Skip to content

[stable32] Fix npm audit#1362

Merged
danxuliu merged 1 commit intostable32from
automated/noid/stable32-fix-npm-audit
Mar 19, 2026
Merged

[stable32] Fix npm audit#1362
danxuliu merged 1 commit intostable32from
automated/noid/stable32-fix-npm-audit

Conversation

@nextcloud-command
Copy link
Copy Markdown
Contributor

@nextcloud-command nextcloud-command commented Feb 8, 2026

Audit report

This audit fix resolves 1 of the total 34 vulnerabilities found in your project.

Updated dependencies

Fixed vulnerabilities

axios #

  • Axios is Vulnerable to Denial of Service via proto Key in mergeConfig
  • Severity: high (CVSS 7.5)
  • Reference: GHSA-43fc-jf86-j433
  • Affected versions: 1.0.0 - 1.13.4
  • Package usage:
    • node_modules/axios

@nextcloud-command nextcloud-command added 3. to review dependencies Pull requests that update a dependency file labels Feb 8, 2026
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable32-fix-npm-audit branch 2 times, most recently from 59ec749 to aa706c0 Compare February 22, 2026 03:46
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable32-fix-npm-audit branch 2 times, most recently from fca1bf2 to b557f68 Compare March 8, 2026 03:32
Signed-off-by: GitHub <noreply@github.com>
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable32-fix-npm-audit branch from b557f68 to dc9ef50 Compare March 15, 2026 03:50
@szaimen szaimen requested a review from danxuliu March 16, 2026 10:12
Copy link
Copy Markdown
Member

@danxuliu danxuliu left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Tested and works 👍

@danxuliu danxuliu merged commit 4d39be8 into stable32 Mar 19, 2026
36 checks passed
@danxuliu danxuliu deleted the automated/noid/stable32-fix-npm-audit branch March 19, 2026 04:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3. to review dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants