Skip to content

[stable33] Fix npm audit#7723

Open
nextcloud-command wants to merge 1 commit intostable33from
automated/noid/stable33-fix-npm-audit
Open

[stable33] Fix npm audit#7723
nextcloud-command wants to merge 1 commit intostable33from
automated/noid/stable33-fix-npm-audit

Conversation

@nextcloud-command
Copy link
Copy Markdown
Contributor

@nextcloud-command nextcloud-command commented Mar 8, 2026

Audit report

This audit fix resolves 1 of the total 43 vulnerabilities found in your project.

Updated dependencies

Fixed vulnerabilities

dompurify #

  • DOMPurify's ADD_TAGS function form bypasses FORBID_TAGS due to short-circuit evaluation
  • Severity: moderate
  • Reference: GHSA-39q2-94rc-95cp
  • Affected versions: <=3.3.3
  • Package usage:
    • node_modules/dompurify

@nextcloud-command nextcloud-command force-pushed the automated/noid/stable33-fix-npm-audit branch from 5d54b0e to 1dedbcd Compare March 15, 2026 03:52
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable33-fix-npm-audit branch from 1dedbcd to 6ed35e3 Compare March 22, 2026 03:54
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable33-fix-npm-audit branch 2 times, most recently from 640a661 to c9ad2de Compare April 5, 2026 03:51
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable33-fix-npm-audit branch from c9ad2de to d04b926 Compare April 12, 2026 04:04
Signed-off-by: GitHub <noreply@github.com>
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable33-fix-npm-audit branch from d04b926 to 3280b42 Compare April 19, 2026 04:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants