Skip to content

[stable32] Fix npm audit#1503

Merged
susnux merged 1 commit intostable32from
automated/noid/stable32-fix-npm-audit
Mar 18, 2026
Merged

[stable32] Fix npm audit#1503
susnux merged 1 commit intostable32from
automated/noid/stable32-fix-npm-audit

Conversation

@nextcloud-command
Copy link
Copy Markdown
Contributor

@nextcloud-command nextcloud-command commented Mar 8, 2026

Audit report

This audit fix resolves 1 of the total 43 vulnerabilities found in your project.

Updated dependencies

Fixed vulnerabilities

fast-xml-parser #

  • fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity names
  • Severity: critical 🚨 (CVSS 9.3)
  • Reference: GHSA-m7jm-9gc2-mpf2
  • Affected versions: 4.0.0-beta.0 - 4.5.3 || 5.0.0 - 5.3.7
  • Package usage:
    • node_modules/@nextcloud/eslint-plugin/node_modules/fast-xml-parser
    • node_modules/fast-xml-parser

@codecov
Copy link
Copy Markdown

codecov Bot commented Mar 8, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

Signed-off-by: GitHub <noreply@github.com>
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable32-fix-npm-audit branch from 40ba03c to 98b8223 Compare March 15, 2026 03:51
@susnux susnux merged commit 53abe9a into stable32 Mar 18, 2026
41 checks passed
@susnux susnux deleted the automated/noid/stable32-fix-npm-audit branch March 18, 2026 11:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3. to review Waiting for reviews dependencies

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants