diff --git a/audit.log b/audit.log index 72c3ec67f..21ebb71f0 100644 --- a/audit.log +++ b/audit.log @@ -1,4 +1,18 @@ ┌─────────────────────┬────────────────────────────────────────────────────────┐ +│ high │ @isaacs/brace-expansion has Uncontrolled Resource │ +│ │ Consumption │ +├─────────────────────┼────────────────────────────────────────────────────────┤ +│ Package │ @isaacs/brace-expansion │ +├─────────────────────┼────────────────────────────────────────────────────────┤ +│ Vulnerable versions │ <=5.0.0 │ +├─────────────────────┼────────────────────────────────────────────────────────┤ +│ Patched versions │ >=5.0.1 │ +├─────────────────────┼────────────────────────────────────────────────────────┤ +│ Paths │ .>mocha>glob>minimatch>@isaacs/brace-expansion │ +├─────────────────────┼────────────────────────────────────────────────────────┤ +│ More info │ https://github.com/advisories/GHSA-7h2j-956f-4vf2 │ +└─────────────────────┴────────────────────────────────────────────────────────┘ +┌─────────────────────┬────────────────────────────────────────────────────────┐ │ moderate │ Undici has an unbounded decompression chain in HTTP │ │ │ responses on Node.js Fetch API via Content-Encoding │ │ │ leads to resource exhaustion │ @@ -27,5 +41,5 @@ ├─────────────────────┼────────────────────────────────────────────────────────┤ │ More info │ https://github.com/advisories/GHSA-73rr-hh4g-fpgx │ └─────────────────────┴────────────────────────────────────────────────────────┘ -2 vulnerabilities found -Severity: 1 low | 1 moderate +3 vulnerabilities found +Severity: 1 low | 1 moderate | 1 high diff --git a/plugins/domains/facebook.com/facebook.post.js b/plugins/domains/facebook.com/facebook.post.js index 716e91dd2..625acf511 100644 --- a/plugins/domains/facebook.com/facebook.post.js +++ b/plugins/domains/facebook.com/facebook.post.js @@ -7,7 +7,7 @@ export default { /^https?:\/\/(?:www|m|business)\.facebook\.com\/photo\.php\?(?:[^\?]+)?fbid=(\d{10,})/i, /^https?:\/\/(?:www|m|business)\.facebook\.com\/photo\/?\?(?:[^\?]+)?fbid=(\d{10,})/i, /^https?:\/\/(?:www|m|business)\.facebook\.com\/[^\/]+\/(posts|activity)\/(\d{10,})/i, - /^https?:\/\/(?:www|m|business)\.facebook\.com\/[^\/]+\/posts\/[^\/]+\/(\d{10,})/i, + /^https?:\/\/(?:www|m|business)\.facebook\.com\/[^\/]+\/posts\/[^\/]+\/(\d{10,})/i, // Facebook still does not recognize it in oEmbed as of Feb 10, 2026 /^https?:\/\/(?:www|m|business)\.facebook\.com\/[^\/]+\/(posts|activity)\/pfbid([a-zA-Z0-9\.\-]+)/i, /^https?:\/\/(?:www|m|business)\.facebook\.com\/[^\/]+\/photos(?:\/[^\/]+)?\/(\d{10,})/i, /^https?:\/\/(?:www|m|business)\.facebook\.com\/notes\/[^\/\?]+\/[^\/]+\/(\d{10,})/i, @@ -58,7 +58,9 @@ export default { "https://www.facebook.com/logvynenko/posts/10151487164961783", "https://www.facebook.com/chamvermeil/photos/a.398119066992522.1073741828.398102673660828/715129168624842/?type=1&theater", "https://www.facebook.com/photo?fbid=3242822485762635&set=pcb.3242829905761893", - "https://www.facebook.com/141700922567987_3903702929701082", + // "https://www.facebook.com/141700922567987_3903702929701082", // Redirects to the unrecognized URL + "https://www.facebook.com/Asda/posts/pfbid02dPKr6XHAY8Ga6MyWNyM3XAEF9YG4WNWhxRUoUU3qJ5nDY7RpXkULPmZVGkHWQB3Ll", + // "https://www.facebook.com/Asda/posts/weve-been-named-the-cheapest-major-online-supermarket-in-may-by-which-the-third-/3903702929701082/", // Facebook still does not recognize it in oEmbed as of Feb 10, 2026 "https://www.facebook.com/docmonkeyorthoanimal/photos/105294651313771/", {noFeeds: true}, {skipMixins: ["fb-error"]} ] diff --git a/plugins/domains/tumblr.com/tumblr.oembed.js b/plugins/domains/tumblr.com/tumblr.oembed.js index 2e3310b36..53584bcd7 100644 --- a/plugins/domains/tumblr.com/tumblr.oembed.js +++ b/plugins/domains/tumblr.com/tumblr.oembed.js @@ -37,6 +37,8 @@ export default { tests: [ "http://fewthistle.tumblr.com/post/58045916432", - "https://nasa.tumblr.com/post/186150527809/pew-pew-pew-imagine-slow-motion-fireworks-that" + "https://nasa.tumblr.com/post/186150527809/pew-pew-pew-imagine-slow-motion-fireworks-that", + "https://tuulikki.tumblr.com/post/806272596495794176/what-is-the-sex-is-just-rock-climbing", + "https://lincolnmotorco.tumblr.com/post/159272549438/the-1961-continental-convertible-photographed-at" ] }; \ No newline at end of file diff --git a/plugins/domains/tumblr.com/tumblr.photo.js b/plugins/domains/tumblr.com/tumblr.photo.js index 3ee26e90a..8e7b91336 100644 --- a/plugins/domains/tumblr.com/tumblr.photo.js +++ b/plugins/domains/tumblr.com/tumblr.photo.js @@ -47,9 +47,9 @@ export default { return links; }, - tests: [{ - pageWithFeed: "http://lincolnmotorco.tumblr.com/" - }, - "http://fewthistle.tumblr.com/post/58045916432" + tests: [ + "https://fewthistle.tumblr.com/post/58045916432", + "https://lincolnmotorco.tumblr.com/post/159272549438/the-1961-continental-convertible-photographed-at", + "https://the-wolf-and-moon.tumblr.com/post/622353448279621632/ngc-2170-angel-nebula" ] }; diff --git a/plugins/domains/tumblr.com/tumblr.text.js b/plugins/domains/tumblr.com/tumblr.text.js index 36a92569e..e707f5957 100644 --- a/plugins/domains/tumblr.com/tumblr.text.js +++ b/plugins/domains/tumblr.com/tumblr.text.js @@ -31,6 +31,7 @@ export default { }, tests: [{skipMethods: ["getData"]}, - "http://blog.slides.com/post/84828911898/slides-turns-one-year-old" + "https://blog.slides.com/post/84828911898/slides-turns-one-year-old", + "https://butts-bouncing-on-the-beltway.tumblr.com/post/804116029629399040" ] }; diff --git a/plugins/domains/twitch.tv/clips.twitch.tv.js b/plugins/domains/twitch.tv/clips.twitch.tv.js index 5499747b4..362be3bc4 100644 --- a/plugins/domains/twitch.tv/clips.twitch.tv.js +++ b/plugins/domains/twitch.tv/clips.twitch.tv.js @@ -32,9 +32,9 @@ export default { }, tests: [{skipMethods: ['getData']}, - "https://clips.twitch.tv/RacySweetJackalBlargNaut-Aurg1DNlYiUgIhJd", - "https://clips.twitch.tv/CourageousRichPeafowlYouDontSay-opqgmVBfJExmluP9", - "https://www.twitch.tv/uhsnow/clip/BlitheHedonisticQuailWutFace-0LqwKOVTwqmrSA_e?filter=clips&range=all&sort=time", - "https://www.twitch.tv/sliggytv/clip/SmoothBoxyCurlewOSsloth-m1exZeUdrO46iNQB", + "https://clips.twitch.tv/RacySweetJackalBlargNaut-Aurg1DNlYiUgIhJd?parent=localhost", + "https://clips.twitch.tv/CourageousRichPeafowlYouDontSay-opqgmVBfJExmluP9?parent=localhost", + "https://www.twitch.tv/uhsnow/clip/BlitheHedonisticQuailWutFace-0LqwKOVTwqmrSA_e?parent=localhost", + "https://www.twitch.tv/sliggytv/clip/SmoothBoxyCurlewOSsloth-m1exZeUdrO46iNQB?parent=localhost", ] }; \ No newline at end of file diff --git a/plugins/domains/twitch.tv/twitch-live-fallback.js b/plugins/domains/twitch.tv/twitch-live-fallback.js index 81a56af1b..439c2f901 100644 --- a/plugins/domains/twitch.tv/twitch-live-fallback.js +++ b/plugins/domains/twitch.tv/twitch-live-fallback.js @@ -39,8 +39,8 @@ export default { tests: [{ noFeeds: true, skipMethods: ["getData"] }, - "https://www.twitch.tv/ninja", - "https://www.twitch.tv/videos/520219960", - "https://www.twitch.tv/videos/2686933296" + "https://www.twitch.tv/ninja?parent=localhost", + "https://www.twitch.tv/videos/520219960?parent=localhost", + "https://www.twitch.tv/videos/2686933296?parent=localhost" ] }; \ No newline at end of file diff --git a/plugins/domains/vbox7.com.js b/plugins/domains/vbox7.com.js index 3ed733d16..c7653884a 100644 --- a/plugins/domains/vbox7.com.js +++ b/plugins/domains/vbox7.com.js @@ -17,6 +17,8 @@ export default { }, tests: [ - "http://www.vbox7.com/play:86abb51a7d?pos=src" + "https://vbox7.com/play:dacbe546dd", + "https://www.vbox7.com/play:bc53a41285", + "https://www.vbox7.com/play:3008fee68a" ] }; \ No newline at end of file