Skip to content

[stable33] Fix npm audit#2645

Open
nextcloud-command wants to merge 1 commit into
stable33from
automated/noid/stable33-fix-npm-audit
Open

[stable33] Fix npm audit#2645
nextcloud-command wants to merge 1 commit into
stable33from
automated/noid/stable33-fix-npm-audit

Conversation

@nextcloud-command

@nextcloud-command nextcloud-command commented Jun 7, 2026

Copy link
Copy Markdown
Contributor

Audit report

This audit fix resolves 4 of the total 22 vulnerabilities found in your project.

Updated dependencies

Fixed vulnerabilities

@nextcloud/cypress #

  • Caused by vulnerable dependency:
  • Affected versions:
  • Package usage:
    • node_modules/@nextcloud/cypress

@vitest/coverage-v8 #

  • Caused by vulnerable dependency:
  • Affected versions: 4.0.0-beta.1 - 4.1.0-beta.6
  • Package usage:
    • node_modules/@vitest/coverage-v8

vite #

  • launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows
  • Severity: moderate
  • Reference: GHSA-v6wh-96g9-6wx3
  • Affected versions: 7.0.0 - 7.3.3
  • Package usage:
    • node_modules/vite

vitest #

  • When Vitest UI server is listening, arbitrary file can be read and executed
  • Severity: critical 🚨 (CVSS 9.8)
  • Reference: GHSA-5xrq-8626-4rwp
  • Affected versions: >=4.0.0 <4.1.0
  • Package usage:
    • node_modules/vitest

@nextcloud-command nextcloud-command added 3. to review dependencies Pull requests that update a dependency file labels Jun 7, 2026
@codecov

codecov Bot commented Jun 7, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@cypress

cypress Bot commented Jun 7, 2026

Copy link
Copy Markdown

Activity    Run #3884

Run Properties:  status check passed Passed #3884  •  git commit ae1fe87502: [stable33] Fix npm audit
Project Activity
Branch Review automated/noid/stable33-fix-npm-audit
Run status status check passed Passed #3884
Run duration 02m 18s
Commit git commit ae1fe87502: [stable33] Fix npm audit
Committer Nextcloud Command Bot
View all properties for this run ↗︎

Test results
Tests that failed  Failures 0
Tests that were flaky  Flaky 0
Tests that did not run due to a developer annotating a test with .skip  Pending 1
Tests that did not run due to a failure in a mocha hook  Skipped 0
Tests that passed  Passing 9
View all changes introduced in this branch ↗︎

@nextcloud-command nextcloud-command force-pushed the automated/noid/stable33-fix-npm-audit branch from f80e710 to 31f2c62 Compare June 14, 2026 04:21
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable33-fix-npm-audit branch from 31f2c62 to 9838d69 Compare June 21, 2026 04:23
Signed-off-by: GitHub <noreply@github.com>
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable33-fix-npm-audit branch from 9838d69 to 6c233b2 Compare June 28, 2026 04:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3. to review dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant