Skip to content

[stable33] Fix npm audit#2645

Open
nextcloud-command wants to merge 1 commit into
stable33from
automated/noid/stable33-fix-npm-audit
Open

[stable33] Fix npm audit#2645
nextcloud-command wants to merge 1 commit into
stable33from
automated/noid/stable33-fix-npm-audit

Conversation

@nextcloud-command

@nextcloud-command nextcloud-command commented Jun 7, 2026

Copy link
Copy Markdown
Contributor

Audit report

This audit fix resolves 3 of the total 22 vulnerabilities found in your project.

Updated dependencies

Fixed vulnerabilities

@nextcloud/cypress #

  • Caused by vulnerable dependency:
  • Affected versions:
  • Package usage:
    • node_modules/@nextcloud/cypress

@vitest/coverage-v8 #

  • Caused by vulnerable dependency:
  • Affected versions: 4.0.0-beta.1 - 4.1.0-beta.6
  • Package usage:
    • node_modules/@vitest/coverage-v8

vitest #

  • When Vitest UI server is listening, arbitrary file can be read and executed
  • Severity: critical 🚨 (CVSS 9.8)
  • Reference: GHSA-5xrq-8626-4rwp
  • Affected versions: 1.0.0-beta.0 - 4.1.0-beta.6
  • Package usage:
    • node_modules/vitest

Full npm audit report

# npm audit report

elliptic  *
Elliptic Uses a Cryptographic Primitive with a Risky Implementation - https://github.com/advisories/GHSA-848j-6mx2-7j84
fix available via `npm audit fix`
node_modules/elliptic
  browserify-sign  >=2.4.0
  Depends on vulnerable versions of elliptic
  node_modules/browserify-sign
    crypto-browserify  >=3.4.0
    Depends on vulnerable versions of browserify-sign
    Depends on vulnerable versions of create-ecdh
    node_modules/crypto-browserify
      node-stdlib-browser  *
      Depends on vulnerable versions of crypto-browserify
      node_modules/node-stdlib-browser
        vite-plugin-node-polyfills  >=0.3.0
        Depends on vulnerable versions of node-stdlib-browser
        node_modules/vite-plugin-node-polyfills
  create-ecdh  *
  Depends on vulnerable versions of elliptic
  node_modules/create-ecdh

esbuild  0.17.0 - 0.28.0
Severity: high
esbuild: Missing binary integrity verification in Deno module enables remote code execution via NPM_CONFIG_REGISTRY - https://github.com/advisories/GHSA-gv7w-rqvm-qjhr
esbuild allows arbitrary file read when running the development server on Windows - https://github.com/advisories/GHSA-g7r4-m6w7-qqqr
No fix available
node_modules/esbuild
node_modules/vite/node_modules/esbuild
  rollup-plugin-esbuild-minify  >=1.0.8
  Depends on vulnerable versions of esbuild
  node_modules/rollup-plugin-esbuild-minify
    @nextcloud/vite-config  *
    Depends on vulnerable versions of rollup-plugin-esbuild-minify
    Depends on vulnerable versions of vite
    Depends on vulnerable versions of vite-plugin-node-polyfills
    node_modules/@nextcloud/vite-config
  vite  4.2.0-beta.0 - 8.0.3
  Depends on vulnerable versions of esbuild
  node_modules/vite

qs  6.11.1 - 6.15.1
Severity: moderate
qs has a remotely triggerable DoS: qs.stringify crashes with TypeError on null/undefined entries in comma-format arrays when encodeValuesOnly is set - https://github.com/advisories/GHSA-q8mj-m7cp-5q26
fix available via `npm audit fix`
node_modules/qs
  @cypress/request  <=4.0.0
  Depends on vulnerable versions of qs
  Depends on vulnerable versions of uuid
  node_modules/@cypress/request
    cypress  4.3.0 - 15.14.2
    Depends on vulnerable versions of @cypress/request
    node_modules/cypress
      @nextcloud/cypress  
      Depends on vulnerable versions of cypress
      node_modules/@nextcloud/cypress

uuid  <11.1.1
Severity: moderate
uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided - https://github.com/advisories/GHSA-w5hq-g745-h8pq
fix available via `npm audit fix --force`
Will install dockerode@5.0.0, which is a breaking change
node_modules/dockerode/node_modules/uuid
node_modules/uuid
  dockerode  4.0.3 - 4.0.12
  Depends on vulnerable versions of uuid
  node_modules/dockerode

16 vulnerabilities (6 low, 6 moderate, 4 high)

To address issues that do not require attention, run:
  npm audit fix

To address all issues possible (including breaking changes), run:
  npm audit fix --force

Some issues need review, and may require choosing
a different dependency.

Node.js: v24.16.0 | npm: 11.17.0 | Branch: stable33

@nextcloud-command nextcloud-command added 3. to review dependencies Pull requests that update a dependency file labels Jun 7, 2026
@codecov

codecov Bot commented Jun 7, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@cypress

cypress Bot commented Jun 7, 2026

Copy link
Copy Markdown

Activity    Run #3873

Run Properties:  status check passed Passed #3873  •  git commit 5874bec00c: [stable33] Fix npm audit
Project Activity
Branch Review automated/noid/stable33-fix-npm-audit
Run status status check passed Passed #3873
Run duration 02m 51s
Commit git commit 5874bec00c: [stable33] Fix npm audit
Committer Nextcloud Command Bot
View all properties for this run ↗︎

Test results
Tests that failed  Failures 0
Tests that were flaky  Flaky 0
Tests that did not run due to a developer annotating a test with .skip  Pending 1
Tests that did not run due to a failure in a mocha hook  Skipped 0
Tests that passed  Passing 9
View all changes introduced in this branch ↗︎

Signed-off-by: GitHub <noreply@github.com>
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable33-fix-npm-audit branch from f80e710 to 31f2c62 Compare June 14, 2026 04:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3. to review dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant