Skip to content

Conversation

@nextcloud-command
Copy link
Contributor

@nextcloud-command nextcloud-command commented Jan 4, 2026

Audit report

This audit fix resolves 2 of the total 30 vulnerabilities found in your project.

Updated dependencies

Fixed vulnerabilities

vite #

  • Vite middleware may serve files starting with the same name with the public directory
  • Severity: low
  • Reference: GHSA-g4jq-h2w9-997c
  • Affected versions: 7.1.0 - 7.1.10
  • Package usage:
    • node_modules/vite

webdav #

  • Caused by vulnerable dependency:
  • Affected versions: 5.7.0 - 5.8.0
  • Package usage:
    • node_modules/webdav

@nextcloud-command nextcloud-command added 3. to review Waiting for reviews dependencies Pull requests that update a dependency file labels Jan 4, 2026
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable31-fix-npm-audit branch 2 times, most recently from f535fe4 to dbdcb9f Compare January 11, 2026 03:46
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable31-fix-npm-audit branch from dbdcb9f to cf53583 Compare January 25, 2026 03:45
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable31-fix-npm-audit branch from cf53583 to 2f25bdb Compare February 1, 2026 04:13
Signed-off-by: GitHub <noreply@github.com>
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable31-fix-npm-audit branch from 2f25bdb to 778a2d5 Compare February 8, 2026 04:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3. to review Waiting for reviews dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant