Security update of packages provided by "npm audit fix"
(base) nightness@Mac-mini open-webui % npm i
added 299 packages, and audited 300 packages in 5s
65 packages are looking for funding
run `npm fund` for details
3 vulnerabilities (2 low, 1 high)
To address all issues, run:
npm audit fix
Run `npm audit` for details.
(base) nightness@Mac-mini open-webui % npm audit
# npm audit report
undici <=5.28.2
Undici proxy-authorization header not cleared on cross-origin redirect in fetch - https://github.com/advisories/GHSA-3787-6prv-h9w3
fix available via `npm audit fix`
node_modules/undici
@sveltejs/kit 1.0.0-next.0 - 1.30.3
Depends on vulnerable versions of undici
node_modules/@sveltejs/kit
vite 4.0.0 - 4.5.1
Severity: high
Vite dev server option `server.fs.deny` can be bypassed when hosted on case-insensitive filesystem - https://github.com/advisories/GHSA-c24v-8rfc-w8vw
fix available via `npm audit fix`
node_modules/vite
3 vulnerabilities (2 low, 1 high)
To address all issues, run:
npm audit fix
(base) nightness@Mac-mini open-webui % npm audit fix
changed 4 packages, and audited 300 packages in 6s
65 packages are looking for funding
run `npm fund` for details
found 0 vulnerabilities
---
### Changelog Entry
package-lock.json modified
### Changed
package-lock.json modified
---
<sub>🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.</sub>
## 📋 Pull Request Information
**Original PR:** https://github.com/open-webui/open-webui/pull/1189
**Author:** [@nightness](https://github.com/nightness)
**Created:** 3/17/2024
**Status:** ❌ Closed
**Base:** `main` ← **Head:** `main`
---
### 📝 Commits (4)
- [`917e76a`](https://github.com/open-webui/open-webui/commit/917e76a7d318c7bf18c8b01223c6dc1897f14de5) patches from npm security audit
- [`361d9c7`](https://github.com/open-webui/open-webui/commit/361d9c787b2c5849bddb90834d3027de68f9c9b2) patches from npm security audit
- [`35a1940`](https://github.com/open-webui/open-webui/commit/35a1940641dddce448827b83fadd32bad45927bb) removed lock files per request
- [`1dfed60`](https://github.com/open-webui/open-webui/commit/1dfed60af62b4222aa16ec4dabb34ee09fbd3b50) removed "c" from npm
### 📊 Changes
**4 files changed** (+9 additions, -6141 deletions)
<details>
<summary>View changed files</summary>
📝 `.gitignore` (+7 -1)
📝 `Dockerfile` (+2 -2)
➖ `bun.lockb` (+0 -0)
➖ `package-lock.json` (+0 -6138)
</details>
### 📄 Description
## Description
Security update of packages provided by "npm audit fix"
```
(base) nightness@Mac-mini open-webui % npm i
added 299 packages, and audited 300 packages in 5s
65 packages are looking for funding
run `npm fund` for details
3 vulnerabilities (2 low, 1 high)
To address all issues, run:
npm audit fix
Run `npm audit` for details.
(base) nightness@Mac-mini open-webui % npm audit
# npm audit report
undici <=5.28.2
Undici proxy-authorization header not cleared on cross-origin redirect in fetch - https://github.com/advisories/GHSA-3787-6prv-h9w3
fix available via `npm audit fix`
node_modules/undici
@sveltejs/kit 1.0.0-next.0 - 1.30.3
Depends on vulnerable versions of undici
node_modules/@sveltejs/kit
vite 4.0.0 - 4.5.1
Severity: high
Vite dev server option `server.fs.deny` can be bypassed when hosted on case-insensitive filesystem - https://github.com/advisories/GHSA-c24v-8rfc-w8vw
fix available via `npm audit fix`
node_modules/vite
3 vulnerabilities (2 low, 1 high)
To address all issues, run:
npm audit fix
(base) nightness@Mac-mini open-webui % npm audit fix
changed 4 packages, and audited 300 packages in 6s
65 packages are looking for funding
run `npm fund` for details
found 0 vulnerabilities
---
### Changelog Entry
package-lock.json modified
### Changed
package-lock.json modified
---
<sub>🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.</sub>
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
📋 Pull Request Information
Original PR: https://github.com/open-webui/open-webui/pull/1189
Author: @nightness
Created: 3/17/2024
Status: ❌ Closed
Base:
main← Head:main📝 Commits (4)
917e76apatches from npm security audit361d9c7patches from npm security audit35a1940removed lock files per request1dfed60removed "c" from npm📊 Changes
4 files changed (+9 additions, -6141 deletions)
View changed files
📝
.gitignore(+7 -1)📝
Dockerfile(+2 -2)➖
bun.lockb(+0 -0)➖
package-lock.json(+0 -6138)📄 Description
Description
Security update of packages provided by "npm audit fix"