Skip to content

[stable28] Fix npm audit - #5914

Merged
mejo- merged 1 commit into
stable28from
automated/noid/stable28-fix-npm-audit
Jun 26, 2024
Merged

[stable28] Fix npm audit#5914
mejo- merged 1 commit into
stable28from
automated/noid/stable28-fix-npm-audit

Conversation

@nextcloud-command

@nextcloud-commandnextcloud-command commented Jun 16, 2024

Copy link
Copy Markdown
Collaborator

Audit report

This audit fix resolves 2 of the total 7 vulnerabilities found in your project.

Updated dependencies

Fixed vulnerabilities

braces #

  • Uncontrolled resource consumption in braces
  • Severity: high (CVSS 7.5)
  • Reference: GHSA-grv7-fg5c-xmjg
  • Affected versions: <3.0.3
  • Package usage:
    • node_modules/braces

ws #

  • ws affected by a DoS when handling a request with many HTTP headers
  • Severity: high (CVSS 7.5)
  • Reference: GHSA-3h5v-q93c-6h6q
  • Affected versions: 6.0.0 - 6.2.2 || 8.0.0 - 8.17.0
  • Package usage:
    • node_modules/ws
    • node_modules/y-websocket/node_modules/ws

@nextcloud-commandnextcloud-command added 3. to review dependencies Pull requests that update a dependency file labels Jun 16, 2024
Signed-off-by: GitHub <noreply@github.com>
@nextcloud-command
nextcloud-commandforce-pushed the automated/noid/stable28-fix-npm-audit branch from 4434ee5 to e68b710CompareJune 23, 2024 03:12
@mejo-
mejo- merged commit d270791 into stable28Jun 26, 2024
@mejo-
mejo- deleted the automated/noid/stable28-fix-npm-audit branch June 26, 2024 08:54
@AltahrimAltahrim mentioned this pull request Jul 10, 2024
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3. to reviewdependenciesPull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@nextcloud-command@mejo-