Skip to content

[stable1.0] Fix npm audit#2492

Merged
AndyScherzinger merged 1 commit into
stable1.0from
automated/noid/stable1.0-fix-npm-audit
Apr 19, 2026
Merged

[stable1.0] Fix npm audit#2492
AndyScherzinger merged 1 commit into
stable1.0from
automated/noid/stable1.0-fix-npm-audit

Conversation

@nextcloud-command

Copy link
Copy Markdown
Contributor

Audit report

This audit fix resolves 1 of the total 23 vulnerabilities found in your project.

Updated dependencies

Fixed vulnerabilities

dompurify #

  • DOMPurify's ADD_TAGS function form bypasses FORBID_TAGS due to short-circuit evaluation
  • Severity: moderate
  • Reference: GHSA-39q2-94rc-95cp
  • Affected versions: <=3.3.3
  • Package usage:
    • node_modules/dompurify

Signed-off-by: GitHub <noreply@github.com>
@nextcloud-command nextcloud-command added 3. to review Waiting for reviews dependencies Pull requests that update a dependency file labels Apr 19, 2026
@AndyScherzinger AndyScherzinger merged commit b9319f3 into stable1.0 Apr 19, 2026
49 of 53 checks passed
@AndyScherzinger AndyScherzinger deleted the automated/noid/stable1.0-fix-npm-audit branch April 19, 2026 16:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3. to review Waiting for reviews dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants