.4
  • Package usage:
    • node_modules/socket.io-adapter

ws #

  • ws affected by a DoS when handling a request with many HTTP headers
  • Severity: high (CVSS 7.5)
  • Reference: https://github.com/advisories/GHSA-3h5v-q93c-6h6q
  • Affected versions: 8.0.0 - 8.17.0
  • Package usage:
    • node_modules/engine.io/node_modules/ws
    • node_modules/socket.io-adapter/node_modules/ws
    • node_modules/ws

nextcloud-command avatar Jun 23 '24 02:06 nextcloud-command