User tests: Successful: Unsuccessful:
Pull Request resolves # .
This pull request (PR) fixes 3 moderate severity security vulnerabilities in indirect NPM dependencies reported by npm audit by using npm audit fix.
All dependencies are indirect development dfependencies.
It needs a development environment with a git clone, composer and npm.
composer install and npm ci.npm audit.# npm audit report
nodemailer <=8.0.4
Severity: moderate
Nodemailer Vulnerable to SMTP Command Injection via CRLF in Transport name Option (EHLO/HELO) - https://github.com/advisories/GHSA-vvjj-xcjg-gr5g
fix available via `npm audit fix`
node_modules/nodemailer
mailparser 2.3.1 - 3.9.6
Depends on vulnerable versions of nodemailer
node_modules/mailparser
smtp-server 2.0.0 - 3.18.3
Depends on vulnerable versions of nodemailer
node_modules/smtp-server
3 moderate severity vulnerabilities
To address all issues, run:
npm audit fix
found 0 vulnerabilities
Please select:
Documentation link for guide.joomla.org:
No documentation changes for guide.joomla.org needed
Pull Request link for manual.joomla.org:
No documentation changes for manual.joomla.org needed
| Status | New | ⇒ | Pending |
| Category | ⇒ | NPM Change |
I have tested this item ✅ successfully on b8a73f9
I have tested this item ✅ successfully on b8a73f9
| Status | Pending | ⇒ | Ready to Commit |
| Labels |
Added:
NPM Resource Changed
bug
PR-6.1-dev
|
||
RTC
| Labels |
Added:
RTC
|
||
I have tested this item ✅ successfully on b8a73f9
This comment was created with the J!Tracker Application at issues.joomla.org/tracker/joomla-cms/47622.