Skip to content

notes

v5.0.1 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 1d Productivity & Wikis
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

distraction-free markdown markdown-editor nextcloud nextcloud-notes notes

Affected surfaces

deps

Summary

AI summary

Updates deps, https://github.com/nextcloud/notes/pull/1853, and https://github.com/nextcloud/notes/pull/1834 across a mixed release.

Changes in this release

Dependency Low

Updates easymde from 2.20.0 to 2.21.0

Updates easymde from 2.20.0 to 2.21.0

Source: llm_adapter@2026-06-02

Confidence: high

Dependency Low

Updates axios from 1.15.0 to 1.16.0

Updates axios from 1.15.0 to 1.16.0

Source: llm_adapter@2026-06-02

Confidence: high

Dependency Low

Updates fast-xml-builder from 1.1.5 to 1.2.0

Updates fast-xml-builder from 1.1.5 to 1.2.0

Source: llm_adapter@2026-06-02

Confidence: high

Dependency Low

Updates php-cs-fixer/shim from 3.94.2 to 3.95.1

Updates php-cs-fixer/shim from 3.94.2 to 3.95.1

Source: llm_adapter@2026-06-02

Confidence: high

Bugfix Medium

Fixes sharing on older NC versions with files v3

Fixes sharing on older NC versions with files v3

Source: llm_adapter@2026-06-02

Confidence: high

Bugfix Medium

Fixes npm audit issues

Fixes npm audit issues

Source: llm_adapter@2026-06-02

Confidence: high

Full changelog

Security Fixes

  • [main] Fix npm audit (notes#1834)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track notes

Get notified when new releases ship.

Sign up free

About notes

Distraction-free notes and writing

All releases →

Related context

Related tools

Earlier breaking changes

  • v6.0.0 Updates minimum required server version to 33.

Beta — feedback welcome: [email protected]