server icon indicating copy to clipboard operation
server copied to clipboard

[master] Fix npm audit

Open nextcloud-command opened this issue 1 year ago • 0 comments

Audit report

This audit fix resolves 23 of the total 32 vulnerabilities found in your project.

Updated dependencies

  • @jimp/core
  • @jimp/custom
  • @nextcloud/dialogs
  • @nextcloud/files
  • @nextcloud/l10n
  • @nextcloud/moment
  • @nextcloud/password-confirmation
  • @nextcloud/vue
  • @testing-library/vue
  • @vue/component-compiler-utils
  • @vue/test-utils
  • cookie
  • engine.io
  • nextcloud-vue-collections
  • node-gettext
  • node-vibrant
  • path-to-regexp
  • phin
  • postcss
  • rollup
  • select2
  • socket.io
  • vue-loader

Fixed vulnerabilities

@jimp/core #

  • Caused by vulnerable dependency:
    • phin
  • Affected versions: <=0.21.4--canary.1163.d07ed6254d130e2995d24101e93427ec091016e6.0
  • Package usage:
    • node_modules/@jimp/core

@jimp/custom #

  • Caused by vulnerable dependency:
    • @jimp/core
  • Affected versions: <=0.21.4--canary.1163.d07ed6254d130e2995d24101e93427ec091016e6.0
  • Package usage:
    • node_modules/@jimp/custom

@nextcloud/dialogs #

  • Caused by vulnerable dependency:
    • @nextcloud/files
    • @nextcloud/l10n
    • @nextcloud/vue
  • Affected versions: >=2.0.0
  • Package usage:
    • node_modules/@nextcloud/dialogs
    • node_modules/@nextcloud/upload/node_modules/@nextcloud/dialogs

@nextcloud/files #

  • Caused by vulnerable dependency:
    • @nextcloud/l10n
  • Affected versions: >=1.1.0
  • Package usage:
    • node_modules/@nextcloud/files

@nextcloud/l10n #

  • Caused by vulnerable dependency:
    • node-gettext
  • Affected versions: >=1.1.0
  • Package usage:
    • node_modules/@nextcloud/l10n
    • node_modules/@nextcloud/moment/node_modules/@nextcloud/l10n

@nextcloud/moment #

  • Caused by vulnerable dependency:
    • @nextcloud/l10n
    • node-gettext
  • Affected versions: >=1.1.1
  • Package usage:
    • node_modules/@nextcloud/moment

@nextcloud/password-confirmation #

  • Caused by vulnerable dependency:
    • @nextcloud/l10n
    • @nextcloud/vue
  • Affected versions: >=3.0.0
  • Package usage:
    • node_modules/@nextcloud/password-confirmation

@nextcloud/vue #

  • Caused by vulnerable dependency:
    • @nextcloud/l10n
  • Affected versions: >=1.4.0
  • Package usage:
    • node_modules/@nextcloud/vue

@testing-library/vue #

  • Caused by vulnerable dependency:
    • @vue/test-utils
    • vue-template-compiler
  • Affected versions: <=5.9.0
  • Package usage:
    • node_modules/@testing-library/vue

@vue/component-compiler-utils #

  • Caused by vulnerable dependency:
    • postcss
  • Affected versions: *
  • Package usage:
    • node_modules/@vue/component-compiler-utils

@vue/test-utils #

  • Caused by vulnerable dependency:
    • vue-template-compiler
  • Affected versions: <=1.3.6
  • Package usage:
    • node_modules/@vue/test-utils

cookie #

engine.io #

  • Caused by vulnerable dependency:
    • cookie
  • Affected versions: 1.8.0 - 6.6.1
  • Package usage:
    • node_modules/engine.io

nextcloud-vue-collections #

  • Caused by vulnerable dependency:
    • @nextcloud/l10n
    • @nextcloud/vue
  • Affected versions: >=0.8.0
  • Package usage:
    • node_modules/nextcloud-vue-collections

node-gettext #

node-vibrant #

  • Caused by vulnerable dependency:
    • @jimp/custom
  • Affected versions: 3.1.5 - 3.1.6
  • Package usage:
    • node_modules/node-vibrant

path-to-regexp #

phin #

postcss #

rollup #

  • DOM Clobbering Gadget found in rollup bundled scripts that leads to XSS
  • Severity: high (CVSS 6.4)
  • Reference: https://github.com/advisories/GHSA-gcx4-mw62-g8wm
  • Affected versions: <2.79.2 || >=4.0.0 <4.22.4
  • Package usage:
    • node_modules/rollup
    • node_modules/vite/node_modules/rollup

select2 #

socket.io #

  • Caused by vulnerable dependency:
    • engine.io
  • Affected versions: 1.6.0 - 4.7.5
  • Package usage:
    • node_modules/socket.io

vue-loader #

  • Caused by vulnerable dependency:
    • @vue/component-compiler-utils
  • Affected versions: 15.0.0-beta.1 - 15.11.1
  • Package usage:
    • node_modules/vue-loader

nextcloud-command avatar Oct 20 '24 02:10 nextcloud-command