Skip to content

[stable35] Fix npm audit - #2231

Open
nextcloud-command wants to merge 1 commit into
stable35from
automated/noid/stable35-fix-npm-audit
Open

nextcloud-command wants to merge 1 commit into
stable35from
automated/noid/stable35-fix-npm-audit

Conversation

@nextcloud-command

@nextcloud-command nextcloud-command commented Aug 30, 2026 •

Copy link
Copy Markdown
Contributor

Audit report

This audit fix resolves 2 of the total 43 vulnerabilities found in your project.

Updated dependencies

Fixed vulnerabilities

@vue/server-renderer #

  • @vue/server-renderer: XSS via missing CR in attribute-name blacklist
  • Severity: high (CVSS 7.2)
  • Reference: GHSA-g2v6-rqmx-r4w6
  • Affected versions: <=3.5.41
  • Package usage:
    • node_modules/@vue/server-renderer

vue #

  • Caused by vulnerable dependency:
  • Affected versions: 3.2.13 - 3.5.41
  • Package usage:
    • node_modules/vue

@nextcloud-command nextcloud-command added 3. to review dependencies Pull requests that update a dependency file labels Aug 30, 2026
@nextcloud-command
nextcloud-command force-pushed the automated/noid/stable35-fix-npm-audit branch from 3c618c4 to a59c6c5 Compare September 6, 2026 07:33
@nextcloud-command
nextcloud-command force-pushed the automated/noid/stable35-fix-npm-audit branch from a59c6c5 to 22ae466 Compare September 13, 2026 08:04
@nextcloud-command
nextcloud-command force-pushed the automated/noid/stable35-fix-npm-audit branch from 22ae466 to 79ae78a Compare September 20, 2026 08:22
@nextcloud-command
nextcloud-command force-pushed the automated/noid/stable35-fix-npm-audit branch from 79ae78a to fd77f5a Compare September 27, 2026 09:02
@nextcloud-command
nextcloud-command force-pushed the automated/noid/stable35-fix-npm-audit branch from fd77f5a to 0486bcf Compare October 4, 2026 09:29
Signed-off-by: GitHub <noreply@github.com>
@nextcloud-command
nextcloud-command force-pushed the automated/noid/stable35-fix-npm-audit branch from 0486bcf to f1bcde3 Compare October 11, 2026 10:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3. to review dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant