Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): bump axios to 0.29.0 in v4 to fix vulnerabilities #392

Open
wants to merge 2 commits into
base: v4
Choose a base branch
from

Conversation

julio-rocketchat
Copy link

@julio-rocketchat julio-rocketchat commented Feb 4, 2025

Axios 0.27.2 has a few medium-severity CVEs. I've noticed in this discussion (#383) that @perry-mitchell wanted to update 0.27.2 to 1.x.x to fix these issues, but it would be too much work. That's no longer needed since Axios released patches for the vulnerabilities (0.28.0, 0.28.1, and 0.29.0).

This PR bumps Axios from 0.27.2 to 0.29.0 (https://www.npmjs.com/package/axios/v/0.29.0).

@perry-mitchell
Copy link
Owner

Package lock not updated, so tests are failing. @julio-rocketchat could you kindly run npm install and commit the changes?

@julio-rocketchat
Copy link
Author

julio-rocketchat commented Feb 8, 2025

Package lock not updated, so tests are failing. @julio-rocketchat could you kindly run npm install and commit the changes?

Done. Forgot about the package-lock.json but it should be good now. Thank you

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants