Skip to content

Conversation

nextcloud-command
Copy link
Contributor

@nextcloud-command nextcloud-command commented Sep 7, 2025

Audit report

This audit fix resolves 2 of the total 16 vulnerabilities found in your project.

Updated dependencies

Fixed vulnerabilities

@nextcloud/webpack-vue-config #

axios #

  • Axios is vulnerable to DoS attack through lack of data size check
  • Severity: high (CVSS 7.5)
  • Reference: GHSA-4hjh-wcwx-xvwj
  • Affected versions: <1.12.0
  • Package usage:
    • node_modules/axios

@nextcloud-command nextcloud-command added 3. to review dependencies Pull requests that update a dependency file labels Sep 7, 2025
Copy link
Member

@danxuliu danxuliu left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Tested and works 👍

@nextcloud-command nextcloud-command force-pushed the automated/noid/stable31-fix-npm-audit branch from 01fbe39 to f8d1c56 Compare September 14, 2025 03:16
Copy link
Member

@danxuliu danxuliu left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Tested and works 👍

@danxuliu danxuliu merged commit 555da95 into stable31 Sep 14, 2025
36 checks passed
@danxuliu danxuliu deleted the automated/noid/stable31-fix-npm-audit branch September 14, 2025 09:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3. to review dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants