v51

OpenAPI 3.0.0raw.githubusercontent.com2026-08-01267339950.6 KB
Hosting: NodeJS

Patch Node.js vulnerabilities

Patches the selected Node.js vulnerabilities by updating the affected package versions in package.json and opening a GitHub pull request in the connected repository. The customer reviews and merges the pull request; merging triggers the automatic deployment.

Auto-fix is only available for websites deployed from a connected GitHub repository. Websites deployed from an archive have no auto-fix path and return a 404. The Hostinger GitHub App needs write access to the repository; without it the request fails with a 403 explaining the missing permission.

Only vulnerabilities with is_patchable set to true can be patched. Non-patchable IDs in the selection are skipped; the pull request covers the patchable subset, listed in patched_vulnerability_ids. Selections without any patchable vulnerability are rejected with a 422. Only one patch pull request can be open at a time per website; close or merge it before patching again. Available on Business and Cloud Hosting plans.

post/api/hosting/v1/accounts/{username}/websites/{domain}/nodejs/vulnerabilities/patch

Path parameters

usernamestring required
Example:u123456789
domainstring required
Example:mydomain.tld

Domain name

Request body

vulnerability_idsstring[] required

List of vulnerability IDs to patch, as returned by the list vulnerabilities endpoint.

Example request

{
  "vulnerability_ids": [
    "GHSA-1111-2222-3333"
  ]
}

Response

Created response

pr_urlstring

URL to the created GitHub pull request

pr_numberinteger

GitHub pull request number

head_branchstring

The branch created with the fix

patched_vulnerability_idsstring[]

List of vulnerability IDs that were patched in the pull request

Example response

{
  "pr_url": "https://github.com/owner/repo/pull/42",
  "pr_number": 42,
  "head_branch": "fix/patch-vulnerabilities-a1b2c3d4",
  "patched_vulnerability_ids": [
    "GHSA-jf85-cpcp-j695"
  ]
}