Skip to content

[stable35] Fix npm audit - #1015

Open
nextcloud-command wants to merge 1 commit into
stable35from
automated/noid/stable35-fix-npm-audit
Open

[stable35] Fix npm audit#1015
nextcloud-command wants to merge 1 commit into
stable35from
automated/noid/stable35-fix-npm-audit

Conversation

@nextcloud-command

@nextcloud-command nextcloud-command commented Aug 30, 2026

Copy link
Copy Markdown
Contributor

Audit report

This audit fix resolves 3 of the total 24 vulnerabilities found in your project.

Updated dependencies

Fixed vulnerabilities

@nextcloud/webpack-vue-config #

@vitest/coverage-istanbul #

  • Caused by vulnerable dependency:
  • Affected versions: 2.1.0-beta.1 - 4.1.10
  • Package usage:
    • node_modules/@vitest/coverage-istanbul

vitest #

  • Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock
  • Severity: moderate (CVSS 5.9)
  • Reference: GHSA-82fw-gwwq-j7x9
  • Affected versions: 2.1.0-beta.1 - 4.1.10
  • Package usage:
    • node_modules/vitest

@nextcloud-command nextcloud-command added 3. to review dependencies Pull requests that update a dependency file labels Aug 30, 2026
@nextcloud-command
nextcloud-command force-pushed the automated/noid/stable35-fix-npm-audit branch from 760df76 to 48b8bc7 Compare September 6, 2026 07:28
Signed-off-by: GitHub <noreply@github.com>
@nextcloud-command
nextcloud-command force-pushed the automated/noid/stable35-fix-npm-audit branch from 48b8bc7 to 5f6c821 Compare September 13, 2026 07:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3. to review dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant