Patch Node.js vulnerabilities
Patches the selected Node.js vulnerabilities by updating the affected package versions in package.json and opening a GitHub pull request in the connected repository. The customer reviews and merges the pull request; merging triggers the automatic deployment.
Auto-fix is only available for websites deployed from a connected GitHub repository. Websites deployed from an archive have no auto-fix path and return a 404. The Hostinger GitHub App needs write access to the repository; without it the request fails with a 403 explaining the missing permission.
Only vulnerabilities with is_patchable set to true can be patched. Non-patchable IDs in the selection are skipped; the pull request covers the patchable subset, listed in patched_vulnerability_ids. Selections without any patchable vulnerability are rejected with a 422. Only one patch pull request can be open at a time per website; close or merge it before patching again. Available on Business and Cloud Hosting plans.
Path parameters
Domain name
Request body
Example request
{
"vulnerability_ids": [
"GHSA-1111-2222-3333"
]
}Response
Created response
Example response
{
"pr_url": "https://github.com/owner/repo/pull/42",
"pr_number": 42,
"head_branch": "fix/patch-vulnerabilities-a1b2c3d4",
"patched_vulnerability_ids": [
"GHSA-jf85-cpcp-j695"
]
}