Skip to content

Dependency audit report #1862

Description

@github-actions

Generated by audit-report.yml on 2026-08-10.

Run yarn npm audit --all --recursive --no-deprecations locally to reproduce.

Report
├─ �[38;5;173mdompurify�[39m
│  ├─ ID: �[38;5;220m1138538�[39m
│  ├─ Issue: DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS
│  ├─ URL: �[38;5;170mhttps://github.com/advisories/GHSA-55q2-fjhq-7xh7�[39m
│  ├─ Severity: moderate
│  ├─ Vulnerable Versions: �[38;5;37m<=3.4.12�[39m
│  │ 
│  ├─ Tree Versions
│  │  └─ �[38;5;111m3.4.12�[39m
│  │ 
│  └─ Dependents
│     └─ �[38;5;173mjspdf�[39m�[38;5;111m@�[39m�[38;5;111mnpm:4.2.1�[39m
│
├─ �[38;5;173mimage-size�[39m
│  ├─ ID: �[38;5;220m1138808�[39m
│  ├─ Issue: image-size: ICNS parser allows denial of service through an infinite loop
│  ├─ URL: �[38;5;170mhttps://github.com/advisories/GHSA-w3rx-r6r6-pgpr�[39m
│  ├─ Severity: high
│  ├─ Vulnerable Versions: �[38;5;37m<=2.0.2�[39m
│  │ 
│  ├─ Tree Versions
│  │  └─ �[38;5;111m0.5.5�[39m
│  │ 
│  └─ Dependents
│     └─ �[38;5;173mless�[39m�[38;5;111m@�[39m�[38;5;111mnpm:4.4.0�[39m
│
├─ �[38;5;173mimage-size�[39m
│  ├─ ID: �[38;5;220m1138809�[39m
│  ├─ Issue: image-size: JXL and HEIF parsers allow denial of service through infinite loops
│  ├─ URL: �[38;5;170mhttps://github.com/advisories/GHSA-5p2g-fcmc-qvqq�[39m
│  ├─ Severity: high
│  ├─ Vulnerable Versions: �[38;5;37m<=2.0.2�[39m
│  │ 
│  ├─ Tree Versions
│  │  └─ �[38;5;111m0.5.5�[39m
│  │ 
│  └─ Dependents
│     └─ �[38;5;173mless�[39m�[38;5;111m@�[39m�[38;5;111mnpm:4.4.0�[39m
│
├─ �[38;5;173mjs-yaml�[39m
│  ├─ ID: �[38;5;220m1138114�[39m
│  ├─ Issue: JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported
│  ├─ URL: �[38;5;170mhttps://github.com/advisories/GHSA-5p4m-2wfm-xmqj�[39m
│  ├─ Severity: high
│  ├─ Vulnerable Versions: �[38;5;37m>=3.0.0 <3.15.1�[39m
│  │ 
│  ├─ Tree Versions
│  │  └─ �[38;5;111m3.15.0�[39m
│  │ 
│  └─ Dependents
│     └─ �[38;5;166m@istanbuljs/�[39m�[38;5;173mload-nyc-config�[39m�[38;5;111m@�[39m�[38;5;111mnpm:1.1.0�[39m
│
├─ �[38;5;173mjs-yaml�[39m
│  ├─ ID: �[38;5;220m1138115�[39m
│  ├─ Issue: JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported
│  ├─ URL: �[38;5;170mhttps://github.com/advisories/GHSA-5p4m-2wfm-xmqj�[39m
│  ├─ Severity: high
│  ├─ Vulnerable Versions: �[38;5;37m>=4.0.0 <4.3.1�[39m
│  │ 
│  ├─ Tree Versions
│  │  └─ �[38;5;111m4.3.0�[39m
│  │ 
│  └─ Dependents
│     └─ �[38;5;173mcosmiconfig�[39m�[38;5;111m@�[39m�[38;5;111mnpm:9.0.2 [c54d6]�[39m
│
└─ �[38;5;173mnanoid�[39m
   ├─ ID: �[38;5;220m1138813�[39m
   ├─ Issue: nanoid: custom generators can loop indefinitely when size is zero
   ├─ URL: �[38;5;170mhttps://github.com/advisories/GHSA-2v37-7h3g-55p8�[39m
   ├─ Severity: high
   ├─ Vulnerable Versions: �[38;5;37m<3.3.17�[39m
   │ 
   ├─ Tree Versions
   │  └─ �[38;5;111m3.3.16�[39m
   │ 
   └─ Dependents
      └─ �[38;5;173mpostcss�[39m�[38;5;111m@�[39m�[38;5;111mnpm:8.5.25�[39m

Advisories with no available fix are recorded in .yarnrc.yml
(npmAuditExcludePackages / npmAuditIgnoreAdvisories), each with the
reasoning and the condition for removing it.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions