-
Notifications
You must be signed in to change notification settings - Fork 353
Open
Description
Running npm i && npm audit returns the following report.
npm audit
# npm audit report
axios 1.0.0 - 1.11.0
Severity: high
Axios is vulnerable to DoS attack through lack of data size check - https://github.com/advisories/GHSA-4hjh-wcwx-xvwj
fix available via `npm audit fix`
node_modules/axios
brace-expansion 2.0.0 - 2.0.1
brace-expansion Regular Expression Denial of Service vulnerability - https://github.com/advisories/GHSA-v6h2-p8h4-qcjw
fix available via `npm audit fix`
node_modules/brace-expansion
form-data 4.0.0 - 4.0.3
Severity: critical
form-data uses unsafe random function in form-data for choosing boundary - https://github.com/advisories/GHSA-fjxv-7rqg-78g4
fix available via `npm audit fix`
node_modules/form-data
vite 6.0.0 - 6.3.5
Vite middleware may serve files starting with the same name with the public directory - https://github.com/advisories/GHSA-g4jq-h2w9-997c
Vite's `server.fs` settings were not applied to HTML files - https://github.com/advisories/GHSA-jqfw-vq24-v9c3
fix available via `npm audit fix`
node_modules/vite
4 vulnerabilities (2 low, 1 high, 1 critical)
To address all issues, run:
npm audit fix
Running npm audit fix addresses all of the issues without conflict. I didn't see any documentation for configuring the test environment and running the tests, so I did not run any tests to verify that there were no regressions.
Metadata
Metadata
Assignees
Labels
No labels