Skip to content

[stable33] Fix npm audit#8708

Merged
mejo- merged 1 commit into
stable33from
automated/noid/stable33-fix-npm-audit
Jun 7, 2026
Merged

[stable33] Fix npm audit#8708
mejo- merged 1 commit into
stable33from
automated/noid/stable33-fix-npm-audit

Conversation

@nextcloud-command

Copy link
Copy Markdown
Collaborator

Audit report

This audit fix resolves 2 of the total 28 vulnerabilities found in your project.

Updated dependencies

Fixed vulnerabilities

@vitest/coverage-v8 #

  • Caused by vulnerable dependency:
  • Affected versions: <=4.1.0-beta.6
  • Package usage:
    • node_modules/@vitest/coverage-v8

vitest #

  • When Vitest UI server is listening, arbitrary file can be read and executed
  • Severity: critical 🚨 (CVSS 9.8)
  • Reference: GHSA-5xrq-8626-4rwp
  • Affected versions: <4.1.0
  • Package usage:
    • node_modules/vitest

Signed-off-by: GitHub <noreply@github.com>
@nextcloud-command nextcloud-command added 3. to review dependencies Pull requests that update a dependency file labels Jun 7, 2026
@codecov

codecov Bot commented Jun 7, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@mejo- mejo- merged commit f93a463 into stable33 Jun 7, 2026
65 checks passed
@mejo- mejo- deleted the automated/noid/stable33-fix-npm-audit branch June 7, 2026 19:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3. to review dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants