Skip to content

Conversation

@nextcloud-command
Copy link
Contributor

@nextcloud-command nextcloud-command commented Dec 14, 2025

Audit report

This audit fix resolves 2 of the total 38 vulnerabilities found in your project.

Updated dependencies

Fixed vulnerabilities

@nextcloud/webpack-vue-config #

lodash #

  • Lodash has Prototype Pollution Vulnerability in _.unset and _.omit functions
  • Severity: moderate (CVSS 6.5)
  • Reference: GHSA-xxjr-mmjv-4gpg
  • Affected versions: 4.0.0 - 4.17.21
  • Package usage:
    • node_modules/lodash

@nextcloud-command nextcloud-command added 3. to review dependencies Pull requests that update a dependency file labels Dec 14, 2025
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable31-fix-npm-audit branch from 6c2a671 to 5a0eb0e Compare January 4, 2026 03:36
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable31-fix-npm-audit branch 2 times, most recently from 363c169 to 5828182 Compare January 18, 2026 03:46
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable31-fix-npm-audit branch from 5828182 to 6567c9e Compare January 25, 2026 03:49
Signed-off-by: GitHub <noreply@github.com>
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable31-fix-npm-audit branch from 6567c9e to fc5b47f Compare February 1, 2026 04:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3. to review dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants