Skip to content

[stable8.4] Fix npm audit#5236

Merged
hamza221 merged 1 commit intostable8.4from
automated/noid/stable8.4-fix-npm-audit
Apr 14, 2026
Merged

[stable8.4] Fix npm audit#5236
hamza221 merged 1 commit intostable8.4from
automated/noid/stable8.4-fix-npm-audit

Conversation

@nextcloud-command
Copy link
Copy Markdown
Contributor

@nextcloud-command nextcloud-command commented Apr 5, 2026

Audit report

This audit fix resolves 4 of the total 17 vulnerabilities found in your project.

Updated dependencies

Fixed vulnerabilities

@microsoft/api-extractor #

  • Caused by vulnerable dependency:
  • Affected versions: 4.0.0 - 7.58.0 || >=8.0.0
  • Package usage:
    • node_modules/@microsoft/api-extractor

lodash #

  • lodash vulnerable to Code Injection via _.template imports key names
  • Severity: high (CVSS 8.1)
  • Reference: GHSA-r5fr-rjxr-66jc
  • Affected versions: <=4.17.23
  • Package usage:
    • node_modules/lodash

rollup-plugin-license #

  • Caused by vulnerable dependency:
  • Affected versions: <=3.6.0
  • Package usage:
    • node_modules/rollup-plugin-license

vite #

  • Vite Vulnerable to Path Traversal in Optimized Deps .map Handling
  • Severity: moderate
  • Reference: GHSA-4w7w-66w2-5vf9
  • Affected versions: 7.0.0 - 7.3.1
  • Package usage:
    • node_modules/vite

@codecov
Copy link
Copy Markdown

codecov bot commented Apr 5, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

Signed-off-by: GitHub <noreply@github.com>
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable8.4-fix-npm-audit branch from 24dd6a2 to 3e85e26 Compare April 12, 2026 03:59
@hamza221 hamza221 merged commit 9b3f709 into stable8.4 Apr 14, 2026
53 checks passed
@hamza221 hamza221 deleted the automated/noid/stable8.4-fix-npm-audit branch April 14, 2026 12:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3. to review Waiting for reviews dependencies

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants