Skip to content

[stable32] Fix npm audit#7825

Open
nextcloud-command wants to merge 1 commit into
stable32from
automated/noid/stable32-fix-npm-audit
Open

[stable32] Fix npm audit#7825
nextcloud-command wants to merge 1 commit into
stable32from
automated/noid/stable32-fix-npm-audit

Conversation

@nextcloud-command
Copy link
Copy Markdown
Contributor

@nextcloud-command nextcloud-command commented Apr 5, 2026

Audit report

This audit fix resolves 1 of the total 39 vulnerabilities found in your project.

Updated dependencies

Fixed vulnerabilities

dompurify #

  • DOMPurify's ADD_TAGS function form bypasses FORBID_TAGS due to short-circuit evaluation
  • Severity: moderate
  • Reference: GHSA-39q2-94rc-95cp
  • Affected versions: <=3.3.3
  • Package usage:
    • node_modules/dompurify

@nextcloud-command nextcloud-command force-pushed the automated/noid/stable32-fix-npm-audit branch from b0b6e72 to 9f42469 Compare April 12, 2026 04:06
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable32-fix-npm-audit branch from 9f42469 to 5aef957 Compare April 19, 2026 04:16
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable32-fix-npm-audit branch 2 times, most recently from 60a8643 to 4c85124 Compare May 3, 2026 04:18
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable32-fix-npm-audit branch from 4c85124 to 3873640 Compare May 10, 2026 04:14
Signed-off-by: GitHub <noreply@github.com>
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable32-fix-npm-audit branch from 3873640 to c3ae974 Compare May 17, 2026 04:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant