Skip to content

[stable34] Fix npm audit#7977

Open
nextcloud-command wants to merge 1 commit into
stable34from
automated/noid/stable34-fix-npm-audit
Open

[stable34] Fix npm audit#7977
nextcloud-command wants to merge 1 commit into
stable34from
automated/noid/stable34-fix-npm-audit

Conversation

@nextcloud-command

@nextcloud-command nextcloud-command commented May 24, 2026

Copy link
Copy Markdown
Contributor

Audit report

This audit fix resolves 1 of the total 78 vulnerabilities found in your project.

Updated dependencies

Fixed vulnerabilities

dompurify #

  • DOMPurify: IN_PLACE mode trusts attacker-controlled nodeName on live non-form nodes, allowing script retention and XSS via attacker-supplied DOM objects
  • Severity: low
  • Reference: GHSA-x4vx-rjvf-j5p4
  • Affected versions: <=3.4.10
  • Package usage:
    • node_modules/dompurify

@nextcloud-command nextcloud-command force-pushed the automated/noid/stable34-fix-npm-audit branch from 407090b to 5a3b4b7 Compare May 31, 2026 04:22
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable34-fix-npm-audit branch from 5a3b4b7 to a401ed0 Compare June 7, 2026 04:24
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable34-fix-npm-audit branch from a401ed0 to 9908600 Compare June 14, 2026 04:27
Signed-off-by: GitHub <noreply@github.com>
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable34-fix-npm-audit branch from 9908600 to 10e47f6 Compare June 21, 2026 04:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant