Skip to content

[stable1.0] Fix npm audit#2754

Closed
nextcloud-command wants to merge 1 commit into
stable1.0from
automated/noid/stable1.0-fix-npm-audit
Closed

[stable1.0] Fix npm audit#2754
nextcloud-command wants to merge 1 commit into
stable1.0from
automated/noid/stable1.0-fix-npm-audit

Conversation

@nextcloud-command

Copy link
Copy Markdown
Contributor

Audit report

This audit fix resolves 2 of the total 46 vulnerabilities found in your project.

Updated dependencies

Fixed vulnerabilities

@nextcloud/cypress #

  • Caused by vulnerable dependency:
  • Affected versions:
  • Package usage:
    • node_modules/@nextcloud/cypress

dompurify #

  • DOMPurify: IN_PLACE mode trusts attacker-controlled nodeName on live non-form nodes, allowing script retention and XSS via attacker-supplied DOM objects
  • Severity: low
  • Reference: GHSA-x4vx-rjvf-j5p4
  • Affected versions: <=3.4.10
  • Package usage:
    • node_modules/dompurify

Signed-off-by: GitHub <noreply@github.com>
@nextcloud-command nextcloud-command added 3. to review Waiting for reviews dependencies Pull requests that update a dependency file labels Jun 21, 2026
@nextcloud-command nextcloud-command added dependencies Pull requests that update a dependency file 3. to review Waiting for reviews labels Jun 21, 2026
@enjeck enjeck closed this Jun 21, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3. to review Waiting for reviews dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants