Skip to content

Conversation

@iocron
Copy link

@iocron iocron commented Jun 13, 2025

Dependency axios 0.21.x has severity "high". Also ~20 other deps have security vulnerabilities (some of them were fixable with npm audit fix).

axios <=0.29.0
Severity: high
Axios Cross-Site Request Forgery Vulnerability - GHSA-wf5p-g6vw-rhxx
axios Requests Vulnerable To Possible SSRF and Credential Leakage via Absolute URL - GHSA-jr5f-v2jv-69x6

I changed axios to ^1.9.0 and applied npm audit fix.
I also run the tests (npm run pretest && npm run test) and everything was successful (91 tests passing).

@SergioCrisostomo
Copy link

A bit concerned to see this PR ignored... it has been 5 months and no one commented, review, merged or rejected.
Given this is a official package I wonder if you discourage the usage of this package or you have other reasons...

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants